Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.
First malicious Outlook add-in abused an abandoned domain to host a fake Microsoft login page, stealing 4,000+ credentials in a supply chain attack.