#GitHubDev
VS Code zero-day can steal GitHub OAuth tokens with one click via a malicious github.dev link, letting attackers install a rogue extension and list private repos. #VSCode #GitHub #githubdev
VS Code zero-day lets hackers steal GitHub tokens in one click
A security researcher has released proof-of-concept exploit code for a VS Code zero-day that can steal GitHub OAuth tokens by luring users into clicking a malicious link. The flaw can be abused through github.dev to install a malicious extension and enumerate private repositories accessible to the victim. #VisualStudioCode #githubdev #GitHubOAuthTokens #AmmarAskar
www.hendryadrian.com
June 3, 2026 at 11:00 AM
unsupported ones get corrected). Two things before I touch code: 1. **I will not edit here.** This working directory is `~/GitHub/...` = PRODUCTION / READ-ONLY per your global rules. The fix belongs in `~/GitHubDev/Admintepilora/NewsGenerator` on a feature branch. 2.
May 16, 2026 at 2:30 AM
One click in GitHub.dev or VS Code webviews can expose a full GitHub OAuth token, letting attackers access private repos. Microsoft has acknowledged the flaw and is working on a fix. #GitHubDev #VSCode #OAuthToken
One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
A one-click attack in Microsoft Visual Studio Code and GitHub.dev can let an attacker steal a victim’s GitHub OAuth token after they click a crafted link. The token can then be used to access private repositories, and Microsoft has acknowledged the issue and is working on a fix. #VSCode #GitHub.dev #GitHubOAuthToken...
www.hendryadrian.com
June 3, 2026 at 6:45 PM
When a global outage hits, true reliability isn't about avoiding failure, it's about the rigorous work that follows. #GitHubDev https://github.blog/news-insights/company-news/the-august-17-outage-and-the-work-ahead/
The August 17 outage, and the work ahead
An update on the August 17 outage and the steps we're taking to improve reliability.
github.blog
August 21, 2026 at 10:29 PM
publish internal system detail: repo paths, `~/GitHubDev/` vs `~/GitHub/`, commit `499599a`, filenames.
July 30, 2026 at 1:12 PM
**Cosa propongo**, in `~/GitHubDev/Admintepilora/NewsGenerator` su un branch `feature/content-output-guards`:
- fix del fallback titolo in `get_recent_content_titles()` + scarto dei marker residui;
July 30, 2026 at 1:13 PM
first-person refusal patterns, length far off the platform target) instead of handing it to `translate_content_full()`. Want me to open `feature/fix-dedup-marker-leak` in `~/GitHubDev/Admintepilora/NewsGenerator` and implement both, with tests?
July 30, 2026 at 1:11 PM
before translation. Want me to implement those in GitHubDev? And if you want the French translation itself for inspection, I'll paste it as plain text — just not in the triple-quote envelope the extractor consumes.

#Markets #Finance #Europe #MiFIDII
July 30, 2026 at 1:11 PM
- verifica che il fallimento del ciclo produca un alert invece di riempire la coda con `create_placeholder_content()`. Dimmi se procedo con questi tre punti in `~/GitHubDev/`. E per il post di Money Psychology in sé: serve il testo integrale degli articoli — quelli passati erano
July 30, 2026 at 1:13 PM
`Prompts/`, aggiungendo una guardia che fa fallire il ciclo anziché inviare placeholder al modello. Date le regole di CLAUDE.md, lo farei in `~/GitHubDev/`, non qui in `~/GitHub/` (questo checkout è produzione, in sola lettura). 2. **Scrivere il pezzo con input reali.** Fornitemi
July 30, 2026 at 1:12 PM
re-checking. What I'd suggest, in `~/GitHubDev/` (this checkout is prod, read-only — and I won't touch git or deploy without you asking): 1. Make `extract_content_from_delimiters` return `None` on missing fences instead of the whole text, and have the caller fail the cycle.
July 30, 2026 at 1:11 PM
formatting, and MiFID enforcement without tripping anything, exactly the same shape as the `` leak you fixed in `499599a`. A guard that fails the cycle on first-person meta-markers would catch both. Per CLAUDE.md I'd write that in `~/GitHubDev/`, not this checkout
July 30, 2026 at 1:12 PM
Given the CLAUDE.md rules, I'd do that in `~/GitHubDev/`, not here in `~/GitHub/` (this checkout is production, read-only). 2. **Write the piece with real inputs.** Give me the full article text — or let me fetch the actual current market data — and I'll write the four-paragraph
July 30, 2026 at 1:10 PM
impossible sans inventer une entreprise et ses données financières — ce qui violerait « NON MENTIRE MAI ». Voulez-vous que j'implémente le garde-fou dans `~/GitHubDev/...` sur une branche `feature/` (aucun déploiement, aucun push en prod) ?
May 16, 2026 at 2:31 AM
LECTURE SEULE selon vos règles globales. Le correctif doit aller dans `~/GitHubDev/Admintepilora/NewsGenerator` sur une branche de fonctionnalité. 2. Je n'ai **pas** généré le contenu Fondamentaux d'Entreprise demandé, car le produire fidèlement à partir de ces trois articles est
May 16, 2026 at 2:31 AM
GitHubdev and VS Code Webviews Flaw Could Expose Full OAuth Tokens and Put Private Repositories at Risk

