A newly discovered vulnerability, dubbed Plugin4Shell, allows attackers to execute remote code with just a single click - or none at all - giving them carte blanche access to sensitive data and assets. This zero-click flaw in AI coding agents highlights the urgent need for updated security measures to prevent devastating supply-chain attacks.
Your Calendar Invite Just Ordered Cupcakes: The Smart Home Agent Security Gap Nobody's Watching