AINewsnow

Plugin4Shell and NIST IR 8587, days apart: what actually authorizes an AI agent’s action?

Two things landed within days of each other, and together they outline a gap I keep running into. Plugin4Shell (AIR Security, disclosed Sept 17) is a zero-click RCE affecting Claude Code, Codex, GitHub Copilot and Gemini CLI. The mechanism is almost boringly simple: marketplaces pin a plugin to a r…

Read the full story at r/AI_Agents ↗

Timeline · 2 reports

  1. 2026-09-20 12:53 · r/artificial
    Plugin4Shell and NIST IR 8587, days apart: what actually authorizes an AI agent’s action?
  2. 2026-09-20 12:32 · r/AI_Agents
    Plugin4Shell and NIST IR 8587, days apart: what actually authorizes an AI agent’s action?

More stories

  1. A zero-click RCE flaw in AI coding agents could have exposed enterprise systems — InfoWorld AI
  2. Getting more accurate results - personalizations — r/ArtificialInteligence
  3. Prompt vs Architecture pt 2 — r/PromptEngineering
  4. AI skills — r/AI_Agents
  5. Pay $39.99 once to put ChatGPT, Claude, Gemini, and more in a single workspace for life — Mashable AI
  6. Gemini self-censors in a harmful, obscure way — r/GeminiAI
  7. I gave 6 different AIs the same 5 questions — r/AI_Agents
  8. What does AI forgetting context actually look like for you? — r/AI_Agents

Get the daily brief of stories like this at 6:30 every morning →