
Tali Ash
152 posts






🚨 Marketplace Takeover: Millions at Risk 🚨 Today, we’re lifting the embargo on one of the most critical supply-chain vulnerabilities we’ve ever seen. Our team at Koi Security discovered a flaw in Open-VSX - the open extension marketplace used by over 8 million developers across VSCode forks like @cursor_ai , @windsurf_ai , Firebase Studio, and many more. Through a misconfigured CI workflow, a malicious actor could silently overwrite every extension in the marketplace. Full control over millions of dev machines. This was a SolarWinds-class risk for developer tooling. We responsibly disclosed the bug in May, worked closely with the Eclipse Foundation on the fix, and today we’re sharing the full write-up — because the ecosystem deserves transparency and protection.








I'm excited about this one 🎉 Hunt in Microsoft 365 Defender without KQL! Our new query builder is now in public preview techcommunity.microsoft.com/t5/microsoft-3… thanks @Taliash1








