In May 2026, GitHub confirmed that an employee device was compromised through a poisoned VS Code extension, reportedly exposing approximately 3,800 internal repositories. The incident demonstrated a critical reality: an organization’s infrastructure does not need to be directly breached.

You might also like...