Grassroots coalition asks politicians to choose voters over Big AI's $140M machine 20 hours ago
Grassroots coalition asks politicians to choose voters over Big AI's $140M machine
AI model watermarking changes agent behavior 21 hours ago
AI model watermarking changes agent behavior
A zero-click vulnerability that allows remote code execution affects all of the major AI coding agents - Anthropic’s Claude Code, OpenAI’s Codex, Google's Gemini CLI, Microsoft’s Copilot, and Microsoft-owned GitHub Copilot - and could give attackers full access to every asset and piece of data that the agent can reach, researchers say.
The exploit, dubbed “Plugin4Shell,” is a “first-of-its-kind AI supply-chain attack,” according to threat hunters at Air, a security startup focused on protecting enterprise AI agents.
Instead of targeting the model or agent, Plugin4Shell attacks trusted marketplaces that host plugins for major coding agents. Such attacks could therefore reach millions of users and machines, the researchers said.
Almost 90 percent of Fortune 500 companies use Copilot, according to Microsoft, which also happens to be one of the two that didn’t ship a patch for the flaw.
“The fix has to ship in the agent, and updating is the only complete mitigation where one exists,” Air researchers Or Nevo, Dor Granat, and Niv Hoffman said in a Thursday report.
The Air team reported the security issue to all four vendors in June, and both Anthropic and OpenAI patched it in Claude Code 2.1.179 and Codex 0.146.0, respectively.
Google has deprecated the Gemini CLI , and therefore told Air it will not patch, so every install remains vulnerable. Google does, however, suggest users migrate to its newer Antigravity agentic development environment, which is protected from this attack.
Microsoft didn’t fix the flaw in Copilot. However, a GitHub spokesperson told us the Plugin4Shell attacks do not affect GitHub.
“To prevent abuse of SHAs, GitHub does not allow users to create branch or tag names that resemble commit SHAs,” the spokesperson said. “This mitigation ensures the reported vulnerability cannot be exploited on GitHub.”
The Air researchers said that the GitHub mitigation isn’t sufficient to defeat Plugin4Shell attacks. This is “because marketplaces can also be hosted in other platforms such as Bitbucket,” the team told The Register.
“Microsoft Copilot is also still vulnerable because it supports marketplaces from such platforms as well, which exposes it to the vulnerability,” the researchers added. “Air also reported the same to Microsoft (since June), but unfortunately due [to] the amount of disclosure volume they’re currently getting we didn’t get a response from them.”
Redmond did not immediately respond to The Register ’s request for .
The security hole sits in how agents enforce marketplaces’ SHA-pinning mechanism, which locks agent plugins and skills to a specific, immutable commit hash instead of a mutable reference like a version tag or branch name.
This aims to prevent supply chain attacks: If a public skill repository is compromised, your AI agent will continue running the same, audited code hash it used when you pinned it instead of automatically pulling new, malicious payloads.
The researchers describe the vulnerability as a “plugin SHA-pinning bypass.”
“The agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin's repo makes the checkout resolve to malicious code while the pin still looks honored," Nevo, Granat, and Hoffman wrote. “The result is zero-click remote code execution.”
Agents’ plugin auto-update feature makes this a zero-click attack. When a pinned commit is swapped upstream, the agent’s plugin gets replaced with a malicious version, and both Claude and Codex automatically update installed plugins by default.
The researchers say an attacker could abuse this flaw in two ways. In one scenario, the attacker submits a benign plugin to a trusted marketplace, the plugin passes review, and then the attacker later replaces the benign content with malicious code.
The second attack involves hijacking a legitimate author's repository and then pushing the malicious version onto every agent that has it installed - essentially bypassing the SHA pinning safety mechanism that exists to stop this type of supply chain attack. The team demonstrates this type of takeover in their earlier SkillJacking and RepoJacking proof-of-concept attacks.
“Together, the chain is proven end to end - takeovers happen at scale, and Plugin4Shell defeats the mechanism built to contain them,” the researchers wrote. ®
KPMG tech cuts come with a severance sum some staff call insulting
AI, Cyber, SAP and Testing teams caught in latest reshaping of Big Four consultancy's Advisory arm
British Army spends £16M on 1,000 pocket-sized eyes in the sky
Surveillance and training drone systems will come through three UK suppliers, though some are built overseas
HPE makes its “unified storage” claim real as B10000 R6 hits GA
PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity
Royal Society slams UK.gov science shake-up
Whitehall changes a 'big mistake' as anything going in with Business department gets squeezed
Open weights are not open source: Why AI's favorite label is under dispute
Downloading a model is increasingly easy. Understanding how it was made, or changing a system at its root, is another matter
Techie fixed Wi-Fi dead zone with a drill
When wires and wireless mix, the combination can be electric
SAAS Salesforce staggers back to feet after global outage
Salesforce staggers back to feet after global outage
databases Oracle celebrates banner quarter with another round of layoffs
Oracle celebrates banner quarter with another round of layoffs
CYBER-CRIME Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
cyber-crime Revolut falls for fake government requests, hands over customer data
Revolut falls for fake government requests, hands over customer data
ai and ml Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent
Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent
devops Microsoft anoints Rust as a 'Tier 1' internal language
Microsoft anoints Rust as a 'Tier 1' internal language
Marvell pushes GlobalFoundries to light up wafer production It might be the trillion-dollar company, but it'll need some help on the supply side to do it
Marvell pushes GlobalFoundries to light up wafer production
It might be the trillion-dollar company, but it'll need some help on the supply side to do it
Huawei's -gen Ascend NPUs could become China's best option 960DT is set to arrive early, boasting performance far exceeding anything the West could offer the Middle Kingdom
Huawei's -gen Ascend NPUs could become China's best option
960DT is set to arrive early, boasting performance far exceeding anything the West could offer the Middle Kingdom
ai and ml AI model watermarking changes agent behavior Lasso Security sees differences in tool handling and model refusals
AI model watermarking changes agent behavior
Lasso Security sees differences in tool handling and model refusals
SYSTEMS Nvidia goes green to keep grid capacity from zapping its revenues GPUzilla woos neoclouds into another walled garden, promising smarter, more efficient, and profitable bit barns
Nvidia goes green to keep grid capacity from zapping its revenues
GPUzilla woos neoclouds into another walled garden, promising smarter, more efficient, and profitable bit barns
cyber-crime Spain gets its first taste of AI-aided cyber attack Data protection chiefs call for 'immediate review' of data protection models
Spain gets its first taste of AI-aided cyber attack
Data protection chiefs call for 'immediate review' of data protection models
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line
Acquisition gives open source CSS framework 'a stable long-term '
Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push
Switzerland tests a FOSS escape route from Microsoft 365
Swiss Army sticks a knife in American cloud apps with its own FOSS push
Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin
Feel peak Windows was 7? You might like Kumander Linux
Debian and Xfce – solid, sensible choices – with a pretty skin
Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted
Canonical shuttering some of its legacy chat channels
The Ubuntu Pastebin went in June, IRC gets demoted
Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Audacity audio-editing app no longer looks like it's from the early 2000s
The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast
A real alternative to running some kind of FOSS Unix clone
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
