VS Code flaw exposes GitHub OAuth tokens via one-click attack on GitHub.dev, enabling private repo access and token theft.
Fake Claude Code installer malware used Google Ads to place spoofed AI tool pages above real documentation since March 2026.
The release-notes platform now publishes every update through three surfaces: a public page, an in-app widget, and a stable Markdown URL ...