AI agents are executing code found in publicly available files on company websites, a vulnerability that has been exploited in the wild. These files, often named llms.txt, serve as instruction sets for AI agents, dictating what to read, which APIs to call, and which domains to trust. Researchers discovered that within minutes, AI agents within a Fortune 500 company executed published code, and later found an active attack using similar methods. AI
IMPACT This vulnerability highlights a new attack vector where AI agents can be tricked into executing malicious code via public website files, posing a significant security risk to organizations.
RANK_REASON The item describes a security vulnerability related to how AI agents interact with web content, which is a tool-related issue.
Read on Mastodon — mastodon.social →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →