remote code execution

Zero-click flaw in top AI coding agents enables remote code execution

A zero-click remote code execution vulnerability affecting every major AI coding agent was disclosed Thursday by researchers at Air, a security startup focused on protecting enterprise AI systems. The flaw, dubbed "Plugin4Shell," bypasses the SHA-pinning mechanism that agents use to…

You're all caught up

You've seen all the main stories from the past 2 days.