chiprook
← Security
SecuritySeptember 22, 2026, 15:51

Plugin4Shell: zero-click RCE hits Claude Code, Codex, Copilot and Gemini CLI

AIR Security disclosed Plugin4Shell, a flaw that lets attackers silently swap SHA-pinned plugin code in four popular AI coding agents. Anthropic and OpenAI have shipped patches, Microsoft has not fixed Copilot, and Google is discontinuing Gemini CLI instead.

Plugin4Shell: zero-click RCE hits Claude Code, Codex, Copilot and Gemini CLI
#Anthropic#OpenAI#Microsoft#Google
Read next
Security

Gartner: 41% of CISOs Hit by Deepfakes in Audio Calls This Year

Security

Gigabyte patches Control Center flaws that exposed kernel to attackers

Security

Scammers sell fake AI subscriptions up to $2,000 a year via genuine Google sign-in

Security

CERT-In flags 14 ISC BIND flaws enabling cache poisoning and zone injection