Microsoft has aligned VS Code's existing agent-plugin feature with a vendor-neutral format for portable skills and MCP servers.
Microsoft explicitly tied its evaluation of Visual Studio's built-in Agent Skills to GitHub Copilot's new usage-based billing model. A public dashboard compares Copilot quality, execution time and ...
New York, USA, August 13th, 2026, FinanceWireDeveloper tools have become a growing part of the enterprise attack surface, ...
Bloom Security found that 677 VS Code Marketplace extension packs and 94 Open VSX packs contained references to extensions that did not exist, creating a supply-chain attack path through trusted ...
In the new release, developers can experimentally dictate in VS Code without a speech extension and gain deeper insights into subagents.
Malicious Solidity Pro VS Code extensions steal crypto wallets, API keys, SSH keys, and developer tokens, then exfiltrate the ...
New expansion to top debugging now available, integrating seamlessly into existing workflows and supporting young programmers ...
Open VSX extensions exposed developer supply-chain risks. Learn how to audit VS Code extensions and reduce credential exposure.
Development environments have evolved into toolkits for directing coding models and coordinating agents. GitHub Copilot, ...
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
Google joined Amazon and Microsoft in backing an open package format for portable AI-agent skills and MCP servers.
New Package Firewall CLI, VS Code extension, and AI coding assistant plugins enforce package trust before malicious or policy-violating dependencies are installed. Modern software supply chain attacks ...