I'm not saying that's a huge concern, but something one has to consider when protecting their organisation.
I'm not saying that's a huge concern, but something one has to consider when protecting their organisation.
But that's already assuming you get compromised anyway, and that your compromised workstations have things worth reaching on their internal network/VPN. All things that are true on real corporate networks, but "fixing" this vulnerability is still pretty low impact in the grand scheme of things one could do to to improve the situation. But in my experience, most CISOs aren't that great at setting priorities and threat modeling anyway: One just recently told me they doesn't want XSS vulnerabilities reported, because the scanner would find them anyway - but sends out daily all-caps emails about specific emails being phishing.
Your developer uses VSCode and sends a lot of data to vscode.dev or another Microsoft domain? Sounds totally normal, nothing suspicious here, move on!