AINewsnow

A single git trick beat the safety lock on four AI coding agents

The AI industry already knew attackers could poison plugin marketplaces. Its answer was to lock every plugin to one reviewed version of its code. That lock is what just broke. Researchers at Air Security published a vulnerability on Thursday that they call Plugin4Shell. It affects the four most wid…

Read the full story at The Next Web ↗

Timeline · 1 report

  1. 2026-09-21 12:53 · The Next Web
    A single git trick beat the safety lock on four AI coding agents

More stories

  1. Introducing Kimi K3 on Amazon Bedrock — AWS Machine Learning Blog
  2. Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
  3. Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Politico Technology
  4. Bessent hails US-China AI dialogue ahead of Trump-Xi meeting — Financial Times AI
  5. Meet the Data Agent in ChatGPT Work — OpenAI YouTube
  6. [ Removed by Reddit ] — r/ArtificialInteligence
  7. NVIDIA CEO Jensen Huang rejects ‘AI will end the world’ claim, yet cautions ‘we should go as fast as we can but...’ — Mint AI
  8. AI hallucination of Chinese nuclear components almost led to US military attack — Ars Technica AI

Get the daily brief of stories like this at 6:30 every morning →