Hacker News new | ask | show | jobs
by zx8080 32 days ago
> "Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately,"

So great that they removed the extension! Do they do it only after their own employee was infected? And why "unnamed" extension?

1 comments

1. Microsoft did link the extension in their official post. Under hacker news guidance, I think that original source link should been posted instead of bleeping computer. https://github.blog/security/investigating-unauthorized-acce...

> “unnamed”

Why is “unnamed” in quotation marks?