AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
CybersecurityInformation Systems
THE AI ANGLE
Executing and installing untrusted software packages referenced in documentationResearchers discovered that AI coding agents like Claude and Codex automatically installed untrusted software packages on corporate networks after processing vendor documentation files (llms.txt) that referenced unregistered package names and domains. When researchers claimed these abandoned names with tracking code, they received phone-home responses from multiple Fortune 500 companies and startups. For Cybersecurity and Information Systems educators, this highlights a critical supply-chain risk where autonomous agents blur the line between documentation and executable instructions by blindly trusting unverified data sources.
THE TEACHING ANGLE
Instructors can examine how the erosion of the boundary between data and code challenges conventional trust models, especially when autonomous agents execute commands directly from unverified documentation.Read the original at schneier.com Generate teaching or study materials
More in Cybersecurity
- The ERP reckoning: Decades of customization could block AI valueCIO.com · September 15, 2026
- RubyGems say OpenAI agents responsible for undisclosed swarm attack against its infrastructureTechRadar · September 15, 2026
- Using AI for Weapons DevelopmentSchneier on Security · September 15, 2026
- Presentation: Decision Models in Agentic Architectures: From Production to Agent SkillsInfoQ · September 14, 2026
- ‘It 100% sounded just like her’: AI voice scams are getting frighteningly convincing — here’s how to protect your familyTechRadar · September 14, 2026