Product
Ansible Lightspeed VS Code Extension Command Injection Vulnerability (CVE-2026-44190)
1 TTP 1 CVEA command injection vulnerability (CVE-2026-44190, CWE-78) in the Ansible Lightspeed Visual Studio Code extension allows remote attackers to execute arbitrary commands on a user's system due to improper validation of the `ansible.python.activationScript` setting, leading to complete system control when a malicious project is opened.
GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
A vulnerability, identified as CVE-2026-47282, in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose sensitive information over a network due to insufficiently protected credentials.
Microsoft Security Updates — July 2026
11 CVEs 354 IOCsRoundup of Microsoft security advisories published in July 2026.
GitHub Internal Repositories Breached via Malicious VS Code Extension
2 rules 7 TTPsA GitHub employee's device was compromised via a malicious VS Code extension, leading to the theft of approximately 3,800 internal repositories by threat actor TeamPCP (UNC6780), who then offered the data for sale.
Multiple Vulnerabilities in Microsoft Developer Tools
3 rules 6 TTPsMultiple vulnerabilities in Microsoft developer tools and platforms could allow an attacker to achieve arbitrary code execution, data manipulation, privilege escalation, bypassing security measures, information disclosure, and denial of service.
CVE-2026-41613 - Visual Studio Code Session Fixation Vulnerability
2 rules 1 TTP 1 CVECVE-2026-41613 is a session fixation vulnerability in Visual Studio Code that allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41611: Visual Studio Code XSS Vulnerability
2 rules 4 TTPs 1 CVECVE-2026-41611 is a cross-site scripting (XSS) vulnerability in Visual Studio Code that allows an attacker to execute code locally due to improper neutralization of script-related HTML tags.
VScode Remote Tunnel Abuse for Command and Control
2 rules 1 TTPAdversaries are leveraging the VScode remote tunnel feature to establish unauthorized access and control over Windows systems, potentially enabling command and control activities via disguised legitimate software.
Detection of Suspicious VScode Remote Tunnel Usage
2 rules 1 TTPThis brief details the detection of potential command and control activity through the suspicious use of the VScode remote tunnel feature, which allows attackers to establish unauthorized remote access to systems.
Suspicious Non-Interactive PowerShell Process Creation
2 rules 1 TTPDetects PowerShell processes spawned by non-interactive parent processes, potentially indicating malicious script execution or automation bypassing user interaction.