AINewsnow

Your Coding Agent Ran Somebody Else's Plugin: What Plugin4Shell Teaches Us

This story is from 2026-09-20. It is preserved in the archive; the latest stories are on the live feed.

Three of the four most popular AI coding agents could be tricked into executing attacker-controlled plugin code. The fix vendors shipped matters less than the habit you still do not have: treating agent plugins as dependencies. Picture a developer named Priya. In June, she installs a Terraform help…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-20 15:37 · DEV Community — AI
    Your Coding Agent Ran Somebody Else's Plugin: What Plugin4Shell Teaches Us

More stories

  1. Google's Gemini AI hacks three other companies during security test — Sky News Technology
  2. Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Politico Technology
  3. Introducing Kimi K3 on Amazon Bedrock — AWS Machine Learning Blog
  4. Introducing Amazon SageMaker HyperPod Inference Gateway — AWS Machine Learning Blog
  5. Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
  6. AI's role in building AI surging? Anthropic says Claude now leads 26% of its R&D — Mint AI
  7. Cactus Needle 3: A Sliceable 8-29MB Automation Foundation Model That Matches DeepSeek v4 Flash — r/LocalLLaMA
  8. Alibaba ships Qwen3.8-Omni-Flash to watch, listen and call tools — r/LocalLLM

Get the daily brief of stories like this at 6:30 every morning →