Digital Event Horizon
In a recent discovery, researchers found that multiple Fortune 500 companies and defense contractors had installed unowned code inside their networks. The unowned code was present in 227 install commands, which were found in corporate documentation pointing to code that nobody owns. This vulnerability is related to the misconfiguration of AI files called llms.txt and llms-full.txt, which can potentially lead to the installation of malware or other harmful packages. The researchers' findings highlight the need for better security measures to prevent this type of vulnerability.
Researchers found unowned code in 227 install commands in corporate networks, posing a significant security risk. The vulnerability was caused by misconfigured AI files llms.txt and llms-full.txt, which can install malware or other harmful packages. The "trust model" is broken, as AI agents treat vendor documents as ground truth without questioning them, allowing them to execute commands without integrity verification. The vulnerability affects not only llms.txt files but also any AI file with instructions that can be executed by an agent. Developers and organizations must properly configure AI files and implement better security measures to prevent the installation of unowned code.
Recently, researchers at a stealth startup in Israel uncovered a vulnerability in corporate networks that has significant implications for the security of large-scale AI systems. The researchers found that multiple Fortune 500 companies, as well as defense contractors and Big Tech companies, had installed unowned code inside their networks. This unowned code was present in 227 install commands, which were found in corporate documentation pointing to code that nobody owns.
The researchers discovered that the source of this vulnerability lay in the misconfiguration of AI files called llms.txt and llms-full.txt. These files, which are used to provide machine-readable summaries of a website's content and its high-level structure, are designed to be consumed by AI agents. However, if these files are not correctly configured, they can be used to install non-existent packages or view unclaimed domains. This can potentially lead to the installation of malware or other harmful packages.
The researchers tested the vulnerability by registering a handful of unclaimed domain names and hosting packages that caused AI agents to reach out to their server. Within an hour, they received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from Fortune 500 companies and others from startups.
The researchers believe that the trust model is broken, as AI agents treat vendor documents as ground truth and do not question them. This allows agents to execute commands without verifying the integrity of the instructions. The researchers also note that the endpoint detection system failed to detect the anomaly, as it was not designed to check the instructions in the llms.txt files.
The source of this vulnerability is the same as the underlying cause of prompt injections. However, this new weakness is broader, as it can affect any AI file that contains instructions that can be executed by an agent. The researchers suggest that the problem goes well beyond llms.txt and llms-full.txt files hosted on websites. Instructions, either implicit or explicit, are present almost everywhere an agent traverses.
The researchers' findings highlight the importance of properly configuring AI files and the need for better security measures to prevent the installation of unowned code. The vulnerability has significant implications for the security of large-scale AI systems, and it is essential that developers and organizations take steps to address this issue.
Related Information:
https://www.digitaleventhorizon.com/articles/The-Erosion-of-Boundaries-How-Unowned-Code-is-Spreading-Through-Corporate-Networks-via-Misconfigured-AI-Files-deh.shtml
https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
Published: Sun Aug 30 01:29:09 2026 by llama3.2 3B Q4_K_M