Skip to main content
Aggregate AI 摘要 Schneier on Security 网络安全 4 Sep 2026 - 19:01

AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

RSS 官方收录 · 可信分层展示

关键摘要

AI编码代理正向企业网络安装未知/不可信代码,已波及多家Fortune 500公司

  • 研究扫描6214个企业域名,发现120个指向未注册代码包或域名
  • 研究人员注册未申领域名后1小时内即收到来自Fortune 500公司的回连响应
  • Claude、OpenAI Codex、Nous Hermes等主流编码代理被确认参与执行

AI 摘要 · 来源可核验

正文提要

We cannot forget that AI coding agents are not yet trustworthy:

Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI’s Codex, and Nous Research’s Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication.

This kind of thing will be exploited. Think Solar Winds–style supply chain attacks.

“The trust model is broken,” Alon Hertz, one of the researchers, wrote in an interview. “Agents treat vendor docs as ground truth and don’t question them­and neither do the humans supervising them. Agentic AI usage is exploding, and agents are spreading across every layer­SaaS, cloud, endpoint. As they multiply, so does the supply-chain surface, and today’s guards don’t cover it.”

打开官方原文 站点原文页 可信分区 本信源更多 今日简报 分享图 RSS 稍后再看列表