A poisoned VS Code extension led to a GitHub breach, and Microsoft owns every link in the chain
…Auto-update did the attacker's work, and nobody was surprised It's been a known problem VS Code updates extensions silently and automatically, and with good intentions. Security patches are important…
