Claude, Codex, and Hermes installed unowned code inside corporate networks

Researchers have discovered that AI agents are inadvertently executing unowned code found in 'llms.txt' files on corporate websites. This vulnerability allows malicious actors to register unclaimed domains or packages to gain unauthorized access to corporate networks.
Why it matters
It highlights a significant new security attack vector for enterprises as they increasingly integrate AI agents into their automated workflows.
AI AGENTS RUN AMOK AGAIN Claude, Codex, and Hermes installed unowned code inside corporate networks 227 install commands were found in corporate docs pointing at code nobody owns.
The report focuses on technical security vulnerabilities and industry practices without partisan bias.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in