- MFA bypass, stolen credentials, identity-based attacks, it’s in the news every week. And for many teams, identity has become the easiest path for attackers.So where are your gaps?Join the Identity Virtual Cybersecurity Summit on September 30th to learn how to detect identity abuse, reduce exposure, and stay ahead of modern attacks.Security Weekly listeners can register for free at https://securityweekly.com/identity using the promo code: CSS26-SW
- InfoSec World is introducing a fresh experience for 2026, with new voices, a new venue, and new topics reflecting the challenges security teams are facing now. Join practitioners and leading professionals from across industries in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.
Doug White
- OpenAI details more cases of AI agents taking unauthorized actions
- Cisco warns of max severity ISE zero-day exploited in attacks
- Settra ransomware group uses MeshAgent RMM in recent attacks
- Flaws in The Events Calendar WordPress plugin enable unauthenticated RCE
- AI coding agents’ 0-click RCE flaw could hand attackers keys to the kingdom
- CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
- Boston police turn to new AI-powered software for social media monitoring. City councilors say they didn’t know. – The Boston Globe
- IV drips used for “detoxification” actually filled with toxins; dozens poisoned
Joshua Marpet
- Plugin4Shell, published today
Air Security found that four AI coding agents, Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI, fetch plugins pinned to a commit hash but never check what they received. Git can read a requested SHA as a branch name, so a repository owner creates a branch whose name looks like the pinned hash, and the agent installs the owner's code while reporting the correct version. Claude Code and Codex are fixed. Copilot has no fix. Google won't patch Gemini CLI and told users to migrate to Antigravity. No CVEs yet.
