Avalerion Intelligence · Edition 016
Tuesday 22 September 2026 · AI, Data & Enterprise Transformation for the Nordics, UK & Ireland
Four coding agents, one flaw, two still unpatched
| Move | Who | Why it matters to you |
|---|---|---|
| Plugin4Shell: zero click code execution through the plugin systems of four coding agents | AIR Security (17 September) | Agent plugins are a software supply chain, and most firms do not govern them as one |
| Claude Code and Codex patched, GitHub Copilot without a fix, Gemini CLI to be retired | Anthropic, OpenAI, Microsoft, Google (18 September) | Your exposure depends on which agent your developers chose |
| Astra for Law: a frontier model configured for one profession, with 26 partner plugins | OpenAI (17 September) | Model vendors now compete with the software built on top of them |
| Nokia Data Suite on Microsoft Fabric, trusted network data "in minutes instead of weeks" | Nokia and Microsoft (17 September) | Agents arrive after data products, not before |
| US proposes an AI incident notification channel with China | US Treasury (20 September) | AI incidents are now a matter for heads of state |
| Novo Nordisk puts Anthropic's models into research and software development | Novo Nordisk (16 September) | A Nordic flagship chose governance first, then scale |
1. Top AI News
A trusted plugin can be swapped for a malicious one.
What happened. On 17 September AIR Security disclosed Plugin4Shell, a zero click remote code execution flaw in Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. Plugin marketplaces pin each plugin to an exact commit. An attacker who controls a plugin's repository creates a branch named after that commit hash; Git resolves the branch first, so the agent installs the attacker's code while the pin still looks honoured. Claude Code and Codex update plugins in the background by default. AIR says a test skill it published reached more than 26,000 agents. Anthropic fixed Claude Code in version 2.1.179 and OpenAI fixed Codex in 0.146.0. Microsoft has not shipped a fix for Copilot, and Google is deprecating Gemini CLI in favour of Antigravity rather than patching it.
Why it matters. The pin was the control everyone relied on, and it did not hold.
What to do. This week, confirm the version of every coding agent in use and list which plugins each one has installed.
Washington wants an AI hotline with Beijing.
What happened. On 20 September in New York, US Treasury Secretary Scott Bessent proposed a US China AI dialogue with a notification system for AI incidents that rise to national security level. Chip export controls are excluded. The idea goes to the Trump and Xi summit in Washington this week.
Why it matters. Incident reporting for AI is becoming a state level expectation, and supervisors tend to follow.
What to do. Check that your incident process has a category for AI failures, with an owner.
China mass produces memory without the banned machines.
What happened. On 20 September CXMT announced mass production on its fifth generation DRAM platform, claiming at least 50 percent more dies per wafer and a 24 gigabit LPDDR5X chip, made without extreme ultraviolet lithography.
Why it matters. Memory is the tightest input in AI servers. TrendForce expected server DRAM contract prices to rise 13 to 18 percent in the third quarter. New supply eases that slowly and first for phones.
What to do. Assume hosted AI unit costs stay firm through 2027 in your budget.
2. Enterprise AI Trend: the model vendor moves into your software
On 17 September OpenAI launched Astra for Law, GPT-6 Astra configured for legal work, with a search index of more than 230 million URLs of United States law and 26 partner plugins, including iManage, Clio and Relativity. Selected firms get it first through a trusted access programme in ChatGPT and Codex, with the API to follow. Harvey and the Stockholm founded Legora will build on it, which means they now build on a product that competes with them. Expect the same pattern in finance, tax and service. When you buy a specialist AI application, ask what it adds that its model supplier could not ship next quarter, and what happens to your data and workflows if it cannot answer.
3. Data & AI Readiness: agents arrive after data products
On 17 September Nokia and Microsoft extended their partnership to combine Nokia Data Suite, a set of ready made telecom data products, with Microsoft Fabric. The claim is that operators reach trusted network data "in minutes instead of weeks", and the first agent use cases, voice service assurance and coverage analysis, sit on top of that. The order is the lesson. Nokia did not start with the agent. It started with governed, reusable data products and let agents consume them, with on premises deployment kept for operators with regulatory limits. If your agent programme has no named data products underneath it, each new agent will rebuild its own data pipeline and inherit its own errors.
