News

The Bug That Could Rewrite Your AI Coding Tool Without You Clicking Anything

English

Security researchers found a way to slip malicious code past four major AI coding agents without a single click, President Trump answered warnings about AI risk by calling them a hoax and standing up an 'AI Force' anyway, Anthropic hired an outside company to watch its own safety work from inside the building, and three Indian shooters opened the Asian Games with a silver that came down to less than a point.

The tuput Editors · · 5 min read

A security researcher found a bug that let an attacker rewrite code inside four of the biggest AI coding assistants on the market, and the victim would not have to click on anything for it to work. In Washington, the president answered months of warnings about AI risk by calling them a hoax, then announced a task force anyway. Anthropic decided the best way to prove its safety work is real is to let an outsider watch it happen. And at the Asian Games, three Indian shooters opened the country’s medal count with a finish so close it needed a second look at the scoreboard.

The bug that needed no click at all

Security firm AIR Security disclosed a vulnerability it calls Plugin4Shell on September 17, and it is a genuinely new kind of problem for the AI industry: the first real supply chain attack aimed at AI coding agents rather than at conventional software. The bug affects four tools people use every day to write code with AI help: Claude Code, OpenAI’s Codex, GitHub Copilot, and Google’s Gemini CLI.

Here is the mechanism. When one of these tools installs a plugin, it is supposed to lock that plugin to a specific, reviewed version using something called SHA pinning, a checksum that should make sure the code you are running is the exact code that got approved. AIR found that none of the four agents actually verified the working files matched that checksum. A plugin author could publish something legitimate, wait for people to install it, then quietly swap in different code later, and the pinning check would wave it through anyway. Because Claude Code and Codex both update installed plugins automatically in the background, a user would never need to approve anything for the malicious version to land.

The response has split four ways. Anthropic patched the flaw in Claude Code version 2.1.179, and OpenAI fixed it in Codex 0.146.0. Microsoft has not shipped a fix for GitHub Copilot. Google went a different direction entirely: rather than patch Gemini CLI, it is deprecating the tool and pointing users toward a newer product called Antigravity instead, which leaves every existing Gemini CLI install exposed with no fix coming.

Trump calls the warnings a hoax, then builds a task force for them anyway

Two days later, on September 19, President Trump addressed the same undercurrent of anxiety from a completely different angle. Posting on Truth Social, he wrote that he was “forming the AI Force, much like I did Space Force, which has been a tremendous SUCCESS, in my First Term,” and said he would soon name an AI “czar,” adding that “only high I.Q. individuals need apply.”

He offered no detail on what the AI Force would actually do, what it would cost, or which part of the government would house it. In the same breath, Trump described concerns that AI could spiral out of human control as another item on his list of media driven hoaxes, even as he acknowledged some of the technology’s risks exist. He said his administration would not “hinder or stifle” the AI industry’s growth and would rely on existing law to deal with harmful conduct rather than write new rules. The announcement follows weeks in which the chief executives of Anthropic, OpenAI, Google DeepMind, Microsoft and xAI have all separately called for the industry to slow down, and it revives a formal AI policy role that has sat empty since David Sacks left the White House’s AI and crypto post in March.

Anthropic hires a company to watch its own safety work up close

On September 18, Anthropic announced it had picked its first “embedded evaluator,” a partner given the kind of access an employee would have to watch how the company actually builds and ships its models, rather than reviewing a finished product from the outside. The partner is Faculty, the AI safety unit of the consulting giant Accenture, and both companies plan to put at least a billion dollars each into the arrangement over five years.

Faculty’s evaluators will be able to observe models during training, sit in on the decisions that shape how they get deployed, and talk directly to Anthropic’s staff, with the work covering red teaming, alignment testing, safeguard checks and incident reporting. Accenture chief executive Julie Sweet said the effort needs “both deep technical expertise and a clear understanding of how AI is used in the real world,” while Faculty chief technology officer Marc Warner said his unit was “founded on the belief that AI should be safe by design, not safe by accident.” Anthropic was careful to note the arrangement does not transfer responsibility. Independent evaluators, the company said, make its safety claims more verifiable, but the safety of its models remains its own job. It is also in talks with the nonprofit evaluator METR about a similar pilot, so this arrangement will not stay exclusive for long.

India’s shooters open the Asian Games with a photo finish

At the Aichi-Nagoya Asian Games, India picked up its first medal of the competition in the women’s 10m air rifle team event, and it very nearly slipped away in the final shots. Sonam Uttam Maskar, Elavenil Valarivan and Vidarsa Vinod combined for a team score of 1898.0, enough for silver but not by much: Japan finished third with 1897.1, just 0.9 points behind India.

China won gold comfortably with 1904.2, a score that broke the qualification world record. Sonam led the Indian trio with 634.1, Elavenil, competing in her third Asian Games, added 633.5, and Vidarsa, shooting in her first Games, contributed 630.4. Vidarsa told reporters afterward that she had “given her best” and was happy with how she shot under the pressure of a debut. For a team sport that is really three individual scorecards added together, it was as tight a start to a medal count as the Games could have offered.

Share
Copied!

Sources & further reading

  1. Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
  2. Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected
  3. Trump says he's creating an AI force and appointing a czar amid concerns over the rapidly developing tech
  4. Trump to form 'AI Force,' name AI czar but rejects calls for constraints
  5. Partnering with Accenture on embedded evaluation
  6. Anthropic selects Accenture as first embedded evaluator to help implement Amodei's slowdown proposal
  7. Sonam, Elavenil, Vidarsa fire India to shooting silver
  8. 'I gave my best, really happy with my performance': Shooter Vidarsa Vinod after India secures silver in women's 10m air rifle team

Researched and written with the help of AI tools and edited for accuracy. Provided for general information and discussion only, not professional advice. See our editorial standards and disclaimer. Spotted an error? Tell us.

#plugin4shell#ai security#claude code#github copilot#gemini cli#openai codex#supply chain attack#donald trump#ai force#ai czar#ai regulation#anthropic#accenture#faculty#ai safety#embedded evaluator#asian games 2026#india shooting#elavenil valarivan#daily roundup

Enjoyed this? Get the next one.

One good read at a time, straight to your inbox. No spam, unsubscribe anytime.

More in News
Anthropic's CEO Told the UN Security Council AI Could Be 'a Risk to Humanity as a Whole'
AI company chiefs told the UN Security Council their own technology could become a risk to humanity, security researchers found malware that lets AI chatbots vote on their own next move, Anthropic cut prices on its newest model, and India collected two more Asian Games medals, one of them a first for the country.
Anthropic Just Revealed How Much of Claude Is Now Built by Claude. The Number Is 26 Percent.
Anthropic put a number on how much of Claude now builds Claude, Microsoft wrote its AI a list of things it can never do, a rival CEO called the industry's safety plan a cartel, and two chip equipment giants backed India's semiconductor ambitions with real money.
Dario Amodei Asked the AI Industry to Slow Down Together. Mark Zuckerberg Said No.
Three of the most powerful people in AI spent the week disagreeing about whether to slow down at all, while two governments bet $300 million on a lab built to never act on its own.
← all articles