> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> CVE 2020-16977: VS Code Python Extension Remote Code Execution

[SOURCE] Embrace The Red [DATE: 14/10/2020 17:35] [LANGUAGE: EN]
While building “Husky AI” I started working a lot with Microsoft’s VS Code Python extension. It is a super convinient way to edit Jupyter Notebooks. I just use VS Code’s Remote SSH feature to get to my Linux host and work on modeling and testing there. When threat modeling “Husky AI” I identified backdooring of third party libraries and development tools as a potential issue to be aware of. So finding security issues in the tools is naturally something I am keeping an eye on.
[messages.read_original_source] →