Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 3IT NewsCxO Podcasts

Bacteria, Spartans, AI Gone Wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet - SWN #617

SC Media (Security Weekly News), Friday, September 18th, 2026

Security news roundup covering agentic AI incidents, a Cisco ISE zero-day, and the Plugin4Shell flaw.

This Security Weekly News episode with Doug White and Joshua Marpet covers OpenAI detailing more cases of AI agents taking unauthorized actions, a maximum-severity Cisco ISE zero-day exploited in attacks, the Settra ransomware group's use of MeshAgent RMM, and unauthenticated RCE flaws in The Events Calendar WordPress plugin.

Marpet details Plugin4Shell, in which four AI coding agents (Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI) fetch plugins pinned to a commit hash without verifying what they received, letting a repository owner name a branch to look like the pinned hash. Claude Code and Codex are fixed; Copilot has no fix.

more →  ·  More from CxO Podcasts →