Skip to content
Tienta, Inc.

Issue No. 7 ·

A zero-click flaw hits four AI coding agents, the 10th Circuit proposes an AI filing rule, and IRS cybersecurity fails again

A zero-click vulnerability called Plugin4Shell lets whoever controls a plugin's repository swap in malicious code across Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI, with two of the four still unpatched. The 10th Circuit proposes a rule requiring lawyers to certify human review of AI-assisted filings, a government watchdog finds IRS cybersecurity ineffective for the second year running, and OpenAI, Anthropic, and DeepSeek are set to brief the UN Security Council on AI risk this week.

Industry sections: Legal Practices · Financial & CFO Firms

This briefing is informational only and does not constitute legal or financial advice. It reports on public industry developments and does not reference any Tienta client.

This Week in AI

Platform Roundup

  • Anthropic (Claude Code): Patched in version 2.1.179 as part of the cross-industry Plugin4Shell disclosure. See below.
  • OpenAI (Codex): Patched in version 0.146.0, same disclosure.
  • Google (Gemini CLI): Retired the product rather than patching it. Anyone still running it stays exposed, with no fix coming.
  • Microsoft (Copilot): No patch shipped as of the disclosure.

Beyond the Platforms

A single flaw, disclosed once, hit four different AI coding agents at the same time

Security researchers at AIR disclosed Plugin4Shell, a zero-click vulnerability in how Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI verify plugin code. Each tool pins plugins to an exact, approved commit, but never confirms that's actually what got checked out. An attacker who controls a plugin's repository can swap in malicious code after the pin check passes, with no click or confirmation needed from the user. The researchers, who found the flaw reaches marketplaces used by millions, report no known exploitation in the wild. Anthropic and OpenAI shipped fixes; Google retired the affected product instead of fixing it; Microsoft has not patched Copilot as of this writing.

Why it matters: this is being called the first real supply-chain vulnerability of the AI coding agent era, and the pattern, trusting a pin without verifying it held, is a general lesson, not just a bug in four specific tools. If anyone on your team uses AI coding assistants with third-party plugins, confirm which tool and which version they're actually running, especially if it's Copilot or Gemini CLI.

Read more

Industry Spotlight

For Legal Practices

The 10th Circuit wants lawyers to certify that a human actually checked every AI-assisted filing

The court's proposed rule would require anyone filing an AI-assisted document in a federal appeal to confirm a person reviewed it: that cited authorities exist, quotes and citations are accurate, the legal analysis holds up, and the filing meets court rules and ethical duties. It would apply to federal appeals in Colorado, Kansas, Oklahoma, New Mexico, Utah, and Wyoming. Public comment is open through October 18, with final rules expected by December 1 and an effective date of January 1, 2027, if adopted.

Why it matters: whatever this circuit finalizes will likely become a template other circuits borrow from. A firm that already has a documented human-review step for AI-assisted filings won't need to change anything when a version of this rule reaches its own jurisdiction. A firm that doesn't has a concrete deadline now to build one.

Read more

For Financial & CFO Firms

A government watchdog found the IRS's own cybersecurity ineffective for the second year in a row

The Treasury Inspector General for Tax Administration reported that 86 percent of sampled IRS information systems, six of seven, had critical vulnerabilities that went unfixed past the agency's own required 30-day window. The agency couldn't produce an inventory of its critical software, and 841 privileged accounts across 313 systems sit outside its account management system entirely. Data-at-rest encryption, originally targeted for completion by fiscal year 2024, has slipped to fiscal year 2027.

Why it matters: the agency your clients' most sensitive data flows to is not a gold standard to defer to on security. That's not a reason to distrust the IRS specifically, it's a reason to hold your own firm's handling of that same data to a standard you set and verify yourself, not one you assume someone else is meeting.

Read more

On the Horizon

OpenAI, Anthropic, and DeepSeek are set to brief the UN Security Council on AI risk this Wednesday. Sam Altman is expected to attend for OpenAI, with senior Anthropic representatives also present, alongside DeepSeek and other Chinese AI firms. It's the first time the Security Council has taken up AI safety directly with sitting lab leadership in the room, weeks after this briefing covered Anthropic's public call for the industry to deliberately slow down.

Why get ahead of this now: nothing here is actionable yet, but a UN-level conversation about AI risk, with the labs themselves at the table, is a step beyond company blog posts and industry letters. Worth watching whether anything concrete comes out of it, or whether it's a one-time statement with no follow-through.

Try This This Week

Pick one AI tool your team relies on, whether that's a coding assistant, a document drafting tool, or anything else with an auto-update or plugin system, and actually check its current version against the vendor's latest patch notes. This week's lesson wasn't really about AI coding agents specifically. It's that "we're using a well-known vendor's tool" and "we're running a version that's actually patched" are two different claims, and only one of them protects you.

Got an idea where AI could help your business but aren’t sure what the next step is? Reach out — no pressure, no pitch.

Book a 30-minute call