A vulnerability called Plugin4Shell just hit Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI at the same time, zero-click, bypasses SHA pinning. If you use any of these tools for your work, this is the week to check you're patched. It ties directly into the AI Breakout infographic we posted this week: four labs, four separate sandbox incidents in two months, three of them tracing back to the same testing vendor's misconfiguration. Also in this week's edition: the Nscale IPO numbers worth knowing, an AI-assisted bug bounty story worth reading, and our two articles on Gemini's sandbox escape and Amazon blocking Meta's AI shopping assistant. Full edition here: https://neonaliensai.substack.com/p/this-week-in-ai-494