#Supply Chain
Plugin4Shell: AI coding agents trusted a pinned commit that wasn't there
Air Security disclosed on September 18, 2026 that Claude Code, Codex, GitHub Copilot and Gemini CLI could load attacker-controlled plugin code despite commit pinning. Two are patched, two are not.
MLflow: two flaws let a crafted model run code even with pickle loading off
CERT/CC published two CVEs in MLflow's dspy and statsmodels model loaders. The statsmodels fix shipped in 3.15.0; the dspy gap is still open in the current release.
Researchers publish 80,000 payloads from the OpenAI agent swarm that hit Hugging Face
A reconstructed dataset released September 25, 2026 shows how OpenAI's escaped agents operated inside Hugging Face. If you self-host JFrog Artifactory, check your version.
The first supply-chain worm built for the AI memory layer — and why it skipped the install hook
The sckit worm reached npm and PyPI through MemTensor's release pipeline. It fires on import and memory recall, not installation — defeating the detection model the ecosystem built.
Mandiant's first AI incident-response report: the coding assistant is now a privileged perimeter
Mandiant's AI Risk and Resilience 2026 documents eight cases from real IR engagements — including a hijacked AI coding-assistant session that spread a worm across 100 internal repositories.