Threat Brief — 2026-09-18 — Plugin swap, max-severity AI flaw, and a ghost CDN
Executive summary: A supply-chain-style flaw dubbed "Plugin4Shell" lets repository owners silently swap pinned plugin code inside four major AI coding assistants (Claude Code, Codex, Copilot, Gemini), enabling zero-click RCE after a plugin has been installed and reviewed. Microsoft patched a CVSS 10.0 privilege-escalation flaw in Azure AI Foundry (CVE-2026-85889), and a ransomware campaign labelled "TargetZimbra" is actively exploiting a known KEV-listed Zimbra SMTP flaw to encrypt email servers without authentication. An abandoned CDN domain was re-registered while thousands of sites still load assets from it, creating a mass supply-chain risk.
Top items
- Azure AI Foundry max-severity patch (CVE-2026-85889, CVSS 10.0). Microsoft released fixes for a privilege-escalation flaw in Azure AI Foundry that could be exploited without authorization. Microsoft states no customer action is required, implying server-side remediation. This continues coverage from 2026-09-17 when the flaw was first reported as part of a broader Azure AI Foundry SSRF and missing-auth patch batch; the new detail is the confirmed CVSS 10.0 rating. (src: The Hacker News)
- "Plugin4Shell" — zero-click RCE across four AI coding agents. A flaw in Claude Code, Codex, Copilot, and Gemini lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious version, even when the agent pinned that plugin to a specific reviewed commit. The attack is zero-click from the user's perspective: a previously trusted plugin turns malicious after installation. This continues the story first reported today, 2026-09-18, by SecurityLab; The Hacker News now provides the "Plugin4Shell" label and confirms it spans all four agents. (src: The Hacker News · SecurityLab)
- TargetZimbra ransomware campaign exploits KEV-listed CVE-2026-73570KEV. A campaign called "TargetZimbra" is encrypting email servers with a single unauthenticated SMTP request using CVE-2026-73570KEV, a flaw already listed in CISA's Known Exploited Vulnerabilities catalog. The vulnerability allows pre-authentication remote code execution via a crafted SMTP request. This is a development in the Zimbra exploitation story first reported 2026-08-20 by BleepingComputer; the new element is a named ransomware campaign weaponising the flaw. (src: SecurityLab)
- AWS AgentCore Harness default configs expose credentials to prompt injection. Unit 42 research shows that default configurations in AWS AgentCore Harness allow prompt-injection attacks to exfiltrate stored credentials, placing agent identity and secrets at risk. The analysis includes remediation steps for securing agent deployments. (src: Unit 42)
- Abandoned CDN domain re-registered, thousands of sites still call it. An expired CDN domain was re-registered in July 2025 after the CDN was wound down years earlier. Thousands of websites still load assets from the domain, giving its new owner the ability to serve arbitrary JavaScript or other content to every visitor. This is a dormant supply-chain risk with no obvious victim-side fix short of removing the stale references. (src: The Hacker News)
- WeaselBiscuit stealer spreads via 13 npm packages. A previously undocumented JavaScript stealer called WeaselBiscuit was found delivered through 13 npm packages, targeting Chrome extension storage to harvest sensitive data. The malware cluster exhibits information-stealing capabilities consistent with the recent trend of npm-based supply-chain attacks. (src: The Hacker News)
Themes
AI agent attack surface is expanding rapidly. Three of today's top items target AI infrastructure: Plugin4Shell compromises the plugin trust model across four coding assistants, AWS AgentCore exposes credentials to prompt injection, and Azure AI Foundry received a CVSS 10.0 patch. The pattern is consistent — default configurations and trust assumptions in AI agent ecosystems are creating new privilege-escalation and code-execution paths that traditional application security models do not cover.
Supply-chain persistence through abandoned infrastructure. The re-registered CDN domain and the npm-based WeaselBiscuit campaign illustrate the same underlying problem: dormant or lightly maintained dependencies remain callable long after their owners lose interest, and attackers exploit that persistence cheaply.
