Today in AI September 18 2026: Plugin4Shell, Anthropic R&D pace, wet lab

Today in AI (September 18, 2026): Coding Agents Get a Supply-Chain Scare, Claude Leads a Quarter of Anthropic’s R&D, and a Wet Lab Joins the Chat

Friday’s through-line is trust at the edges. Security researchers say four major AI coding agents shared a plugin-pinning flaw that can turn a “safe” update into remote code execution. Anthropic publishes its first public scorecard of how much Claude is doing its own R&D. And Reuters reports Anthropic has stood up a Bay Area wet lab as it pushes Claude into physical biology work.


1. Plugin4Shell: four coding agents, one shared pin mistake

On September 17, 2026 (coverage running hard into Friday), Air Security researchers Or Nevo, Dor Granat, and Niv Hoffman disclosed Plugin4Shell, a zero-click remote code execution path they say hits Anthropic’s Claude Code, OpenAI’s Codex, GitHub Copilot, and Google’s Gemini CLI. The Register and The Hacker News both walked the disclosure.

Marketplaces pin plugins to a reviewed commit SHA so a later repo takeover cannot silently change what you run. Air says the agents check out that pin but never verify the working tree actually landed on that commit. An attacker who controls the plugin repo can make checkout resolve to malicious code while the pin still looks honored. Background plugin auto-update (default on Claude Code and Codex, per Air) turns that into zero-click.

Patch status, per Air and follow-on reporting: Claude Code fixed in 2.1.179; Codex fixed in 0.146.0; GitHub Copilot has no agent-side fix shipped as of the disclosure coverage (GitHub blocks SHA-shaped branch names on GitHub itself; Air says Copilot still supports other hosts where the trick works); Gemini CLI will not be patched (deprecated), with users pointed toward Antigravity. Air found a working proof of concept in May 2026 and disclosed in June. As of September 18 reporting, The Hacker News notes no CVE assigned yet and no sign of in-the-wild exploitation.

Why it matters: if you run a coding agent with marketplace plugins, update Claude Code past 2.1.179 and Codex past 0.146.0, audit installed plugins, and turn off auto-update until you trust the pin story again. Copilot users on non-GitHub marketplaces should assume extra risk until Microsoft ships a client fix. Researchers are not claiming breaches in the wild. Still treat agent plugins like software that can touch your whole machine.

Sources: Air Security – Plugin4Shell, The Register – 0-click RCE in coding agents, The Hacker News – Plugin4Shell pin bypass


2. Anthropic opens the books on AI building AI

Anthropic published Measurements for understanding the pace of AI development inside frontier labs, its first public snapshot of how much Claude is automating Anthropic’s own research loop. The company frames the numbers as visibility for a world that is “considering slowing” frontier development.

As of August 2026, using an Epoch AI-style automation scale: Claude is not fully autonomous on any measured slice of AI R&D; Claude leads about 26% of Anthropic’s AI R&D (most of a task end-to-end from a high-level prompt, with human supervision); and more than 90% of that work sits at “AI collaborates” or higher.

On oversight, Anthropic says roughly 30,000 agents were doing research and engineering work at once on its most-used internal platform, with online monitors covering 100% of those actions before execution. Across more than a billion agent decisions in August, about 0.002% (roughly 1 in 47,000) were blocked. On compute, for a sampled mid-July week, Anthropic estimates about 6% of AI R&D compute went to safety work, and about 12% of compute inside AI-driven AI R&D (conservative counts).

Why it matters: the lab that builds Claude is already using Claude to build a lot of the next Claude, and it wants outside eyes on the pace. For a small team, echo the same three questions: who leads, who watches, and where the spend goes. Ask vendors for version notes, human approval gates, and spend caps before you hand them the keys.

Sources: Anthropic – Measuring the pace of AI development, Euronews – Anthropic on AI building its successor, BNN Bloomberg – Claude helping build the next Claude


3. Anthropic’s wet lab: Claude meets pipettes

Separately on September 18, 2026, Reuters reported that Anthropic has quietly set up a wet lab in the San Francisco Bay Area for physical biology experiments, not only computer simulations. Anthropic’s head of life sciences, Eric Kauderer-Abrams, confirmed the lab in a Reuters interview: “We believe that to do biology, the final test is still and will be for a while in real lab work.” A spokesperson later clarified the lab is not for drug discovery specifically, without elaborating.

People familiar with the effort told Reuters Anthropic wants Claude to direct robotic units for science experiments with limited human intervention, while the company still calls human oversight essential. Anthropic has talked publicly about preclinical work on conditions traditional pharma may skip, launched Claude Science software, added Novartis CEO Vas Narasimhan to its board, and confirmed buying Coefficient Bio (media put the deal near $400 million in stock; Anthropic declined to comment on price). Kauderer-Abrams said Anthropic is not running clinical trials for now and is not trying to compete with drugmakers that bring medicines to market.

Why it matters: most readers will not stand up a wet lab this weekend. The signal is where frontier labs think useful AI goes next: out of the chat window and into machines that move liquids. If you sell into biotech or lab automation, watch Anthropic’s partner posture. If you are an everyday user, treat it as context. The same companies shipping your writing and coding agents are arguing about how fast those agents should improve, and where physical-world leverage belongs.

Sources: Reuters – Anthropic sets up biology lab


The quick take

Friday is about pins, pace, and pipettes. Update your coding agents before you install another marketplace plugin. Read Anthropic’s R&D scorecard if you want a concrete number behind the “AI building AI” chatter. And remember that “useful” now includes labs that wet-bench as well as autocomplete.

If you only do one thing today, patch Claude Code and Codex (or migrate off Gemini CLI), then list every plugin your agents auto-update. If you only do two, skim Anthropic’s pace post and ask any vendor running agents on your stack what share of actions a human still approves.

Want a standing digest of the public changes that matter to you (not just competitor noise)? See how to have Grok Bot monitor the internet for things you care about.


Posted

in

, ,

by

Comments

0 responses to “Today in AI (September 18, 2026): Coding Agents Get a Supply-Chain Scare, Claude Leads a Quarter of Anthropic’s R&D, and a Wet Lab Joins the Chat”

Leave a Reply

Your email address will not be published. Required fields are marked *