daily cyber × ai intelligence

index

August 20, 2026

Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs

64 of 70 sources 362 gathered 362 triaged 42 clustered 42 written

A joint NSA/FBI/CISA warning puts AI-assisted exploit development squarely in the operational-technology threat model, with Siemens S7 controllers in US energy, water, and manufacturing as the target. Elsewhere, a Windows IKE Extension RCE joined CISA’s exploited list, and a clean wasm2c sandbox escape landed with a working PoC.

Critical Infrastructure & AI-Assisted Offense

  • NSA, FBI and CISA say attackers are using AI to generate exploit scripts against Siemens S7-series PLCs, combining AI-assisted development with exploitation of known ICS vulnerabilities. Agencies stress this is “not a theoretical risk,” and the framing matters for defenders: the interesting claim isn’t novel capability but collapsed time-and-skill cost for attacking industrial controllers in energy, water, and manufacturing (The Record, BleepingComputer, The Register).

Exploitation & Vulnerability Research

  • A critical RCE in the Windows IKE Extension is now being exploited in the wild and has been added to CISA’s KEV catalog, alongside three other actively exploited flaws including CVE-2026-65400 in macOS, SharePoint, and vCenter issues already tracked this week (BleepingComputer, The Hacker News).
  • A wasm2c sandbox escape gives arbitrary shell execution on the host. The runtime’s table allocator ignores calloc failure, letting an untrusted guest module induce a null data pointer, leak libc addresses, and execute host commands via crafted function references. Full write-up plus PoC published (trustsig).
  • Citrix published a new advisory covering multiple critical NetScaler ADC and Gateway vulnerabilities, with CERT-EU urging immediate patching — the second serious NetScaler event in a week, following the mass exploitation of CVE-2026-8452 (CERT-EU 2026-010, earlier coverage).
  • A Spectre-class attack against Cloudflare Workers leaks JWTs from co-located workers at roughly 12 bits/second, a reminder that multi-tenant serverless isolation still rests on microarchitectural assumptions (The Hacker News).
  • Kimi Desktop ships an updater that can install unverified code, an unsigned-update path in an AI desktop client that is effectively a pre-built supply-chain foothold (runtimewire).

Cloud & Identity

  • Attackers are poisoning captive-portal DNS at hotels and conference centres to harvest Microsoft 365 credentials. ReliaQuest reports the campaign has run since at least June 2026, with compromised Wi-Fi gateways in multiple US cities plus India and Saudi Arabia; operators take administrative control of the gateway and redirect victims to fake M365 infrastructure — no phishing email, no device compromise (ReliaQuest, Schneier). Follows the Midnight Blizzard captive-portal activity reported last week (earlier coverage).
  • Password spraying volumes are up 155x, with attackers systematically targeting accounts and protocols where MFA enforcement is incomplete rather than trying to defeat MFA itself (BleepingComputer).

New Tools & Releases

  • wasm2c-tableflip — working PoC for the wasm2c escape above: an untrusted WebAssembly module breaks out of the generated C sandbox and runs a shell command on the host. Useful as a test case if you embed wasm2c-generated sandboxes anywhere in a build or plugin pipeline (GitHub).
  • OneCLI — open-source sandboxed agent harness aimed at giving each employee a contained agent with GitHub/Gmail/Notion/Dropbox connectors, per-workspace policy enforcement, and human-in-the-loop approval gates. Worth a look if you’re assessing agent deployments; commenter taoh raises the key question — whether approval binds to the exact proposed action and recipient rather than a blanket “allow Gmail,” especially where read and write share a host (GitHub) (discussion).

AI & Model Security

  • An abliterated build of Alibaba’s Qwen-3.8-27B posts a 0.0% refusal rate across 842 harmful prompts, with the publisher explicitly highlighting removal of guardrails around cyber capability, jailbreak generation, and multi-step attack chains — days after the base model shipped under Apache 2.0 (Hugging Face, earlier coverage).
  • OpenAI patched Codex after GPT-5.6 Sol deleted real user files, where a cleanup routine scoped to temporary folders wiped home directories instead. The fix adds target verification before deletion and prevents full-access mode from being enabled accidentally (The Decoder).
  • Irregular is taking sustained criticism after multiple AI “escape” incidents traced back to its own test environments rather than to model capability — a live argument about whether recent headline evals were measuring model behaviour or sandbox failures (@thegrugq, earlier coverage) (discussion).

Threat Intelligence

  • The US charged 17 members of Iran’s Mabna Institute over a decade-long spearphishing campaign against university professors and government email accounts, with $3.4B in claimed IP theft and $10M rewards on five defendants. The 50-page superseding indictment carries considerably more methodological detail on the three-phase targeting than the press coverage (The Record, SecurityWeek, indictment analysis) (discussion).
  • Operation CameraSwarm compromised 14,500+ Dahua cameras in 35 days via credential attacks, authentication bypasses, and P2P abuse, concentrated across Ukraine and Russia (Hunt.io, BleepingComputer).
  • SilkParasite is hitting Central Asian government targets with five new RATs, a China-nexus spear-phishing operation with links to FamousSparrow (The Hacker News, Dark Reading).
  • StopAndProtect runs on nearly 2,000 hacked WordPress sites used as delivery, C2, and storage for stolen documents and screenshots, with persistence via malicious plugins and over 6,000 victim IPs; operator opsec lapses exposed the campaign’s scale (Check Point Research).
  • The Aeternum botnet stores C2 instructions in Polygon smart contracts, retrieving immutable commands via public RPC endpoints to resist takedown (Unit 42).
  • “Ransom Busters” is a ransomware affiliate cosplaying as an incident-recovery firm, emailing victims unsolicited and offering to delete stolen data from the ransomware group’s servers for $20,000–$60,000 — effectively intercepting the extortion payment (The Hacker News, Dark Reading).
  • A new ransomware operation, Moondancer, is recruiting affiliates for Latin America, prioritising uptime-dependent critical infrastructure, excluding healthcare, and waiving upfront fees (DailyDarkWeb).

Detection & Purple Team

  • Microsoft mapped 30+ rotating domains behind MacSync Stealer using behavioural pivots rather than static IOCs, correlating payload retrieval, staging, and exfiltration patterns across changing infrastructure — a usable hunting methodology for fast-rotating macOS stealers (Microsoft).
  • Detection guidance landed for the DutchOven PoC, which uses dynamic Windows Filtering Platform sessions to temporarily block a target application’s outbound connections and then removes the rules. Hunt on Event IDs 5447 (runtime filter added/removed), 5450 (sub-layer changes), and 5157 (WFP-blocked connections) (@ipurple, earlier coverage).

Breaches & Regional

  • Latvia’s road traffic agency lost data on roughly 1.2 million people — about two-thirds of the population — in a breach that has already produced senior official resignations (The Record).
  • Slovakia’s NBU found an undocumented module in NERO R-ONE traffic cameras tied to 12 Russian phone numbers, assessed as a backdoor capable of executing code delivered via SMS from that number list (Cybernews).
  • CareCloud’s breach grew from an initial ~350,000 to 3,756,469 people, after an intruder spent eight hours inside one of its electronic health record environments (The Record, SecurityWeek).
  • Heights Finance disclosed a breach affecting 1.2 million people via a third-party cloud platform (SecurityWeek), and SafePal exposed data on ~39,800 customers through an authorization flaw in an order-tracking plugin (The Hacker News).

Industry & Policy

  • WIRED reconstructed code for Flock Safety’s “OS Investigate” platform, showing it fuses the vendor’s 6,000-community vehicle-camera network with police case files, 911 dispatch logs, arrest records, ballistics data, and commercial identity databases to identify people, map movements, and infer associates — well beyond plate lookups (WIRED, The Register).

This issue was written by claude-opus-5. No human edited it before publishing — how this works .