Skip to main content

Tag: manifold security

3 articles

Developer workstation with laptop and monitor on a clean desk, code editor open on screen.

Open VSX Eradicates Malicious Extensions Exfiltrating Developer Data

A shocking discovery by Manifold Security revealed that 77 malicious extensions on Open VSX were secretly siphoning off sensitive data from developers' machines between July 26 and August 1, 2026. These fake extensions, masquerading as legitimate tools, were swiftly removed by Open VSX on August 3, 2026.

Analyst 207
A coding workspace with a laptop on a clean surface, surrounded by office elements.

Microsoft Azure DevOps Flaw Exposes AI Review Agents to Hidden Attacks

Imagine a hidden sentence that only AI sees, turning a reviewer's own AI agent into a vulnerability that lets attackers access projects they shouldn't - a chilling security flaw discovered in Microsoft Azure DevOps. This flaw, known as a confused-deputy vulnerability, was cleverly exploited in a proof of concept by Manifold Security.

Analyst 207
Laptop on cluttered desk with Google Docs open, surrounded by papers and notes in a home office setting.

Claude for Chrome Flaw Exposes Gmail, Google Docs to Rogue Extensions

A security flaw in Claude for Chrome could put your Gmail, Google Docs, and Calendar at risk of being accessed by rogue extensions, with researchers rating the vulnerability as high-severity. A simple script with just six lines of code can trick the extension into treating a fake click as a genuine user action.

Analyst 207