▶ VIDEO Security Weekly - A CRA Resource

The AI Vulnerability That Isn’t AI

AIR Security has disclosed a critical vulnerability named "plugin for shell" that compromises plugin installers across Cloud Code, OpenAI Codex, GitHub Copilot, and Gemini CLI. This flaw allows attackers to trick tools into installing malicious software instead of the intended reviewed version, bypassing all AI model safeguards. The issue represents a standard software engineering error rather than a novel AI-specific attack like prompt injection or model manipulation. Consequently, the vulnerability exists in the underlying installation mechanisms of these four major AI products.

▶ VIDEO David Bombal

How He Infiltrated LockBit

A cybersecurity researcher infiltrated the LockBit ransomware gang by creating fake personas and engaging directly with operators on the dark web. After six months of infiltration, the researcher published a report bearing his real name, prompting the group to display his face on a new avatar as a warning. Despite the initial threat, the gang eventually identified him as a favorite researcher and engaged in over a year of communication. This interaction revealed the human cost of the work, including severe mental health impacts from monitoring attacks on hospitals and children. The situation escalated following a legal indictment, shifting the dynamic from professional engagement to active hostility.