VS Code zero-day lets hackers steal GitHub tokens in one click

2026-06-03T07:23:29Z80924e3e8682b344aae65f0b5224a8f9ff90913625944566c8154c25205f1d05
Active Directory discoveryAndroid patchCISACVE-2026-8206ClickFixDashlaneDriveSurgeEDR evasionFakeUpdateGitHub tokensKirkiMiasmaOracle WebLogicVS CodeWeedHackWordPressaccount takeoveractive exploitationbrute-forcecredential theftmalwarenpm compromiseransomwaresupply-chain compromisezero-day

What happened

A BleepingComputer roundup reports multiple active and high-impact security incidents: a VS Code zero-day with exploit code that can steal GitHub authentication tokens via a malicious click; a critical privilege-escalation flaw in the Kirki WordPress plugin (CVE-2026-8206) being actively exploited to take over admin accounts; large-scale malware and supply-chain campaigns (WeedHack infecting >116k Minecraft systems, Red Hat npm package compromise distributing the Miasma credential stealer, and DriveSurge ClickFix/FakeUpdate distribution); and an AI-built ransomware toolkit that automates AD/ED

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
80924e3e8682b344aae65f0b5224a8f9ff90913625944566c8154c25205f1d05
Enrichment time
2026-06-03T07:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.