• About
  • Disclaimer
  • Privacy Policy
  • Contact
Sunday, June 15, 2025
Cyber Defense GO
  • Login
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration
No Result
View All Result
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration
No Result
View All Result
Cyber Defense Go
No Result
View All Result
Home Cyber Security

Sicherheitsrisiko: Microsoft entfernt VSCode-Erweiterungen | CSO On-line

Md Sazzad Hossain by Md Sazzad Hossain
0
Sicherheitsrisiko: Microsoft entfernt VSCode-Erweiterungen | CSO On-line
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

You might also like

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board

Discord Invite Hyperlink Hijacking Delivers AsyncRAT and Skuld Stealer Concentrating on Crypto Wallets

Why Each Enterprise Wants a Regulatory & Compliance Lawyer—and the Proper IT Infrastructure to Assist Them


Malware entdeckt
Forscher haben herausgefunden, dass zwei VSCode-Erweiterungen mit Schadcode infiziert sind.

VZ_Art – Shutterstock.com

Die IT-Forscher Amit Assaraf und Itay Kruk entdeckten kürzlich, dass die beiden Erweiterungen für Visible Studio Code – “Materials Theme – Free” und “Materials Theme Icons – Free” Schadcode enthalten. Berichten zufolge erfreuten sich diese Erweiterungen großer Beliebtheit und wurden insgesamt quick neun Millionen Mal heruntergeladen.

Laut einer Mitteilung eines Microsoft-Mitarbeiters hat der Tech-Konzern daraufhin nicht nur die beiden Erweiterungen entfernt, sondern auch den Entwickler aus dem Market verbannt. Microsoft bestätigte, dass die Sicherheitsanalyse durch die Neighborhood mehrere Hinweise auf böswillige Absichten ergeben habe. Recherchen von Microsofts eigenen Experten hätten den Vorfall weiter untermauert, heißt es.

Die Forscher berichteten gegenüber Bleeping Pc, dass ihr Scanner verdächtige Aktivitäten im Code der Erweiterungen aufgespürt habe. Sie gehen davon aus, dass der bösartige Code durch ein Replace aufgespielt wurde, entweder durch eine Provide-Chain-Attacke oder eine Kompromittierung des Entwicklerkontos. Besonders auffällig sei gewesen, dass Themes in der Regel statische JSON-Dateien seien und keinen Code ausführen sollten. Zudem entdeckten die Analysten stark verschleierten JavaScript-Code in den “release-notes.js”-Dateien, der mehrfach auf Benutzername- und Passwort-Felder verwies.

Tags: CSOentferntMicrosoftOnlineSicherheitsrisikoVSCodeErweiterungen
Previous Post

Insurcomm Continues Enlargement With New Workplace Opening in Foxborough, Massachusetts

Next Post

dMel: Speech Tokenization Made Easy

Md Sazzad Hossain

Md Sazzad Hossain

Related Posts

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board
Cyber Security

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board

by Md Sazzad Hossain
June 15, 2025
Discord Invite Hyperlink Hijacking Delivers AsyncRAT and Skuld Stealer Concentrating on Crypto Wallets
Cyber Security

Discord Invite Hyperlink Hijacking Delivers AsyncRAT and Skuld Stealer Concentrating on Crypto Wallets

by Md Sazzad Hossain
June 14, 2025
The Carruth Knowledge Breach: What Oregon Faculty Staff Must Know
Cyber Security

Why Each Enterprise Wants a Regulatory & Compliance Lawyer—and the Proper IT Infrastructure to Assist Them

by Md Sazzad Hossain
June 14, 2025
Detecting Ransomware on Community: How Community Site visitors Evaluation Helps
Cyber Security

Detecting Ransomware on Community: How Community Site visitors Evaluation Helps

by Md Sazzad Hossain
June 13, 2025
What’s Zero Belief Structure? A Newbie’s Information
Cyber Security

What’s Zero Belief Structure? A Newbie’s Information

by Md Sazzad Hossain
June 13, 2025
Next Post
Decoding CLIP: Insights on the Robustness to ImageNet Distribution Shifts

dMel: Speech Tokenization Made Easy

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

New botnet hijacks AI-powered safety device on Asus routers

New botnet hijacks AI-powered safety device on Asus routers

May 31, 2025
Pushing the frontiers of audio technology

Pushing the frontiers of audio technology

February 1, 2025

Categories

  • Artificial Intelligence
  • Computer Networking
  • Cyber Security
  • Data Analysis
  • Disaster Restoration
  • Machine Learning

CyberDefenseGo

Welcome to CyberDefenseGo. We are a passionate team of technology enthusiasts, cybersecurity experts, and AI innovators dedicated to delivering high-quality, insightful content that helps individuals and organizations stay ahead of the ever-evolving digital landscape.

Recent

Predicting Insurance coverage Prices with Linear Regression

Predicting Insurance coverage Prices with Linear Regression

June 15, 2025
Detailed Comparability » Community Interview

Detailed Comparability » Community Interview

June 15, 2025

Search

No Result
View All Result

© 2025 CyberDefenseGo - All Rights Reserved

No Result
View All Result
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration

© 2025 CyberDefenseGo - All Rights Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In