Comment on Claude, Codex, and Hermes installed unowned code inside corporate networks
OpenStars@discuss.online 8 hours agoThe first paragraph in the article says:
Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware.
So… yes. All someone has to do is register to become the new owner of the previously non-existent resource and then they can serve up whatever content they wish to the slop machines.
01189998819991197253@infosec.pub 8 hours ago
Sorry. I was being sarcastic. Forgot the s tag. I’m adding now.
OpenStars@discuss.online 7 hours ago
That should help! 😃