Researchers outline how the PhantomRaven campaign exploits hole in npm to enable software supply chain attacks.
VS Code 1.105 also introduces a built-in MCP server marketplace and allows users to resume recent Copilot Chat sessions.