AI Business LensTHE BUSINESS OF AI, FOR PEOPLE WHO TEACH IT OR LEARN FROM IT
Schneier on Security · September 7, 2026

AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

CybersecurityInformation Systems
THE AI ANGLE
Executing and installing untrusted software packages referenced in documentation

Researchers discovered that AI coding agents like Claude and Codex automatically installed untrusted software packages on corporate networks after processing vendor documentation files (llms.txt) that referenced unregistered package names and domains. When researchers claimed these abandoned names with tracking code, they received phone-home responses from multiple Fortune 500 companies and startups. For Cybersecurity and Information Systems educators, this highlights a critical supply-chain risk where autonomous agents blur the line between documentation and executable instructions by blindly trusting unverified data sources.

THE TEACHING ANGLE
Instructors can examine how the erosion of the boundary between data and code challenges conventional trust models, especially when autonomous agents execute commands directly from unverified documentation.

Read the original at schneier.com   Generate teaching or study materials

Instructors get discussion guides, assignments, and mini-cases. Students and readers get a plain summary, class prep, and an exercise. All built from the full article. Three are free with an account.

More in Cybersecurity