Claude, Codex, and Hermes installed unowned code inside corporate networks
Back to Home
security

Claude, Codex, and Hermes installed unowned code inside corporate networks

August 28, 20265 views2 min read

Security researchers found 227 installation commands in corporate documents pointing to unowned code from AI tools like Claude, Codex, and Hermes, raising serious enterprise security concerns.

Major AI companies are under scrutiny after security researchers discovered that popular AI tools like Claude, Codex, and Hermes had installed unowned code within corporate networks. The discovery was made when researchers analyzed corporate documentation and found 227 installation commands that pointed to code with no clear ownership or accountability.

Widespread Installation of Unclear Code

The problematic installations were found in various enterprise environments, raising serious concerns about the security and transparency of AI deployment processes. These commands, embedded within corporate documents and scripts, were designed to automatically download and execute code from remote servers. However, the origin and ownership of this code remained unclear, creating potential vulnerabilities that could be exploited by malicious actors.

Implications for Enterprise Security

Security experts warn that such practices could lead to significant risks for organizations relying on these AI tools. When code is installed without proper ownership verification, companies may unknowingly introduce backdoors or malicious software into their systems. The lack of accountability makes it difficult to trace the source of potential security breaches or malware infections. "This is a serious breach of trust," said one cybersecurity analyst. "Companies need to know exactly what code they're installing and where it comes from."

Industry Response and Future Outlook

While the affected companies have yet to issue comprehensive responses, the incident has sparked discussions about the need for greater transparency in AI tool deployments. Many experts are calling for stricter regulations and verification processes to prevent similar issues in the future. The incident serves as a wake-up call for enterprises to implement more rigorous security protocols when integrating AI solutions into their infrastructure.

This development highlights the growing complexity of AI deployment and the urgent need for better governance frameworks to protect corporate networks from potential security threats.

Source: Ars Technica

Related Articles