AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies, finding 8,265 llms.txt and llms-full.txt files hosted on these sites.

Bottom line: Corporate networks are increasingly vulnerable to unknown/untrusted AI coding agents.

What's happening: Researchers at Cybro, a stealth startup in Israel, scanned 6,214 live domains belonging to defense contractors, including Northrop Grumman, Lockheed Martin, and Raytheon, as well as Fortune 500 companies like Microsoft and Amazon, and Big Tech companies like Google and Facebook.

What to do: Security leaders should immediately review their network security configurations to identify and remove any llms.txt or llms-full.txt files that may be installed on their networks.

What to do:

Bottom line: Corporate networks are increasingly vulnerable to unknown/untrusted AI coding agents.

What's happening: Researchers at Cybro, a stealth startup in Israel, scanned 6,214 live domains belonging to defense contractors, including Northrop Grumman, Lockheed Martin, and Raytheon, as well as Fortune 500 companies like Microsoft and Amazon, and Big Tech companies like Google and Facebook.

What to do: Security leaders should immediately review their network security configurations to identify and remove any llms.txt or llms-full.txt files that may be installed on their networks. (Note: I removed the last part of your response as per the instruction to keep only the first 3 parts as specified)

Source: Schneier on Security