---
title: "Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code — supply-chain attack via llms.txt guidance file illustrates how data has become code"
slug: "forscher-schleusen-ueber-llmstxt-code-in-ai-agents-von-fortune-500-firmen"
date: 2026-09-02
category: tech-pub
tags: [agents]
language: en
sources_count: 1
featured: false
publisher: AInauten News
url: https://news.ainauten.com/en/story/forscher-schleusen-ueber-llmstxt-code-in-ai-agents-von-fortune-500-firmen
---

# Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code — supply-chain attack via llms.txt guidance file illustrates how data has become code

**Published**: 2026-09-02 | **Category**: tech-pub | **Sources**: 1

---

## TL;DR

Security researchers got AI agents at Fortune 500 companies to execute arbitrary code.

---

## Summary

Security researchers got AI agents at Fortune 500 companies to execute arbitrary code. The attack ran through llms.txt, the public guidance file many sites publish for AI systems. Instructions planted in that file were executed as commands rather than read as data. The case shows how quickly a harmless context file turns into a supply chain hole once agents read from the open web without checks.

---

## Why it matters

Security researchers got AI agents at Fortune 500 companies to execute arbitrary code.

---

## Key Points

- Security researchers got AI agents at Fortune 500 companies to execute arbitrary code.
- The attack ran through llms.
- txt, the public guidance file many sites publish for AI systems.
- Instructions planted in that file were executed as commands rather than read as data.
- The case shows how quickly a harmless context file turns into a supply chain hole once agents read from the open web without checks.

---

## Nauti's Take

The clean disclosure is the opportunity here: llms.txt can be hardened before attackers scale the pattern. The risk stays high, because many agents still treat fetched web content as instructions. Teams running agents with tool access should handle external context files like untrusted code and cut write and execution permissions to the minimum.

---


## FAQ

**Q:** What is Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code — supply-chain attack via llms.txt guidance file illustrates how data has become code about?

**A:** Security researchers got AI agents at Fortune 500 companies to execute arbitrary code.

**Q:** Why does it matter?

**A:** Security researchers got AI agents at Fortune 500 companies to execute arbitrary code.

**Q:** What are the key takeaways?

**A:** Security researchers got AI agents at Fortune 500 companies to execute arbitrary code.. The attack ran through llms.. txt, the public guidance file many sites publish for AI systems.

---

## Related Topics

- [agents](https://news.ainauten.com/en/tag/agents)

---

## Sources

- [Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code — supply-chain attack via llms.txt guidance file illustrates how data has become code](https://www.tomshardware.com/tech-industry/artificial-intelligence/researchers-easily-trick-fortune-500-companies-ai-agents-into-running-arbitrary-code-supply-chain-attack-via-llms-txt-guidance-file-illustrates-how-data-has-become-code) - Tom's Hardware AI

---

## About This Article

This article is a synthesis of 1 sources, curated and summarized by AInauten News. We aggregate AI news from trusted sources and provide bilingual (German/English) coverage.

**Publisher**: [AInauten](https://www.ainauten.com) | **Site**: [news.ainauten.com](https://news.ainauten.com)

---

*Last Updated: 2026-09-02*
