< Back to all clusters
[TECHNOLOGY] · 10 sources

started · updated

AI security risks: Malicious code execution and crawler impersonation

Security researchers have identified critical vulnerabilities in how AI coding agents interact with website documentation. By exploiting the emerging llms.txt and llms-full.txt file standards, attackers can trick autonomous agents into installing malicious software.

Alon Hertz and a security research team discovered that many major organizations, including defense contractors and Fortune 500 companies, have documentation referencing unregistered software packages or domains. By registering these unclaimed names on public registries, researchers demonstrated that AI agents from Anthropic, OpenAI, and Nous Research would automatically download and execute the code. In one instance, a Fortune 500 company's agent executed a test package in less than four minutes.

Separately, security firm GreyNoise reported that threat actors are impersonating AI crawlers to hunt for exposed credentials. Automated scanners from 824 different IP addresses forged the names of 13 AI crawlers—including those from Anthropic, OpenAI, Google, and Perplexity—to search for sensitive configuration files and password stores on misconfigured web servers.

Entities

Alon Hertz · Anthropic · Google · GreyNoise · Nous Research · OpenAI · Perplexity

Claims

What the coverage asserts, and how many sources carry each claim.