One Model Used to Break Into Another (09/18/2026)

September 18, 2026
One Model Used to Break Into Another (09/18/2026)
Key Intel / TL;DR
  • Researchers used Anthropic's Claude to compromise the ChatGPT accounts of OpenAI employees.
  • Microsoft patched a CVSS 10.0 privilege escalation flaw in Azure AI Foundry.
  • Plugin4Shell lets a repository owner swap pinned plugin code across four separate AI coding agents.
  • An abandoned CDN domain was re-registered while thousands of sites still request scripts from it.
  • A WeaselBiscuit stealer campaign used 13 npm packages to harvest Chrome extension storage.

The pinned dependency is supposed to be the thing that does not change under you. Today’s Plugin4Shell research shows four AI coding agents where the repository owner can swap the code behind a pin, which removes the one property the pin existed to provide.

Top 5 Critical Security Alerts

1. Researchers Used One Model to Break Into Another Vendor

Researchers demonstrated using Anthropic’s Claude to compromise the ChatGPT accounts of OpenAI employees, which is the first widely reported case of one commercial model being driven as the tooling in an attack on another provider’s users. The notable part is not novelty for its own sake but what it says about capability distribution, since the operator supplied the objective and the model supplied the work. Every organization now has staff with accounts at multiple model providers and no policy describing what that concentration means. The Register has the research and TechCrunch has the detail.

2. Microsoft Patches a Maximum Severity Azure AI Foundry Flaw

Microsoft fixed a CVSS 10.0 vulnerability in Azure AI Foundry permitting unauthorized privilege escalation. The AI platform layer is where organizations are placing model access, prompts, and the connectors that reach real data, and it has been in production for a considerably shorter time than anything else holding that much trust. A maximum-severity escalation there reaches whatever the platform was wired into. The Hacker News has the patch.

Operator Note: List which data sources your AI platform holds connectors to, because that list is the actual scope of any flaw in the platform itself.

3. Plugin4Shell Breaks the Pin on Four Coding Agents

Researchers disclosed Plugin4Shell, a technique letting a repository owner swap the code behind a pinned plugin reference across four separate AI coding agents. Pinning exists so that the artifact you reviewed is the artifact you run, and a pin that the upstream owner can redefine is a version string with no integrity behind it. This lands in the same week an attacker spread a worm through a hijacked coding assistant session, which makes two independent paths into the same trusted tooling. The Hacker News has the technique.

Operator Note: Find out whether your coding agents verify a hash or only a name and version, because that difference decides whether your pins mean anything.

4. An Abandoned CDN Domain Came Back Under New Ownership

A content delivery domain that had been abandoned was re-registered by somebody else while thousands of websites still request scripts from it. Every one of those sites is executing whatever the new owner chooses to serve, with full access to the pages that include it, and none of their operators took any action to create the exposure. An expired domain in a script tag is a supply chain handover that happens without a transaction. The Hacker News has the research.

5. Thirteen npm Packages Harvested Chrome Extension Storage

A stealer tracked as WeaselBiscuit spread through 13 npm packages to collect data from Chrome extension storage. Extension storage holds session tokens and configuration for whatever the extension does, which in a developer’s browser is frequently a set of cloud consoles. A package dependency reaching browser storage is two supply chains crossing in a place neither one models. The Hacker News has the campaign.

Additional Security Alerts

Threat Intelligence

  • Transparent Tribe is using private GitHub repositories for command and control: A new Rust backdoor takes instructions from repositories that look like ordinary private development to anybody monitoring the traffic. The Hacker News
  • North Korea’s fake job interviews infected 30,000 devices: The campaign’s scale is the update, since the technique has been reported for two years and the count had not. The Register
  • Fake LastPass Authenticator repositories are pushing an infostealer: Malicious GitHub repositories impersonating a password manager’s authenticator deliver the Rapuncel stealer. BleepingComputer
  • The FBI and Coast Guard boarded hacked oil tankers approaching the US: A cyber incident aboard vessels produced a physical interdiction, which is the converged version of this category. TechCrunch
  • Manufacturing now accounts for 22% of all ransomware victims: The sector’s share reflects low tolerance for downtime and an OT estate that resists patching. Infosecurity Magazine
  • Impersonation scams cost victims $1.6 billion: The FBI’s figure covers fake law enforcement and government officials, which works for the same reason the Revolut request did. The Register

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)