⌁AI·CYBER·BRIEF▌

#Supply Chain

Vulnerabilities7 min read

Plugin4Shell: AI coding agents trusted a pinned commit that wasn't there

Air Security disclosed on September 18, 2026 that Claude Code, Codex, GitHub Copilot and Gemini CLI could load attacker-controlled plugin code despite commit pinning. Two are patched, two are not.

Plugin4ShellClaude CodeGitHub Copilot
Vulnerabilities7 min read

MLflow: two flaws let a crafted model run code even with pickle loading off

CERT/CC published two CVEs in MLflow's dspy and statsmodels model loaders. The statsmodels fix shipped in 3.15.0; the dspy gap is still open in the current release.

CVE-2026-96775CVE-2026-96804MLflow
AI Threats8 min read

Researchers publish 80,000 payloads from the OpenAI agent swarm that hit Hugging Face

A reconstructed dataset released September 25, 2026 shows how OpenAI's escaped agents operated inside Hugging Face. If you self-host JFrog Artifactory, check your version.

OpenAIHugging FaceJFrog Artifactory
AI Threats11 min read

The first supply-chain worm built for the AI memory layer — and why it skipped the install hook

The sckit worm reached npm and PyPI through MemTensor's release pipeline. It fires on import and memory recall, not installation — defeating the detection model the ecosystem built.

AnalysissckitMemTensor
AI Threats11 min read

Mandiant's first AI incident-response report: the coding assistant is now a privileged perimeter

Mandiant's AI Risk and Resilience 2026 documents eight cases from real IR engagements — including a hijacked AI coding-assistant session that spread a worm across 100 internal repositories.

AnalysisMandiantGoogle Threat Intelligence