Microsoft has had a VS Code extension for a long time, and it finally came back to bite them.
A GitHub employee installed a routine VS Code extension update, handed cybercrime group TeamPCP enough access to exfiltrate ...