Bleepingcomputer Malicious Ransomware Extensions Found on Microsoft VS Code Marketplace
Article Content
Browse articles
A ransomware-style extension named susvsex, created with basic capabilities and labeled as 'vibe-coded,' was discovered on Microsoft's official VS Code marketplace. The extension, published by 'suspublisher18,' openly advertised its malicious functionality, raising concerns about security in the marketplace. Researcher John Tuckner from Secure Annex identified the extension, noting its lack of sophistication and accidental inclusion of command and control server code.
Ask AI about this cluster
Answers cite the sources they use
Updated 205d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track Ransomvibe in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…