AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

·Schneier on Security··

We cannot forget that AI coding agents are not yet trustworthy: Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such file...

Read full article →

Related Articles

Google Chrome silently installs a 4 GB AI model on your device without consent
john-doe · Hacker News · 4mo ago
ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click
miohtama · Hacker News · 22h ago
DNSSEC disruption affecting .de domains – Resolved
warpspin · Hacker News · 4mo ago
Security through obscurity is not bad
mobeigi · Hacker News · 4mo ago
US healthcare marketplaces shared citizenship and race data with ad tech giants
ZeidJ · Hacker News · 4mo ago