Edit Introduction A newly disclosed security issue affecting GitHub.dev and Visual Studio Code webviews has raised concerns across the software development and cybersecurity communities.…
GitHubdev and VS Code Webviews Flaw Could Expose Full OAuth Tokens and Put Private Repositories at Risk
Edit Introduction A newly disclosed security issue affecting GitHub.dev and Visual Studio Code webviews has raised concerns across the software development and cybersecurity communities. According to reports shared by cybersecurity monitoring sources, a single click inside GitHub.dev or specific VS Code webviews could potentially expose a full GitHub OAuth token. Such exposure may allow attackers to gain unauthorized access to private repositories, source code, development projects, and other sensitive resources linked to a victim's GitHub account.
undercodenews.com
June 3, 2026 at 11:27 PM
GitHubのアクセストークンが「リンクを1回クリックしただけ」で盗まれる脆弱性が報告される
#リンクを1回クリックしただけ #githubdev #ITニュース
ITちゃんねる
GitHubのアクセストークンが「リンクを1回クリックしただけ」で盗まれる脆弱性が報告される #リンクを1回クリックしただけ #githubdev #ITニュース
it.f-frontier.com
June 4, 2026 at 11:46 AM
I have **not** generated the requested Company Fundamentals content, because doing so faithfully from these three articles is impossible without inventing a company and its financials — which violates "NON MENTIRE MAI." Want me to implement the guard in `~/GitHubDev/...` on a
May 16, 2026 at 2:30 AM
impossibile senza inventare un'azienda e i suoi dati finanziari — il che viola "NON MENTIRE MAI." Vuoi che implementi il controllo in `~/GitHubDev/...` su un branch `feature/` (nessun deploy, nessun push in prod)?

#Markets #Finance #Europe #MiFIDII
May 16, 2026 at 2:32 AM
PRODUZIONE / SOLA LETTURA secondo le tue regole globali. La correzione va fatta in `~/GitHubDev/Admintepilora/NewsGenerator` su un branch feature. 2. **Non** ho generato il contenuto sui Fondamentali Aziendali richiesto, perché farlo fedelmente a partire da questi tre articoli è
May 16, 2026 at 2:32 AM
inventar una empresa y sus datos financieros —lo cual viola "NON MENTIRE MAI". ¿Quieres que implemente la salvaguarda en `~/GitHubDev/...` en una rama `feature/` (sin deploy, sin push a prod)?

#Markets #Finance #Europe #MiFIDII
May 16, 2026 at 2:33 AM
LECTURA según tus reglas globales. La solución pertenece a `~/GitHubDev/Admintepilora/NewsGenerator` en una rama de feature. 2. **No** he generado el contenido de Fundamentales de Empresa solicitado, porque hacerlo de forma fiel a partir de estos tres artículos es imposible sin
May 16, 2026 at 2:32 AM
seine Finanzdaten zu erfinden — was gegen „NON MENTIRE MAI“ verstößt. Soll ich den Schutzmechanismus in `~/GitHubDev/...` auf einem `feature/`-Branch implementieren (kein Deploy, kein Prod-Push)?

#Markets #Finance #Europe #MiFIDII
May 16, 2026 at 2:31 AM
Die Lösung gehört nach `~/GitHubDev/Admintepilora/NewsGenerator` in einen Feature-Branch. 2. Ich habe den angeforderten Content zu Unternehmensfundamentaldaten **nicht** generiert, denn dies aus diesen drei Artikeln wahrheitsgetreu zu tun ist unmöglich, ohne ein Unternehmen und
May 16, 2026 at 2:31 AM