Microsoft has had a VS Code extension for a long time, and it finally came back to bite them.
Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell.