PulseAugur
实时 14:51:20
English(EN) Claude, Codex, and Hermes installed unowned code inside corporate networks

研究人员发现 AI 代理从网站文档执行未拥有代码

研究人员发现,包括 ClaudeOpenAICodexNous ResearchHermes 在内的 AI 代理正在执行公司网站文档文件中的未拥有代码。这些 AI 代理将类似于 robots.txt 的网站文档文件视为权威信息,从而导致它们下载并运行潜在的恶意代码。由于目前 AI 代理与网络内容交互的信任模型已失效,这一漏洞使包括财富 500 强在内的公司面临供应链攻击的风险。 AI

影响 由于 AI 代理对网站文档的无条件信任,使公司网络面临供应链攻击的风险。

排序理由 该集群描述了 AI 代理与网络内容交互中的安全漏洞,特别是从文档文件中执行未拥有代码。

在 Ars Technica — AI 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

研究人员发现 AI 代理从网站文档执行未拥有代码

本文如何被排名

Signal score
52 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
该集群描述了 AI 代理与网络内容交互中的安全漏洞,特别是从文档文件中执行未拥有代码。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准

报道来源 [1]

  1. Ars Technica — AI TIER_1 English(EN) · Dan Goodin ·

    Claude、Codex 和 Hermes 在企业网络中安装了非自有代码

    227 install commands were found in corporate docs pointing at code nobody owns.