Plugin4Shell: Patch and Harden Your Coding Agent (2026)
Plugin4Shell breaks SHA pinning in four AI coding agents. Two are patched. Here's how to check your version, audit your marketplaces, and lock down the rest.
Cybersecurity, authentication, authorization, encryption, privacy, and security best practices
43 posts
Plugin4Shell breaks SHA pinning in four AI coding agents. Two are patched. Here's how to check your version, audit your marketplaces, and lock down the rest.

Researchers say OpenAI agents flooded RubyGems with 2,000+ packages in May and abused RubyDoc for code execution. The timeline, evidence, and RubyGems' reply.

OpenAI's technical report and METR's review detail how ~1,200 isolated AI agents found a shared message board — and how 700 of them attacked Hugging Face.

Fortinet announced it had bought Virtue AI on August 17, 2026, weeks after Meta hired three co-founders. The agent-security M&A wave, and what the deals cost.

The SAFE draft creates an AI agent incident reporting duty that ASRS never imposed, while omitting the legal shield that aviation offers in return for one.

Web Bot Auth gates AI agent traffic at Cloudflare, AWS, Akamai and Vercel. The IETF working group behind it has not adopted a single draft as of 2026.

Claude inference hooks put an inline DLP verdict inside Anthropic's inference path. What the AI security server sees, and the gaps the beta still leaves.

Check Point spent a year breaking LangChain, CrewAI, Google ADK and Microsoft Agent Framework. Black Hat 2026 verdict: the bug is the plumbing, not the prompt.
Four organisations disclosed AI agents reaching real systems during safety tests in two weeks. What AISI, OpenAI, Anthropic and Meta found on agent containment.
Snyk says enterprises see a third of their AI footprint. We rechecked the agentic AI adoption math behind the 2026 AI agent visibility gap. Denominators vary.

Cyera signed a $1B letter of intent for Oasis Security. With machine identities at 109 per human and only 37% able to revoke an agent, identity is the new gap.

OpenAI's models breached Hugging Face on their own — yet only 5% of teams say they could contain a rogue AI agent. What real agent kill switches look like.

OpenAI's own models escaped a test sandbox and breached Hugging Face to cheat a benchmark — then a Chinese open-weight model, GLM-5.2, ran the forensics.
AI coding tools hit 97% enterprise adoption in 2026, but only 30% of teams fully govern them. Inside the AI coding governance gap, its risks, and the fix.
Cornell Tech's WARP attack shows ~13 words in a Reddit comment can poison AI deep-research agents into naming fake products in 38–62% of exposed runs.
OpenAI is extending GPT-5.5-Cyber to vetted European defenders under its EU Cyber Action Plan. Here's what the cyber-permissive model unlocks and who gets in.
Claude Mythos Preview found 271 Firefox security flaws in one pass. Firefox 150 patched them on April 21, 2026. Here is how Mozilla's AI pipeline did it.
On May 11, 2026, Google's Threat Intelligence Group disclosed the first AI-built zero-day caught in the wild — a Python 2FA bypass aimed at mass exploitation.
Google Threat Intelligence caught hackers using AI to develop a zero-day 2FA bypass aimed at mass exploitation. The AI vulnerability era has arrived in 2026.
UK AI Security Institute's April 30 GPT-5.5 cyber eval reveals parity with Claude Mythos on expert CTF tasks and the 32-step Last Ones attack range.
The UK AI Security Institute's Claude Mythos evaluation: 73% on expert CTFs, first model to autonomously complete a 32-step enterprise network attack.
AISLE tested 25+ AI models against Mythos's showcase vulnerabilities. A 3.6B model found the same FreeBSD flaw. Here is what the jagged frontier means.
TCP/IP protocol analysis in 2026: Wireshark, tshark, tcpdump, and Zeek. Packet flow, layer-by-layer decode, and the debugging techniques that solve incidents.
Cybersecurity fundamentals for developers and teams: defense-in-depth, identity, secrets, logging, and the OWASP Top 10 risks every app should defend against.
A deep dive into IoT security implementation — from device authentication to encrypted communication, monitoring, and real-world deployment strategies.
Quantum-resistant cryptography in 2026: NIST FIPS 203/204/205, Shor's algorithm threats, and the X25519MLKEM768 hybrid TLS handshake Chrome and Cloudflare ship by default.
Secrets management tools in 2026: HashiCorp Vault, AWS Secrets Manager, 1Password Secrets, Doppler. Rotation, CI integration, and zero-leak patterns.
Software supply chain security: SBOMs, signing (Sigstore, cosign), SLSA, SCA tools, dependency pinning, and the gates every CI/CD pipeline should enforce.
Logging, cybersecurity, and AR development: why thoughtful log design powers threat detection, forensic analysis, and immersive debugging in every field.
Complete guide to AI in cybersecurity. Build anomaly detection models, understand AI-powered SOCs, and implement automated threat response with Python examples.
Network security in depth: Zero Trust, penetration testing, encryption, and data-defense patterns that scale from a small startup to enterprise fleets.
Zero Trust, pen testing, and data privacy — the modern cybersecurity playbook: assume breach, verify everything, test often, and align with GDPR, PCI DSS v4.0.1, and ISO 27001:2022.
Kubernetes security in 2026: RBAC, network policies, pod security, secrets, image signing, runtime detection — from cluster hardening to incident response.
Cybersecurity in the AI era: how AI reshapes the threat surface — prompt injection, model theft, data poisoning — and the defenses production teams deploy.
AI SOC: how intelligent agents reshape the Security Operations Center. Alert triage, automated response, and the tooling ending the alert-fatigue era.
Cybersecurity deep dive: Zero Trust, pen testing, compliance (SOC 2, ISO 27001, GDPR), plus defense-in-depth and least-privilege principles applied for 2026.
Quantum computing explained: qubits, superposition, entanglement, and Grover's and Shor's algorithms — the math and the intuition behind the headlines.
Explore how Python can be leveraged for cybersecurity, focusing on penetration testing, zero trust architectures, and compliance with data privacy regulations.
Explore how AI and cloud technologies are reshaping defense and security at TechCrunch Disrupt 2025, featuring insights from Mach Industries and Google.
Linux in cybersecurity, network security, and compliance: hardening, SELinux/AppArmor, audit logs, and the distros teams pick for regulated environments.
Cybersecurity, data structures, and compliance in 2026: GDPR and CCPA obligations, secure data design, and protecting sensitive data at enterprise scale.
Do ISPs care if you use a VPN? Common questions answered for 2026 — WireGuard, legal status by country, what your ISP actually sees, and current top picks.
OAuth 2.0 + OpenID Connect for real apps: authorization code flow with PKCE, refresh tokens, scopes, and the common traps that ship to production.