Back to Blog

Vulnerability Disclosure

5 articles on this topic.

AI & Agent Security24 September 2026

Plugin4Shell: A Zero-Click RCE in Claude Code, Codex, Copilot and Gemini CLI

A SHA-pinning bypass lets a malicious marketplace plugin silently swap in attacker code across four major AI coding agents — with no click required, and no fix yet for two of them.

ai-securitysupply-chain-securityai-coding-agents
4 min readRead
Web3 & Smart Contract Security28 August 2026

Cosmos EVM Bug Drains Three Chains After Early Public Disclosure

A shared underflow in the Cosmos EVM module let an attacker drain KiiChain, TAC, and Nesa Chain within days of Cosmos Labs publishing the fix — before telling the chains that ran the vulnerable code.

cosmosvulnerability-disclosureweb3-security
4 min readRead
AI Agent Security21 August 2026

11 Bugs in LangChain, LangGraph, CrewAI, AutoGen and Google ADK Expose Agent Internals

A year-long Check Point audit of six major AI agent frameworks found the real risk isn't cleverer prompt injection — it's that injected content can reach trusted orchestration, memory and checkpoint code underneath it.

ai-agent-securityprompt-injectionlanggraph
4 min readRead
Application Security15 July 2026

FIFA's Broken Access Control Bug Left World Cup Streams Open to Hijack

A researcher who signed up as a football agent found himself inside FIFA's internal platforms — because the authorization checks only ran in the browser.

broken-access-controlpenetration-testingvulnerability-disclosure
4 min readRead
Mobile Security7 July 2026

Pixel's 0-Click Chain, Part 3: What Google Learned About Android Patching

Project Zero's own 0-click exploit chain against Pixel 9 took just weeks to build — but fixing the two bugs behind it took over four months and exposed real cracks in how Android's supply chain patches shared components.

androidmobile-security0-click
5 min readRead