Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 20:13:24 EDT

Explore

PostsPeople
LatestRanked
@simsus.social.tchncs.de.ap.brid.gySep 23, 2026, 6:00 AM

Kritische Lücke bei #ClaudeCode, #OpenAICodex, #GitHubCopilot und #GeminiCLI | Developer https://www.heise.de/news/Kritische-Luecke-bei-Claude-Code-OpenAI-Codex-GitHub-Copilot-und-Gemini-CLI-11459862.html #ArtificialIntelligence #AI #AIagent #AIagents #Patchday #Plugin4Shell

@shehackspurple.bsky.socialSep 21, 2026, 10:16 PM

One of my favorite lessons from #Plugin4Shell has almost nothing to do with AI.

**It's not enough to implement part of a security control. You need to verify the security property you're depending on.**
1/4

A smiling woman with long brown hair points toward the camera while seated in front of white shelves filled with books and security-themed items, with a fuzzy microphone in the foreground. On-screen text reads “AI Coding Plugins Are Part of Your Software Supply Chain” and “Plugin4Shell.”
@thedailytechfeed.comSep 21, 2026, 2:43 PM

Big threats: Cisco ISE zero-day, Plugin4Shell RCE, Brevo ClickFix takeover. #AI #Plugin4Shell #Security #CyberThreats #Malware #ZeroDay thedailytechfeed.com/top-cyber-th...

@rtfclmgzn.bsky.socialSep 21, 2026, 1:08 PM

Plugin4Shell: a Git branch named after a commit hash can impersonate it. Four AI coding agents' plugin-pinning checks fall for it. 2 of 4 vendors patched so far.

https://rtfclmgzn.com/?utm_source=bluesky&utm_medium=social&utm_campaign=autopost#
#AppSec #Plugin4Shell #SHA

@pulseofnations.lolSep 21, 2026, 2:51 AM

A Git pinning bypass lets a repo owner swap malicious code into Claude Code, Codex, Copilot and Gemini CLI with no click. Two vendors patched, two did not.

#ClaudeCode #Codex #Copilot #GeminiCli #Plugin4shell #Security #SupplyChain

@securityonline.bsky.socialSep 21, 2026, 1:02 AM

Plugin4Shell is a zero-click RCE hitting every major AI coding agent via a SHA pinning bypass. Claude Code and Codex are patched; Copilot and Gemini CLI are not.

#Plugin4Shell #AIsupplychain #CodingAgents #ClaudeCode #ZeroClickRCE #SHApinning #AIsecurity

@pulseofnations.lolSep 20, 2026, 6:26 AM

The Plugin4Shell zero-click flaw let a plugin repository owner serve malicious code under a reviewed commit hash. Claude Code and Codex patched it. Copilot and Gemini CLI did not.

#AiSecurity #ClaudeCode #Codex #CodingAgents #Copilot #GeminiCli #Plugin4shell #SupplyChain

@psoheil.bsky.socialSep 19, 2026, 2:46 PM

A new AI supply chain vulnerability called #Plugin4Shell highlights a serious weakness in how AI coding agents handle plugins.

#Cybersecurity #AISecurity #ArtificialIntelligence #SupplyChainSecurity #DevSecOps #GitHub #ClaudeCode #OpenAI #Copilot #SoftwareSecurity

thehackernews.com/2026/09/plug...

@cerberusit.bsky.socialSep 19, 2026, 7:04 AM

AI coding agents check commit hashes yet happily download swapped malicious plugin code anyway. Splendid work from the tools supposed to write our software. #Plugin4Shell #PatchPanic

@shehackspurple.bsky.socialSep 18, 2026, 11:09 PM

AI coding plugins are becoming a new part of our software supply chain. And this week we got a pretty spectacular demonstration of why that matters. 😬 Security researchers disclosed #Plugin4Shell, a vulnerability affecting several major AI coding agents. 1/5

A smiling woman with long brown hair points toward the camera while seated in front of white shelves filled with books and security-themed items, with a fuzzy microphone in the foreground. On-screen text reads “AI Coding Plugins Are Part of Your Software Supply Chain” and “Plugin4Shell.”
@hendryadrian.bsky.socialSep 18, 2026, 5:15 PM

Ransomware developer sentenced, SAP flaw under active attack, and new AI agent risks emerge as SecurityWeek also notes urgent fixes for WordPress, TP-Link, and AI coding tools. #SAP #Plugin4Shell #AIAgents

@hendryadrian.bsky.socialSep 18, 2026, 2:00 PM

Plugin4Shell is a zero-click RCE in four AI coding agents, bypassing SHA pinning to swap malicious plugin code during background updates. Two remain unpatched. #Plugin4Shell #ClaudeCode #GitHubCopilot

@thedailytechfeed.comSep 18, 2026, 11:23 AM

Plugin4Shell lets repo owners swap pinned plugin code in AI agents—even with version locks. Some agents fixed, others still exposed. #Plugin4Shell #AI #Security #Vulnerability #DevOps https://thedailytechfeed.com/plugin4shell-vulnerability-allows-pinned-plugins-to-be-swapped-in-ai-agents/