A VS Code exploit for github.dev can steal GitHub OAuth tokens after one malicious link, exposing private repositories while teams await a patch.
GitHub confirmed a breach affecting about 3,800 internal repositories after an employee installed a malicious VS Code ...