资讯🔥8.0
Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code — supply-chain attack via llms.txt guidance file illustrates how data has become code
📌 概要
安全研究人员通过篡改公开的llms.txt引导文件,轻易诱导财富500强企业的AI智能体执行任意代码。这种供应链攻击表明,AI系统将网页数据当作指令处理,使“数据即代码”成为新的重大安全隐患,企业亟需加强对AI代理数据来源的防护。
⚡ 关键要点
- ▸研究人员利用公开llms.txt文件成功诱导财富500强企业AI代理执行任意代码
- ▸攻击属于供应链攻击,通过污染AI引用的引导文件实现
- ▸事件凸显'数据即代码'风险:AI将外部数据视为指令的固有漏洞
Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code. This supply-chain attack, done via using data in public llms.txt guidance files, illustrates the dangers of data becoming code.