Friday, 9 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Papers: Fee Man Utd could receive for wantaway JJ Gabriel revealed› Wilder could feature on the undercard of Fury vs Joshua fight› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Papers: Fee Man Utd could receive for wantaway JJ Gabriel revealed› Wilder could feature on the undercard of Fury vs Joshua fight
Technology

AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom

The Register ·
AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom

A zero-click vulnerability that allows remote code execution affects all of the major AI coding agents - Anthropic’s Claude Code, OpenAI’s Codex, Google's Gemini CLI, Microsoft’s Copilot, and Microsoft-owned GitHub Copilot - and could give attackers full access to every asset and piece of data that the agent can reach, researchers say.

The exploit, dubbed “Plugin4Shell,” is a “first-of-its-kind AI supply-chain attack,” according to threat hunters at Air, a security startup focused on protecting enterprise AI agents.

Instead of targeting the model or agent, Plugin4Shell attacks trusted marketplaces that host plugins for major coding agents.

Such attacks could therefore reach millions of users and machines, the researchers said.

Almost 90 percent of Fortune 500 companies use Copilot, according to Microsoft, which also happens to be one of the two that didn’t ship a patch for the flaw.

“The fix has to ship in the agent, and updating is the only complete mitigation where one exists,” Air researchers Or Nevo, Dor Granat, and Niv Hoffman said in a Thursday report.

The Air team reported the security issue to all four vendors in June, and both Anthropic and OpenAI patched it in Claude Code 2.1.179 and Codex 0.146.0, respectively.

Google has deprecated the Gemini CLI, and therefore told Air it will not patch, so every install remains vulnerable.

Google does, however, suggest users migrate to its newer Antigravity agentic development environment, which is protected from this attack.

Microsoft didn’t fix the flaw in Copilot.

However, a GitHub spokesperson told us the Plugin4Shell attacks do not affect GitHub.

“To prevent abuse of SHAs, GitHub does not allow users to create branch or tag names that resemble commit SHAs,” the spokesperson said.

“This mitigation ensures the reported vulnerability cannot be exploited on GitHub.” The Air researchers said that the GitHub mitigation isn’t sufficient to defeat Plugin4Shell attacks.

This is “because marketplaces can also be hosted in other platforms such as Bitbucket,” the team told The Register.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›