A VS Code vulnerability in GitHub.dev lets attackers steal full GitHub OAuth tokens via a single malicious link, exposing all private repositories.
These features are rolling out to subset of website owners in the UK and will expand it to more in the future.