AINewsnow

A zero-click RCE flaw in AI coding agents could have exposed enterprise systems

This story is from 2026-09-17. It is preserved in the archive; the latest stories are on the live feed.

Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted plugin from an online…

Read the full story at InfoWorld AI ↗

Timeline · 2 reports

  1. 2026-09-18 15:39 · InfoWorld AI
    A zero-click RCE flaw in AI coding agents could have exposed enterprise systems
  2. 2026-09-17 14:22 · r/ChatGPTCoding
    [ Agenteq ] A single canoncial source for AI coding agents rules

More stories

  1. A zero-click RCE flaw in AI coding agents could have exposed enterprise systems — InfoWorld AI
  2. Plugin4Shell and NIST IR 8587, days apart: what actually authorizes an AI agent’s action? — r/AI_Agents
  3. Pay $39.99 once to put ChatGPT, Claude, Gemini, and more in a single workspace for life — Mashable AI
  4. Gemini self-censors in a harmful, obscure way — r/GeminiAI
  5. What does AI forgetting context actually look like for you? — r/AI_Agents
  6. One prompt two models — r/AI_Agents
  7. Solving image to text captchas — r/AI_Agents
  8. Own 1 dashboard for ChatGPT, Gemini, Claude, and more for only $54.97 — Mashable AI

Get the daily brief of stories like this at 6:30 every morning →