A new VS Code exploit can rewrite AI agents across all code repositories, an application security specialist demonstrated Thursday.
On Wednesday, the SANS Technology Institute reported on new zero-click exploit that only requires developers open the folder in affected editors. The VS Code exploit involves a malicious tasks.json file that silently runs inside code editors. It was originally identified by Oasis, along with a recommended mitigation developers could apply.
Within 24 hours, Isaac Lewis showed how the exploit can be used to…

![[CITYPNG.COM]White Google Play PlayStore Logo – 1500×1500](https://startupnews.fyi/wp-content/uploads/2025/08/CITYPNG.COMWhite-Google-Play-PlayStore-Logo-1500x1500-1-630x630.png)