Top Tweets for #Plugin4Shell
One of my favorite lessons from #Plugin4Shell has almost nothing to do with AI.
**It's not enough to implement part of a security control. You need to verify the security property you're depending on.**
The affected AI coding agents had a specific Git commit that a plugin was supposed to be pinned to.
They asked Git to check out that commit.
But they didn't verify afterward that the code they actually got WAS that commit.
And I love this example because we make this kind of mistake in application security ALL THE TIME.
Your framework can generate a CSRF token.
Your frontend can send it.
Fantastic!
But if you don't correctly validate it on the server, you haven't actually completed the security control.
Security controls aren't magic. They need to actually enforce the thing we think they're enforcing.
🎥 Plugin4Shell gave us a fascinating example of this, plus a reminder that AI coding plugins are now part of our software supply chain:
https://t.co/wTR6AYUWhR

Plugin4Shell is a zero-click RCE hitting every major AI coding agent via a SHA pinning bypass. Claude Code and Codex are patched; Copilot and Gemini CLI are not.
#Plugin4Shell #AIsupplychain #CodingAgents #ClaudeCode #ZeroClickRCE #SHApinning #AIsecurity
https://t.co/j20QrBXzq3
⚠️ #Plugin4Shell: una falla deja cambiar el código de plugins "pineados" por hash en #ClaudeCode, #Codex, #Copilot y #GeminiCLI sin que el agente lo note. Parcheado en Claude Code 2.1.179+ y Codex 0.146.0+; pero Copilot y Gemini CLI siguen sin fix. 🔒
#Plugin4Shell Lets Repository Owners Swap Pinned #Plugin Code Across Four #AI_Coding_Agents
https://t.co/PGni8YCA0v

AI coding plugins are becoming a new part of our software supply chain.
And this week we got a pretty spectacular demonstration of why that matters. 😬
Security researchers disclosed #Plugin4Shell, a vulnerability affecting several major AI coding agents.
The interesting part to me isn't just the vulnerability.
It's what WE can DO about it. (Spoiler: it's AppSec)
If your coding agent can run plugins or skills, treat them like dependencies:
→ Keep your coding agent updated
→ Be selective about what you install
→ Inventory your plugins and skills
→ Limit what the agent can access
→ Keep production credentials outside its reach
→ Separate coding, CI/build, and production deployment identities
→ Monitor what the agent is actually doing
AI coding plugins aren't something we need to panic about.
They're software.
They're dependencies.
And they're becoming part of our software supply chain.
Fortunately, we already know a LOT about how to secure software supply chains. :-)
🎥 I made a short video about Plugin4Shell and what developers can do to protect themselves:
https://t.co/d9dk3SEDyv

🚨 PLUGIN4SHELL: RCE zero-click en Claude Code, Codex, Copilot y Gemini CLI. Bypass del pinning de plugins → código malicioso llega solo en updates automáticos. Dos agentes aún sin parche.
Actualiza ya o desactiva plugins.
#Plugin4Shell #AIAgents #RCE

Ransomware developer sentenced, SAP flaw under active attack, and new AI agent risks emerge as SecurityWeek also notes urgent fixes for WordPress, TP-Link, and AI coding tools. #SAP #Plugin4Shell #AIAgents
https://t.co/So8DiMI6sA
Plugin4Shell is a zero-click RCE in four AI coding agents, bypassing SHA pinning to swap malicious plugin code during background updates. Two remain unpatched. #Plugin4Shell #ClaudeCode #GitHubCopilot
https://t.co/tQeSoXbgdq
#المحقق_NØØT 🕵️
🚨 تحذير أمني من AIR Security
كشفت الشركة عن #Plugin4Shell وهي ثغرة Zero-Click RCE تمس Claude Code وCodex وCopilot وGemini CLI وقد تسمح باستبدال إضافة موثوقة بكود خبيث دون تفاعل المستخدم
حدّث Claude Code وCodex فورًا
ولا دليل على استغلال فعلي حتى الآن
المصدر: AIR Security
urlAIR Security — Plugin4Shellhttps://t.co/HgSF87O1Cw
Last Seen Hashtags on Sotwe
nsfwtwt
Seen from Chile
algarrobo
Seen from United States
bluewhale
Seen from United States
CDCAfrica
Seen from United States
yağmurşimşek
Seen from Turkey
BaeYoonJung
Seen from United States
teenageee
Seen from United States
脂肪溶解
Seen from United States
البورد_الأمريكي
Seen from United States
逆から読むと
Seen from United States
Most Popular Users

Elon Musk 
@elonmusk
241.7M followers

Barack Obama 
@barackobama
119M followers

Cristiano Ronaldo 
@cristiano
114.3M followers

Donald J. Trump 
@realdonaldtrump
111.9M followers

Narendra Modi 
@narendramodi
107.2M followers

Rihanna 
@rihanna
98.7M followers

NASA 
@nasa
92.4M followers

Justin Bieber 
@justinbieber
91.8M followers

KATY PERRY 
@katyperry
90M followers

Taylor Swift 
@taylorswift13
83.9M followers

Lady Gaga 
@ladygaga
75.4M followers

Virat Kohli 
@imvkohli
73.3M followers

Kim Kardashian 
@kimkardashian
70.9M followers

YouTube 
@youtube
68.8M followers

Neymar Jr 
@neymarjr
66.3M followers

Bill Gates 
@billgates
65.1M followers

Selena Gomez 
@selenagomez
63M followers

The Ellen Show
@theellenshow
62.3M followers

CNN 
@cnn
61.8M followers

X 
@x
60.7M followers






