Five free Marketplace extensions promise private, locally run coding assistance as developers look for alternatives to metered cloud AI.
Microsoft has aligned VS Code's existing agent-plugin feature with a vendor-neutral format for portable skills and MCP servers.
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
A trojanized QuickFox Windows installer delivered FDMTP in a supply chain attack active since at least August 2025, after ...
Tom Fenton tackles seven free and open-source AI tools bring local chat, coding, voice, design and research capabilities to personal computers and self-hosted environments.
The Computer History Museum made the Word 1.1a source code publicly available in 2014, now it has been ported to 64-bit ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
A researcher held access to North Korean hacker servers for 22 months and mapped 1,640 victims in 57 countries.
A hijacked GitHub account let the Shai-Hulud worm pass npm's trust check, spreading through packages with 2 billion monthly ...
A massive supply chain attack on the Node Package Manager (npm) registry has infected over 400 packages with over 2 billion downloads with the ...
Catch up with this week's Microsoft stories in our latest recap. See why Windows takes too long to modernize, learn about ...