4. Business Process Spotlight: the update nobody approved
Plugin4Shell is a security story, but the gap it exposed is a process one. Most organisations run formal change control on production software and none on the plugins, skills and connectors their developers add to coding agents, which update themselves overnight. Astra for Law launched with 26 plugins on day one; plugin estates will only grow. Treat them like any other third party dependency. Keep an approved list, pin versions you have reviewed, turn off automatic plugin updates where the tool allows it, and route new plugins through the same approval path as a new library. The work is dull and it closes the door Plugin4Shell used.
5. Nordic Technology: Novo Nordisk chooses governance first
On 16 September Novo Nordisk, headquartered in Bagsværd, announced a collaboration with Anthropic. Novo will test the Claude Science workbench in specific research and development workflows and use Anthropic's models to strengthen software development across the company. Both sides stressed that the programme was "designed with robust data governance and human oversight." Named workflows, a stated governance design and a defined scope is the pattern that gets AI past the pilot stage in regulated industries. In Sweden, the 13 September election gave the opposition 176 seats to 173, and a new government will inherit the national AI strategy published in February.
Do this next. Thirty minutes with us: which coding agents and plugins run in your estate, who approves a new one, and which data products your agents actually stand on. We will map all three with you. No pitch, no deck.
Recommended reading: What AI readiness actually means for Nordic companies and Why most enterprise AI projects still fail, at avalerions.com/insights
Frequently asked questions
What is Plugin4Shell?
Plugin4Shell is a zero click remote code execution flaw disclosed by AIR Security on 17 September 2026. It affects the plugin systems of Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. An attacker who controls a plugin repository creates a branch named after the pinned commit hash, so the agent installs malicious code while the pin appears honoured. Claude Code 2.1.179 and Codex 0.146.0 contain fixes.
Which AI coding agents are still exposed to Plugin4Shell?
As of 18 September 2026, Microsoft had not shipped a fix for GitHub Copilot. Google chose to deprecate Gemini CLI rather than patch it and advises users to move to Antigravity. Anthropic patched Claude Code in version 2.1.179 and OpenAI patched Codex in version 0.146.0. Organisations should confirm installed versions and review installed plugins.
What is OpenAI Astra for Law?
Astra for Law, launched on 17 September 2026, is GPT-6 Astra configured for legal work. It includes a search index of more than 230 million URLs of United States law, legal analysis and writing instructions, controls for law firms and 26 partner plugins. Selected firms receive it first through a trusted access programme, with API access to follow. Harvey and Legora will build on it.
What did Novo Nordisk and Anthropic announce?
On 16 September 2026 Novo Nordisk announced a collaboration with Anthropic. Novo will test the Claude Science workbench in specific research and development workflows to support drug discovery, and use Anthropic's models to strengthen software development across the company. Both companies said the programme was designed with robust data governance and human oversight.
Sources
- AIR Security, "Plugin4Shell: Zero Click RCE Vulnerability found in top 4 most popular coding agents", 17 September 2026: air.security
- Help Net Security, "Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched", 18 September 2026: helpnetsecurity.com
- SecurityOnline, "Plugin4Shell: Zero-Click RCE Hits Four AI Coding Agents": securityonline.info
- Al Jazeera, "US proposes AI safety notification mechanism in talks with China", 20 September 2026: aljazeera.com
- CNN Business, "Bessent proposes AI safety notifications in talks with China ahead of Xi-Trump meeting", 20 September 2026: cnn.com
- TechNode, "CXMT announces mass production of fifth-generation DRAM platform", 21 September 2026: technode.com
- TrendForce, "Server DRAM Contract Prices Expected to Rise 13-18% QoQ in 3Q26", 9 July 2026: trendforce.com
- The Next Web, "OpenAI launches Astra for Law, and its own legal research index", 18 September 2026: thenextweb.com
- Artificial Lawyer, "OpenAI Launches Astra For Law", 18 September 2026: artificiallawyer.com
- Nokia, "Nokia accelerates network automation through agentic, unified data foundation with Microsoft", Espoo, 17 September 2026: globenewswire.com
- Novo Nordisk, "Novo and Anthropic will collaborate to advance drug discovery with Claude", Bagsværd, 16 September 2026: globenewswire.com
- Wikipedia, "2026 Swedish general election": en.wikipedia.org
- Government Offices of Sweden, "Sweden's AI Strategy", February 2026: government.se