Security news weekly round-up - 3rd April 2026
Malware, vulnerability, and research in computer security are mostly what we'll talk about in this week's security review. As always, you should know the threat out there and you're responsible for...

Source: DEV Community
Malware, vulnerability, and research in computer security are mostly what we'll talk about in this week's security review. As always, you should know the threat out there and you're responsible for acting accordingly. As always, my name is Habdul Hazeez. Welcome to this week's review. Fake VS Code alerts on GitHub spread malware to developers If you're a developer who receives lots of email notifications from GitHub, be careful of the one that you respond to. Here is what's going on: The discussions are posted in an automated way from newly created or low-activity accounts across thousands of repositories within a few minutes, and trigger email notifications to a large number of tagged users and followers. The posts include links to supposedly patched versions of the impacted VS Code extensions, hosted on external services such as Google Drive. Although Google Drive is obviously not the official software distribution channel for a VS Code extension, it’s a trusted service, and users ac