CyberSecurity News
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
AI summary
Researchers in Israel analyzed over 6,000 domains of major companies and found numerous instances of AI coding agents installing potentially malicious code. They discovered 120 files that pointed to unregistered code packages or domain names, indicating a lack of trustworthiness in AI coding agents. The researchers then registered some of the unclaimed names and hosted packages to test the AI agents' behavior. This test was done to understand what happens when an AI agent processes such files. The study highlights the risks associated with using AI coding agents on corporate networks. The findings suggest that these agents can introduce unknown or untrusted code into a company's system.
Countries in focus
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to Schneier on Security.

