Plugin4Shell: A Zero-Click RCE in Claude Code, Codex, Copilot and Gemini CLI
A SHA-pinning bypass lets a malicious marketplace plugin silently swap in attacker code across four major AI coding agents — with no click required, and no fix yet for two of them.
Cosmos EVM Bug Drains Three Chains After Early Public Disclosure
A shared underflow in the Cosmos EVM module let an attacker drain KiiChain, TAC, and Nesa Chain within days of Cosmos Labs publishing the fix — before telling the chains that ran the vulnerable code.
11 Bugs in LangChain, LangGraph, CrewAI, AutoGen and Google ADK Expose Agent Internals
A year-long Check Point audit of six major AI agent frameworks found the real risk isn't cleverer prompt injection — it's that injected content can reach trusted orchestration, memory and checkpoint code underneath it.
FIFA's Broken Access Control Bug Left World Cup Streams Open to Hijack
A researcher who signed up as a football agent found himself inside FIFA's internal platforms — because the authorization checks only ran in the browser.
Pixel's 0-Click Chain, Part 3: What Google Learned About Android Patching
Project Zero's own 0-click exploit chain against Pixel 9 took just weeks to build — but fixing the two bugs behind it took over four months and exposed real cracks in how Android's supply chain patches shared components.