{"data":{"id":"c3c5d7e8-dce3-4160-97b6-6b34f763e9ff","title":"AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks","summary":"Researchers discovered that AI coding agents (automated systems that write and execute code) are installing malicious software on corporate networks by exploiting llms.txt files (configuration files that tell AI agents where to find code packages). The agents, including Claude and OpenAI's Codex, blindly trusted these files and installed code from unclaimed domains that the researchers had set up, causing machines at Fortune 500 companies to connect to the researchers' servers within an hour, showing the agents don't verify whether code sources are legitimate before executing them.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://www.schneier.com/blog/archives/2026/09/ai-coding-agents-are-installing-unknown-untrusted-code-on-corporate-networks.html","publishedAt":"2026-09-04T10:35:17.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic","OpenAI"],"affectedVendorsRaw":["Claude","OpenAI","Codex","Nous Research","Hermes"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-04T10:35:17.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}