info on the github breach appears to only be available on xitter 🙄 , I fished it out for you.

#github

@0xabad1dea Huh. It’s almost as if an editor with a marketplace for extensions and zero thought to the security model (beyond ‘extensions have complete access to your computer’) might not have been the best idea after all.
@david_chisnall @0xabad1dea
While yes, I think it's more about the
perception of extensions being secure. Emacs has the same security model, but you don't see Big Newsâ„¢ about it.

Granted part of this is that Emacs itself requires a certain level of understanding to use so it filters out users who Just Install Things© but still.

@phil @0xabad1dea @david_chisnall No no, Emacs has a *far* more sophisticated security model than VSCode.

Malware authors sit down to learn Emacs, so they can write Elisp malware ...

... and ten years later they're still customising their editor, and haven't written a single line of malicious code.

(Posted with love as an  user for several decades ...)