Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
2026-07-21T20:52:20Z•e36e8476bc74738d1ed926ac95c7965fde13581e9b8e732cf64ec8b6044f5247
--ignore-scriptsMini-Shai-Huludactive-exploitationai-agent-securityanthropicci-cdcisa-alertclaude-tagconfig-poisoningdeveloper-toolingdevsecopshash-pinningpackage-managementrbacsharepointsonicwallsupply-chain-wormwordpresswp2shellzero-day
What happened
Tenable research highlights multiple high-impact active threats: an emerging class of supply-chain worms (e.g., Mini Shai-Hulud) that poison AI coding-assistant harness/config files to achieve stealthy persistence and lateral spread across developer repos; pre-auth remote code execution in WordPress (wp2shell) via CVE-2026-63030 and CVE-2026-60137 with in-the-wild exploitation and public PoCs; multiple Microsoft SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) under active exploitation (CISA alert) plus two additional SharePoint flaws; SonicWall SMA1000 zero‑y
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- e36e8476bc74738d1ed926ac95c7965fde13581e9b8e732cf64ec8b6044f5247
- Enrichment time
- 2026-07-21T20:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.