资讯
Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code — supply-chain attack via llms.txt guidance file illustrates how data has become code
📌 概要
研究人员利用公开的llms.txt引导文件实施供应链攻击,轻易诱骗财富500强企业的AI代理执行任意代码。该攻击揭示了AI代理将外部数据当作指令执行的风险——数据已成为代码,企业AI系统面临新的安全隐患。
⚡ 关键要点
- ▸研究人员通过llms.txt文件轻松诱骗财富500强企业AI代理执行任意代码
- ▸攻击属于供应链攻击,利用AI代理对外部引导文件的信任
- ▸此事件凸显'数据即代码'带来的新型安全风险
Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code. This supply-chain attack, done via using data in public llms.txt guidance files, illustrates the dangers of data becoming code.