developer supply chain

  1. CVE-2026-47287: VS Code Tampering Risk in the Developer Supply Chain

    CVE-2026-47287 is a Microsoft-listed tampering vulnerability in Visual Studio Code, published through the Microsoft Security Response Center on June 9, 2026, affecting the developer toolchain rather than the Windows kernel, and currently framed around confidence in the vulnerability’s existence...