National Cyber Warfare Foundation (NCWF)

Microsoft Fixes One-Click GitHub Dev Attack That Let Attackers Steal OAuth Tokens


0 user ratings
2026-06-06 08:53:12
milo
Attacks
Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token.

"Just by clicking a link, it's possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones," security researcher Ammar Askar said.

GitHub supports a feature called GitHub.dev that runs as



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.