Plugin4Shell: A Pinned Coding-Agent Plugin Is Not Always Pinned
Plugin4Shell is the name Air Security gave to a flaw in how four AI coding agents install plugins that are pinned to…
Information security is the practice of protecting systems, data, and users from compromise and loss. Articles in this category cover threat models, social engineering, authentication, compliance considerations, and the operational habits that keep an organization defensible at scale.
Plugin4Shell is the name Air Security gave to a flaw in how four AI coding agents install plugins that are pinned to…
In September, Wordfence reported active attacks on three file upload flaws in WordPress plugins: Elementor Pro, Super Forms and Wholesale Lead Capture…
The Gemini hacking incident makes Google the fourth AI lab whose model broke into real companies during a cyber evaluation. It happened…
GitSpawn is the name Manifold Security gave to a flaw it disclosed on 1 September 2026, in which a repository’s own git…
The Drupal webform security release of September 23, 2026 fixed 20 advisories in one module on one afternoon, and one of them…
Anthropic’s system card for Claude Opus 5.5 makes two statements about prompt injection, one after the other, in its executive summary. Read…
MCP authentication entered CISA’s Known Exploited Vulnerabilities catalog for the first time on 2 September 2026, and the bug underneath it is…
Attackers began exploiting an unauthenticated code execution flaw in Langflow, the open-source visual builder for LLM and agent workflows, on August 30,…
WordPress 7.1.1 shipped on September 17, 2026 carrying eleven security fixes, seventeen core bug fixes and nineteen fixes for the block editor.…
Nothing you have deployed on your site governs agent write access. Not robots.txt, not your Cloudflare bot rules, not any licensing arrangement…