Fake VS Code alerts on GitHub spread malware to developers

2026-03-27T19:23:27Z470beecd5a8888d447d790ce6b3c7b0b81aa95d20d6e77dd480a3c6a3093d094
ai-securityawscisacloud-breachcorunacve-2026-33017data-exposuredeveloper-targetinggithubinfostealerios-exploitlangflowlaw-enforcementmalwarephishingredlinesanctionssecurity-updatetakedownvulnerabilitywindows-11xinbi

What happened

Multiple active cyber incidents and developments: a large-scale campaign is abusing GitHub Discussions to post fake Visual Studio Code security alerts that trick developers into downloading malware; CISA warns of active exploitation of a critical Langflow vulnerability (CVE-2026-33017) used to hijack AI workflows; the European Commission is investigating unauthorized access to its Amazon cloud account. Other notable items include phishing-driven breaches at the Dutch National Police, a data/ticket-hijack incident at AFC Ajax, the takedown of the AnimePlay streaming app, UK sanctions on the Xin

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
470beecd5a8888d447d790ce6b3c7b0b81aa95d20d6e77dd480a3c6a3093d094
Enrichment time
2026-03-27T19:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Fake VS Code alerts on GitHub spread malware to developers · Baitaphish