Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How much of a problem is AI’s water use?

    Barret Zoph, the Thinking Machines co-founder ousted before joining OpenAI, is now at Google

    A Judge Has Blocked the Pentagon’s Attempt to Blacklist Anthropic

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    • Artificial Intelligence
    AI News TodayAI News Today
    Home»Chatbots»Claude, Codex, and Hermes installed unowned code inside corporate networks
    Chatbots

    Claude, Codex, and Hermes installed unowned code inside corporate networks

    By No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Claude, Codex, and Hermes installed unowned code inside corporate networks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware.

    The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging convention websites employ to provide machine-readable summaries of the site’s content and its high-level structure. These files are the AI equivalent of the robots.txt standard that instructs search engines how to index the site’s content. Google Lighthouse, a tool for helping web developers, has more here. Correctly configured llms.txt and llms-full.txt files for Cloudflare are here and here.

    How the researchers found it

    Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI’s Codex, and Nous Research’s Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication.

    “The trust model is broken,” Alon Hertz, one of the researchers, wrote in an interview. “Agents treat vendor docs as ground truth and don’t question them—and neither do the humans supervising them. Agentic AI usage is exploding, and agents are spreading across every layer—SaaS, cloud, endpoint. As they multiply, so does the supply-chain surface, and today’s guards don’t cover it.”

    Claude Code Codex Corporate Hermes installed Networks unowned
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticlePanic passes Trump tariff refunds back to the Playdate customers who paid them
    Next Article AI, athletes, and Keith Rabois: StrictlyVC is back in New York on September 10
    • Website

    Related Posts

    Chatbots

    Barret Zoph, the Thinking Machines co-founder ousted before joining OpenAI, is now at Google

    Chatbots

    The GTA VI ‘extended look’ is now streaming on YouTube

    Chatbots

    Anthropic’s new hardware standard lets AI agents control the physical world

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    How much of a problem is AI’s water use?

    0 Views

    Barret Zoph, the Thinking Machines co-founder ousted before joining OpenAI, is now at Google

    0 Views

    A Judge Has Blocked the Pentagon’s Attempt to Blacklist Anthropic

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    How much of a problem is AI’s water use?

    0 Views

    Barret Zoph, the Thinking Machines co-founder ousted before joining OpenAI, is now at Google

    0 Views

    A Judge Has Blocked the Pentagon’s Attempt to Blacklist Anthropic

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.