Bots with good manners are better at fooling people on social media
2026-09-19T14:51:40Z•f509a45e498d0f4ea9feb225128f939f9f4c43058a37b755ab1ad1ad1126cd18
AI coding agentsAI securityAndroid securityGitHubIoT securityMCPWordPress securityabandoned applicationsbot detectioncloud resiliencecredential exposuredata losshardcoded secretsidentity fraudincident responseplugin marketplaceremote code executionsocial engineeringsoftware supply chainvulnerable dependencieszero-click RCE
What happened
Help Net Security coverage highlights a zero-click remote code execution vulnerability affecting four major AI coding agents through marketplace plugins, with two reportedly still unpatched. Additional reporting covers hardcoded credentials in publicly exposed MCP configuration files, abandoned IoT applications retaining vulnerable dependencies and transmitting data to broken servers, fraudulent hires obtaining enterprise credentials, AI-agent governance, social-media bot deception, Android security-state tooling, WordPress recovery preparedness, and permanent AWS data loss following regionali
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- f509a45e498d0f4ea9feb225128f939f9f4c43058a37b755ab1ad1ad1126cd18
- Enrichment time
- 2026-09-19T14:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.