AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

Schneier on Security

Overview

A recent study by researchers from a stealth startup in Israel has raised concerns about the trustworthiness of AI coding agents after scanning over 6,200 domains belonging to major defense contractors and Fortune 500 companies. They discovered that 120 files contained links to unregistered code packages. To investigate, the researchers registered some of these unclaimed names and hosted packages, which led to multiple Fortune 500 companies unknowingly connecting to their server. This indicates that popular AI coding agents, including those from OpenAI and Anthropic, may install untrusted code on corporate networks. The implications of this are significant, as it highlights potential vulnerabilities in how companies utilize AI for coding tasks, raising questions about security protocols and the oversight of AI-generated code.

Key Takeaways

  • Affected Systems: Fortune 500 companies, defense contractors, Big Tech companies, AI coding agents (Claude, OpenAI Codex, Nous Research's Hermes)
  • Action Required: Companies should review AI coding practices and implement stricter code verification processes to ensure that only trusted and verified code is executed.
  • Timeline: Newly disclosed

Original Article Summary

We cannot forget that AI coding agents are not yet trustworthy: Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI’s Codex, and Nous Research’s Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication...

Impact

Fortune 500 companies, defense contractors, Big Tech companies, AI coding agents (Claude, OpenAI Codex, Nous Research's Hermes)

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Newly disclosed

Remediation

Companies should review AI coding practices and implement stricter code verification processes to ensure that only trusted and verified code is executed.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

The Hacker News

Recent vulnerabilities in PaperCut have been exploited by attackers to steal credentials from educational institutions in the U.S. and Europe. The Arctic Wolf Adversary Research Team identified two specific vulnerabilities, CVE-2026-81578 and CVE-2026-82078, which allow for authentication bypass and remote code execution. These flaws enable attackers to execute commands and gather information within the affected systems. The impact is particularly significant for schools and universities, as they often handle sensitive student and staff information. Immediate action is essential to prevent unauthorized access and potential data breaches.

Sep 5, 2026

European parliament members call for slowdown of Serbia’s EU entry over spyware use

CyberScoop

Members of the European Parliament are urging a delay in Serbia's entry into the European Union due to concerns over the government's use of spyware against activists. This call comes after reports that Serbian student activists were targeted with the invasive Pegasus and NoviSpy spyware. These revelations have raised alarms about human rights and privacy violations in Serbia, especially in the context of its EU accession talks. The situation reflects broader pressures on the Serbian government regarding its commitment to democratic practices and the protection of civil liberties. The Parliament's stance indicates that future EU membership may depend on significant improvements in these areas.

Sep 4, 2026

HPE Patches Critical RCE Vulnerabilities in AOS-CX

SecurityWeek

Hewlett Packard Enterprise (HPE) has released critical patches to address a series of vulnerabilities in its AOS-CX networking operating system. These vulnerabilities, collectively identified as CVE-2026-73749, carry a high severity score of 9.8, indicating they could allow remote code execution. This means that attackers could potentially exploit these flaws to take control of affected systems from a distance. Organizations using AOS-CX should prioritize applying these updates to safeguard their networks. The vulnerabilities are significant as they could affect a wide range of network devices, potentially putting sensitive data and operations at risk.

Sep 4, 2026

Companies Have 6 Months to Prepare for Automated Attacks

darkreading

Recent advancements in AI technology have enabled automated systems to conduct end-to-end attacks on various digital infrastructures. These AI models can compromise systems either intentionally or inadvertently, raising alarms for organizations that rely on traditional cybersecurity defenses. Experts warn that companies have a six-month window to enhance their security measures in anticipation of these automated threats becoming more prevalent. The urgency lies in the fact that as AI capabilities improve, so does the potential for sophisticated attacks that could bypass existing security protocols. Organizations need to prepare by investing in updated security technologies and protocols to safeguard their data and systems against these emerging risks.

Sep 4, 2026

Critical Citrix NetScaler auth bypass now leveraged in attacks

BleepingComputer

Attackers are now exploiting a significant vulnerability in Citrix NetScaler, identified as CVE-2026-19490, which allows for authentication bypass. This flaw poses a severe risk as it could enable unauthorized access to systems using affected versions of NetScaler. Companies that utilize Citrix NetScaler for application delivery or networking are particularly at risk, as this vulnerability can compromise their security posture. Security researchers from Previdian have reported that the flaw is actively being exploited in the wild, indicating an urgent need for users to assess their systems. Organizations should prioritize applying any available patches or implementing mitigation strategies to protect against potential breaches.

Sep 4, 2026

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

The Hacker News

PostgreSQL has issued updates to fix a serious security vulnerability, tracked as CVE-2026-6471, that has existed for 12 years. This flaw allows users with the REPLICATION attribute to execute arbitrary code as the operating system user running the database server. The vulnerability affects several versions of PostgreSQL, specifically those released before 18.6, 17.11, 16.15, 15.19, and 14.24. The potential for attackers to exploit this flaw poses a significant risk to database security, making it crucial for users to apply the updates promptly. The vulnerability was introduced with the logical decoding feature in PostgreSQL 9.4, highlighting the importance of regularly updating database systems to protect against long-standing vulnerabilities.

Sep 4, 2026