About this talk
This talk, presented by Vinod Tiwari, focuses on the security risks posed by malicious IDE extensions that run on developer machines. The speaker discusses a practical detection system designed to inventory extensions across popular IDEs such as VS Code, Cursor, and JetBrains. By maintaining an allowlist and providing real-time alerts on potential threats, this session addresses the critical need to safeguard sensitive credentials, source code, and production systems from vulnerability.
More from this event
See all 91 talks →
BSidesSF 2026 - Opening Remarks (Sunday) (Reed Loden)
14:36
BSidesSF 2026 - Follow the data to learn the secret (Dylan Ayrey)
35:17
BSidesSF 2026 - Not My Vibe: When AI Coding Agents Go Off the Rails (Aonan Guan, Zhengyu Liu)
45:56
BSidesSF 2026 - "Ask the EFF" Panel (Panel)
45:30