🚨 We discovered a namespace-hijacking technique targeting AI IDEs that lets attackers impersonate any Microsoft Marketplace publisher via @openvsx , and a live campaign already exploiting it across 150 extensions.
Every developer who imports extensions into @cursor_ai , @devindesktop , @WindsurfCurrent , or @kirodotdev is in scope.
Additional details in the 🧵
The AI ecosystem is the wild west 🐎 You connect a new MCP, skill, or agent... and find out it's sketchy after the damage is done.
We built Market Space - discover & install AI tools that are secure by default 🪐
plutonium.pluto.security
The security assumption every AI team gets wrong: "As long as trust_remote_code=False is set, we are safe." ❌
We put that to the test. What we uncovered is a critical RCE vulnerability in @huggingface Transformers (CVE-2026-4372) that completely bypasses this control.
A thread on how a routine model load turns into complete environment compromise 👇
1/3 🔍 The Exploit & ScaleBy abusing model configuration fields, an attacker can embed a malicious payload inside a configuration file. It executes arbitrary code even with remote code disabled.
The affected versions were downloaded over 232M times while live.
2/3 🚨 The RiskSuccessful exploitation means full environment compromise—exposing cloud credentials, API keys, source code, and proprietary datasets.
Impacts Transformers versions 4.56.0 through 5.2.x.
3/3 🛡️ Remediation• Upgrade to version 5.3.0 immediately. • Audit previously downloaded model configurations. • Move beyond checkbox security—static ecosystem flags aren't enough.
Kudos to the Hugging Face team for the quick patch collaboration.
👇 Full technical breakdown link in the replies!
Last time, we published ClaudeSec - our security-first hub for the Claude ecosystem.
Now, CopilotSec is officially LIVE.
A new community knowledge hub for security of the Microsoft AI ecosystem, powered by Pluto.
Ever wanted a single place to understand what Microsoft AI connectors actually do?
Wondered which ones are high-risk?
Trying to figure out how to securely deploy Copilot Studio, agents, MCP servers, or AI workflows in production?
That’s exactly why we built CopilotSec.
Inside you’ll find:
1,718 Microsoft ecosystem connectors mapped by capability and riskSecurity guides for Copilot Studio and Microsoft AI deploymentsCurated security updates and findings that actually matter to security teams
Built for practitioners. Open to everyone.
Give it a try and let us know what you think!
Link in the first comment 👇
Someone finally built a security database for the Claude ecosystem.
It's called ClaudeSec, and Pluto Security just launched it for free.
Here's the gap it fills => 53 new Claude connectors shipped in the last 30 days. Your security team reviewed zero of them. Someone on your team authorized at least one.
Most enterprises adopting Claude have no process to evaluate connectors before authorization.
ClaudeSec tracks 384 connectors. 103 flagged high risk. That's around 27% of the ecosystem.
Every entry shows:
→ What capabilities the connector actually has
→ What tools it exposes to the model
→ Why it's rated risky
→ Source-code findings where they did the review
Security guides are live for Claude Managed Agents and Cowork. Real configuration - policies, hooks, permission scopes, allow/deny rules.
The Cowork guide is the one Enterprise teams need to read first.
Cowork runs code, browses with real user sessions, and operates unattended. The architecture is solid, gVisor sandbox, layered network controls. But Cowork activity is excluded from Audit Logs, the Compliance API, and Data Exports. All plan tiers. Including Enterprise.
Your visibility tools don't see what Cowork is doing.
Claude Code and Office Agents guides ship next.
The curated news feed flags CVEs and incidents as they happen. The window between a connector being compromised and detection is roughly 3 hours. The feed is built around that window.
Read here:
ClaudeSec: claudesec.pluto.security
Launch blog: pluto.security/blog/introduci…
Cowork teardown: pluto.security/blog/claude-co…
Thanks to @pluto_security for supporting this post.
@sama@VampireGurlAI Big move. Most enterprises are still figuring out how to govern the AI they already have. Now they need to secure what's securing them too.
@AnthropicAI Opening up bug bounties is the right call. Finding the vulnerability is step one. The harder question is what happens in production before anyone finds it.
ClaudeSec is officially LIVE!
Meet the new security-first hub for the Claude ecosystem, powered by @pluto_security.
❓Always yearned for a unified search of all existing extensions?
❓Ever wondered what ones are flagged as high-risk?
❓Dreaming of knowing how to deploy safely with Claude?
All of this (and more) is now waiting for you on our new planet.
Give it a go and let us know in the comments what you thought!
Link in the first comment.
507 Followers 760 FollowingFounder @shopydash, building https://t.co/F2tkErR6h9
I build websites and apps that are not just user-friendly but also convert!
AI and ML Enthusiast!
261 Followers 379 FollowingAi Engineer..
Curious tech guy building SaaS | AI, LLMs, Ai agents & scalability | Documenting the AI journey one build at a time 🤖
1K Followers 1K FollowingBuilt https://t.co/DFLPHK8NXC to help service businesses stop no-shows, recover missed calls & automate follow-ups | Full-stack dev | DMs open
605 Followers 520 FollowingCofounder at https://t.co/e8ibbTGNkF building the best AI wearable note taker. Check it out. DM for discount and questions! Ex-@google, ex-@citadel. Let’s connect
105 Followers 493 FollowingFounder of Reeno — integration reliability for SaaS.
Know when the services your app depends on break before customers do.
Building in public.
675 Followers 685 FollowingFull-time dev · Building Levelyss
AI-powered task manager with XP, skills & quests
Making productivity fun
Open beta → https://t.co/2zv5CYhJs1. Let’s connect 👋
814 Followers 830 FollowingCreative director running a small software empire from one Mac 📸 🇵🇭🇬🇧
💻https://t.co/p6eLKRrzan
🎧https://t.co/SReIfHZPxM 🎨https://t.co/CRcj5lOhj7
🎰https://t.co/LW1i743jfu 🫧https://t.co/xQF6NpjouS
66 Followers 131 FollowingGrowing an AI saas & reverse-engineering how the best ones scale.
I share the playbooks as I iterate. No gatekeep.
Short form and organic distribution mostly.