
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

Security researchers disclosed Plugin4Shell, a zero-click supply-chain flaw in Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI that redirects git-pinned plugin installs to malicious code.
Summary
Three vendors patched; GitHub Copilot has not given a timeline.
This is a brief wire summary — the full story (linked below) has the complete details.
KazaSec's take
A newly disclosed vulnerability is only a real risk to your organization once it's confirmed present and exploitable in your own environment — not every CVE applies equally to every network. Knowing the difference is exactly what a proper vulnerability assessment is for.
Coverage details
We've archived 417 other articles touching the same topic (supply chain attack, microsoft copilot, github) — see the full security news archive.
Related security advisories
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.