{
  "id": 5535170,
  "title": "AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks",
  "url": "https://urgent.news/2026/09/04/ai-coding-agents-are-installing-unknown-untrusted-code-on-corporate",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-04T10:35:17.000Z",
  "source": {
    "name": "Schneier on Security",
    "slug": "schneier-on-security",
    "url": "https://www.schneier.com/blog/archives/2026/09/ai-coding-agents-are-installing-unknown-untrusted-code-on-corporate-networks.html"
  },
  "original_language": "en",
  "account": "AI coding agents could be posing a significant risk to corporate networks, according to researchers from a stealth startup in Israel. After scanning 6,214 live domains associated with defense contractors, Fortune 500 companies, and major tech firms, the researchers discovered 8,265 llms.txt and llms-full.txt files. Out of these, 120 files contained unregistered code packages or domain names.\n\nTo test the implications of AI agents processing these files, the team registered a few unclaimed names and deployed packages that redirected any machine executing them to their own server. Within an hour, the researchers received a phone-home response from a Fortune 500 company, followed by several more within a day. These responses were traced back to coding agents such as Claude, OpenAI's Codex, and Nous Research's Hermes.\n\nSubsequent analysis revealed that these agents, including those from Anthropic, OpenAI, and Nous Research, were involved in the process. The researchers noted that this represents a potential supply chain attack akin to the Solar Winds incident. They emphasized that the current trust model used by these agents is flawed. The agents treat vendor documentation as indisputable truth and don't question it, leaving the humans monitoring them in a similar situation.\n\nAs the usage of agentic AI continues to surge, proliferating across every layer of systems — from SaaS and cloud to endpoints — the attack surface for potential supply chain breaches expands correspondingly. The researchers concluded that the trust model currently in place is fundamentally broken, signaling a dire need for revised security measures to safeguard against such AI-driven threats.",
  "summary": "We cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code…",
  "key_points": [
    "8,265 AI coding agent files found on corporate networks",
    "Researchers tested agents by redirecting packages to their server",
    "Attack model flawed; agents trust vendor docs without question"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}