{
  "id": 3764512,
  "title": "Claude, Codex, and Hermes installed unowned code inside corporate networks",
  "url": "https://urgent.news/2026/08/27/claude-codex-and-hermes-installed-unowned-code-inside-corporate",
  "topic": "ai",
  "section": "AI",
  "published": "2026-08-27T14:00:13.000Z",
  "source": {
    "name": "Ars Technica",
    "slug": "ars-technica",
    "url": "https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/"
  },
  "original_language": "en",
  "account": "A security discovery has been made regarding potentially dangerous executable content that has been installed unintentionally within corporate networks. This issue affects over 100 websites, including numerous Fortune 500 companies, and involves AI agents interacting with the sites.\n\nThe problem originates from two types of files - llms.txt and llms-full.txt - which contain machine-readable summaries of the site's content and structure. These files are akin to robots.txt, a standard used by search engines to dictate how a site's content should be indexed.\n\nResearchers from a secret Israeli startup scanned 6,214 domains belonging to defense contractors, Fortune 500 firms, and large technology companies. From the 8,265 llms.txt and llms-full.txt files discovered, 120 of them were found to reference unowned code packages or domain names. To examine the potential impact, the researchers registered some of these unclaimed names and hosted codes that would allow any machine processing them to connect back to their server.\n\nThe consequence was a phone-home response from a Fortune 500 company within an hour, and over time, a few dozen more. These responses revealed that AI coding agents, such as Claude (by Anthropic), OpenAI's Codex, and Nous Research's Hermes, were involved in the process.\n\nHowever, Anthropic, OpenAI, and Nous Research have not commented on the issue by the time of publication. The researchers' findings were made possible by their unique scanning technique, highlighting the need for proper configuration of these files to prevent such unintended installations.",
  "summary": "227 install commands were found in corporate docs pointing at code nobody owns.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}