跳到主内容
精选85Ars Technica AI(RSS)行业动态

AI 代理被诱骗安装未注册代码,多家财富 500 强中招

Claude, Codex, and Hermes installed unowned code inside corporate networks

原文
推荐理由

做 AI 安全或 Agent 开发的同学必看,这是针对 llms.txt 的新型投毒攻击,已实锤打到财富 500 强,赶紧检查你的代理会不会执行这类文件。

Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware.

超过100个网站上的文档文件引用了潜在危险的、可执行的内容,当许多AI代理访问这些网站时,这些内容会自动安装。包括一些财富500强公司在内的数十家公司执行了概念验证代码。至少有一个配置错误的网站正在将访客(无论是人类还是AI)引导至实时恶意软件。

The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging convention websites employ to provide machine-readable summaries of the site’s content and its high-level structure. These files are the AI equivalent of the robots.txt standard that instructs search engines how to index the site's content. Google Lighthouse, a tool for helping web developers, has more here. Correctly configured llms.txt and llms-full.txt files for Cloudflare are here and here.

潜在危险内容位于llms.txt和llms-full.txt文件中,这是网站采用的一种新兴约定,用于提供网站内容及其高层结构的机器可读摘要。这些文件相当于AI领域的robots.txt标准,后者指示搜索引擎如何索引网站内容。Google Lighthouse,一个帮助网页开发者的工具,在此处有更多信息。Cloudflare正确配置的llms.txt和llms-full.txt文件可在此处和此处查看。

How the researchers found it

研究人员如何发现这一点

Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI's Codex, and Nous Research's Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication.

以色列一家隐形初创公司的研究人员扫描了属于国防承包商、财富500强和大型科技公司的6,214个活跃域名。在他们发现的8,265个llms.txt和llms-full.txt文件中(许多网站同时托管了llms.txt和llms-full.txt文件),其中120个文件(每个位于不同网站)指向了一个或多个未注册的代码包或域名。为了测试AI代理处理此类文件时会发生什么,研究人员注册了几个未认领的名称并托管了包,这些包导致任何执行它们的机器连接到他们的服务器。不到一小时内,研究人员就收到了一家财富500强公司的回拨响应。随着时间的推移,他们又收到了几十个响应,有些来自其他财富500强公司,有些来自初创公司。他们的信标还记录了每个安装产生的父进程链,最终揭示了包括Claude、OpenAI的Codex和Nous Research的Hermes在内的编码代理参与其中。Anthropic、OpenAI和Nous Research在发布时未回应评论请求。

Read full article

阅读全文

Comments

评论

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近