Visual Studio Code Delays Extension Updates by Two Hours9. June 2026CybersecurityVSCode automatically delays extension updates by two hours after release to minimize the distribution time of compromised versions. Share on:
Without Cyber Threat Intelligence, Supply-Chain Security Remains Blind8. June 2026Cybersecurity, NIS2Supply-chain security requires connecting threat intelligence with internal software inventories and build processes to implement prioritized countermeasures. Share on:
VS Code Introduces Two-Hour Delay for Extension Updates8. June 2026CybersecurityVS Code delays automatic extension updates by two hours to create a detection window for compromised software components. Share on:
RubyGems Introduces Cooldown Phase for Package Updates5. June 20264. July 2026CybersecurityRubyGems introduces a delayable waiting period for newly published packages to extend the time window in which malware in gems can be detected. Share on:
Hugging Face Transformers: RCE Vulnerability in Model Configurations Bypasses Security Measures4. June 20264. July 2026AI Models, CybersecurityHugging Face Transformers allows silent remote code execution via obfuscated parameters in model configurations as long as the optional kernels package is installed (CVE-2026-4372, patched in 5.3.0). Share on:
Component Bills of Materials Help CISOs Manage Vulnerabilities1. June 2026Cybersecurity, NIS2Component and hardware bills of materials (CBOM/HBOM) reduce delays in security risk assessment through systematic transparency of dependencies used. Share on: