Plugin4Shell: zero-click RCE in the plugin systems of all four major coding agents
Air Security disclosed Plugin4Shell, a zero-click remote code execution vulnerability affecting Claude Code, Codex, GitHub Copilot, and Gemini CLI. The attack ignores the model and abuses plugin marketplaces plus auto-update: agents pin plugins to a reviewed git commit hash; the attacker ships a benign plugin, waits for the marketplace to pin a new hash, then creates a branch whose name is literally that hash string, pointing at malicious code. When a name matches both a branch and a commit, git resolves to the branch, so the next background update checks out the attacker’s code with no user interaction at all. The researchers found the flaw in May and disclosed it to all four vendors in June: Claude Code (2.1.179) and Codex (0.146.0) are patched, Google says Gemini CLI is deprecated and will not be fixed, Microsoft has shipped no patch, and GitHub disputes that Copilot is affected (see The Register). Every agent checked which hash it pinned; none checked where the checkout actually landed. Marketplace review happens at listing time, and neither that review nor the SHA pin can stop a swap that comes later. If you have plugins installed, verify your agent version today.
Unsealed filings: a Microsoft exec privately called AI scraping possibly “the largest theft of labor in human history”
On September 17 the court unsealed unredacted summary judgment motions in The New York Times’ copyright case against Microsoft and OpenAI. As quoted in the Times’ brief, Brent Hecht, Microsoft’s Director of Applied Science, wrote in a January 2023 internal memo that OpenAI’s scraping of news content was “an astonishing theft of unprecedented proportions” and possibly “the largest theft of labor in human history.” The filings also state that OpenAI’s training data contained more than 91,000 copies of works from the three news plaintiffs, that one Common Crawl-derived dataset held over 2 million documents from nytimes.com alone, and that when an OpenAI researcher mentioned a “hack to get around nytimes paywall,” Greg Brockman replied “ah nice.” At summary judgment the court has to weigh fair use head-on, and how the defendants described their own conduct at the time may carry more weight than any expert report. (See the CourtListener docket.)
The UN and Google launch the UN System Data Commons, built for AI agents
Google and the UN relaunched data.un.org on September 17 as the UN System Data Commons, built on Google’s open-source Data Commons: 26 UN entities have committed, data from about 20 is live at launch, and the platform natively supports the Model Context Protocol (MCP), the open standard that lets AI applications query external data sources directly, with attribution back to the original source. The motivation is blunt. In an unpublished UNICEF working paper reported by TechCrunch, six mainstream models averaged 21.2% accuracy across more than 133,000 answers about global development indicators; about three in five answers produced no usable number, and models that did give a number returned the same one only about half the time when asked again two days later. Rather than hoping models memorize the figures, the UN is turning authoritative data into an interface agents can query, with a target of 80% of the UN system’s statistical datasets on the platform by 2027. (Also see TechCrunch.)
Base Labs, Hugging Face, and Goodfire set out to write a safety standard for open-weight models
Base Labs, the research group that inference provider Baseten spun up this year, announced a partnership with Hugging Face and interpretability startup Goodfire to develop a “safety infrastructure standard” for open-weight models: safety methods built into how models are trained and deployed rather than bolted on afterward. Base Labs contributes training and monitoring methods, Goodfire the interpretability tooling, Hugging Face the hosting and distribution (the announcement exists only as an X post). The context: Hugging Face currently lists over 6,000 “abliterated” models, open models re-uploaded after the community strips out their refusal behavior at low cost. Closed-lab safety stacks don’t apply to a world where weights are public and anyone can modify them, so this parallel track fills a real gap; the three companies have disclosed no technical details yet, though, so judge it by what ships. (Also see TechCrunch.)
Pushback on Amodei’s slow-down essay: safety, or control?
TechCrunch rounds up this week’s reactions to Dario Amodei’s roughly 4,000-word essay arguing frontier AI development should slow down. The sharpest response comes from Cohere CEO Aidan Gomez: “AI needs guardrails. That is not the dispute and never has been. The dispute is over who writes them, who gets to participate and whose interests the rules are protecting.” China’s foreign ministry spokesperson accused the US side of “fearmongering.” The piece is synthesis rather than new reporting, but it cites The Information’s report that OpenAI, Anthropic, and other major labs are organizing an industry standards body; as long as safety arguments travel together with export controls and standard-setting, the question of whether this is a safety agenda or a competitive strategy will keep coming back.
Huawei pulls the Ascend 960DT forward to Q1 2027
At Huawei Connect 2026 in Shanghai, Huawei said its training chip Ascend 960DT will be ready in Q1 2027, three quarters ahead of its published roadmap, with the inference-oriented 960PR one quarter early in Q3 2027 and the Ascend 970 and 980 slotted for 2028 and 2029 on a yearly cadence (roadmap details also in TrendForce). The system-side numbers moved the other way: the Atlas 960 SuperPoD, previously pitched as scaling to 15,488 cards, was shown this week as a 4,096-card system. An aggressive chip schedule paired with a smaller flagship system reads like capacity constraints forcing a choice to ship silicon first; for Chinese buyers, the date they can actually buy moves up while the promise of very large-scale interconnect gets trimmed. (Also see TechCrunch, which carries Huawei’s spokesperson confirmation.)
Crusoe raises a $3.9B Series F at a $30.9B valuation
Data center and AI cloud company Crusoe announced a $3.9 billion Series F at a $30.9 billion post-money valuation, roughly triple its $10 billion Series E mark from last October; Atreides, Mubadala Capital, and Valor co-led, with NVIDIA, Founders Fund, and Qatar Investment Authority among the backers. The money goes to both ends of the size spectrum: hyperscale campuses like the Abilene, Texas site it built for OpenAI, and Crusoe Spark, truck-transportable modular data centers the company says cut field construction from years to weeks. Crusoe reports $140 billion in total contracted value; customers include OpenAI, Meta, Microsoft, and Jane Street, which signed a $13 billion five-year contract. The fast-rising valuation rests on the visibility of those long contracts; the risk to watch is how concentrated they are in a handful of very large buyers. (Also see TechCrunch.)
Instinct and Meta’s Muse both put their agents on the phone
Instinct, the consumer AI assistant whose Series B last month brought its total funding to $350 million at a $2.5 billion valuation, launched “Concierge”: its agent now makes real phone calls, booking restaurants that don’t take online reservations, getting you onto a dentist’s cancellation list, or arguing with customer service (announced only on X). The same day, Meta expanded its Muse agent’s beta to include outbound calls to US businesses, also announced only via a Meta staffer’s X post. Neither announcement says whether the agent discloses it is an AI on the call, or describes call-specific abuse safeguards; I couldn’t find either company addressing the question elsewhere. Agents are stepping out of the screen and into the phone network, and the business answering has no way to tell whether a caller is a person, a delegated agent, or an automated scam. The closest existing rule in the US is the FCC’s 2024 ruling that AI-generated voices count as “artificial” under the Telephone Consumer Protection Act, the law governing robocalls, which requires prior consent for such calls to consumers; that framework was written for mass robocalls, and how it applies to one person’s agent phoning a restaurant is untested. (Also see TechCrunch.)
Research radar
LimiX-2: tabular in-context learning as mechanism modeling, not target prediction
From Stable AI and Peng Cui’s group at Tsinghua. Tabular foundation models in the TabPFN line learn to predict a query row’s target from in-context examples; LimiX-2’s “contextual mechanism network” instead learns a context-conditioned joint model: pretraining masks random feature columns of query rows and asks the model to reconstruct them from the remaining features plus the context, on fully synthetic data generated by structural causal models. The 406M-parameter model leads three tabular benchmarks in overall Elo, and its feature attention recovers causal skeletons (mean F1 near 0.80) as a byproduct. Worth reading if you work on tabular ML or causal discovery.
ScienceIDE: turning scientific codebases into trainable agent environments
The team converts 27 scientific codebases into 64 executable environments with 2,812 tasks (mostly code repair) and 1,076 executable checks; pass criteria are numerical tolerances or physical invariants such as conserved quantities, and a domain expert reviews each environment’s decomposition. The problem statement is a good one: decades of scientific knowledge is locked in research code and hard to turn into verifiable training signal. SFT plus RL on these environments roughly doubles repair success in a few individual environments and transfers to general code benchmarks; frontier models top out around 67% on the hard subset, so there is headroom. Relevant if you build research agents or design RL environments.
Value flattening: a systematic failure of PPO critics in LLM training
From Shanghai Jiao Tong University, Shanghai AI Laboratory, and others. Estimating true state values with Monte Carlo continuations, the authors show values swing sharply within a response while the critic’s predictions stay nearly flat, and they trace this to the dense token-level value loss, which carries an implicit variance penalty that pushes predictions toward flatness. The fix, SP³O, applies the value loss only at a few separated anchor positions (around 0.3, 0.6, and 0.9 of the response); on Qwen3-4B-Base it beats standard PPO by about 8 points on math reasoning averages. If you run PPO pipelines for LLMs, this is a concrete failure mode you can check for in your own critic.
Today in one line: marketplace review happens at listing time; the attack can come any time after. Go check your coding agent’s version today.