CybersecurityDev3 min reading time

AI coding agents followed abandoned package references, 6K domains analyzed

Hacker News
Read full post
Researchers analyzed over 6,000 domains and found 120 unclaimed package or domain references in llms.txt files used by AI coding agents. These stale references could allow attackers to register the names and deploy malicious packages, potentially compromising corporate systems. An experiment showed that Fortune 500 companies' systems contacted these malicious packages within an hour, highlighting a new software supply-chain attack vector.

More in Cybersecurity

Cybersecurity10 min read

Anthropic Details Disrupted Claude Misuse Across Seven Harm Areas

Covered by 4 sources
Cybersecurity4 min read

Sam Altman met with top power utilities about securing the electrical grid. He offered one possible solution: OpenAI's cyber services.

Covered by 2 sources
Cybersecurity6 min read

Anthropic reveals rogue AI agents hate CAPTCHAs, just like you

TechCrunch