FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Cybersecurity·High

VS Code Now Delays Updates to Catch Malicious Code

A software developer sits at a wooden desk, working on code within the Visual Studio Code editor on a laptop.

TL;DR: Microsoft's VS Code will now wait two hours before automatically updating extensions. This delay gives developers and security teams a small window to catch and block malicious code before it spreads, improving software supply chain security.

By Neeraj Dhiman·3h ago·1 min read·updated 1h ago
Source

Key facts

Category
Cybersecurity
Impact
High
Published
3h ago
Source
The Hacker News

Full summary

VS Code now delays automatic extension updates by two hours, giving developers a window to catch malicious code before it spreads.

Microsoft has introduced a significant security enhancement for Visual Studio Code, one of the world's most widely used code editors. The software will now automatically apply a two-hour delay before installing new versions of extensions. This feature is active by default for any user with automatic updates enabled and is designed to counter the growing threat of software supply chain attacks, where malicious actors compromise legitimate software to distribute malware. By intentionally slowing down the update cycle, Microsoft creates a crucial time buffer. This window gives its security teams, extension developers, and the wider community a chance to detect, report, and block a malicious update before it reaches the vast user base of VS Code. It is a proactive defense mechanism built directly into the development workflow to protect projects and infrastructure from a dangerous class of cyberattacks.

The importance of this change lies in its ability to mitigate the speed and scale of a potential attack. Previously, a compromised extension could be distributed to millions of developers almost instantly, leaving little time for anyone to react. A malicious update could steal sensitive data like API keys, inject backdoors into company source code, or disrupt development pipelines. The two-hour delay fundamentally alters this dynamic, acting as a critical tripwire. It provides a practical window for automated systems to scan the new package or for the original developer to realize their account was compromised and revoke the update. While not a complete solution, this simple, non-intrusive change adds a powerful layer of protection for individual developers and the organizations they work for, underscoring the need for built-in safeguards in modern development tools.

Action checklist

  1. 1Verify that automatic updates are enabled in your VS Code settings to benefit from this feature.
  2. 2Regularly review the extensions you have installed and remove any that are unused or from untrusted publishers.
  3. 3Encourage your development team to be cautious and report any suspicious extension behavior immediately.

Related on Notifire

  • ResearchKubernetes security
  • ResearchSupply-chain security
  • ResearchCritical CVEs of 2026
  • CompareSSO vs SCIM

✦ Notifire newsletter

Get more Cybersecurity intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Related stories

Primary source: The Hacker News

Part of our research on

  • Software supply-chain security →

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube