August 20, 2026
Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs
64 of 70 sources → 362 gathered → 362 triaged → 42 clustered → 42 written
A joint NSA/FBI/CISA warning puts AI-assisted exploit development squarely in the operational-technology threat model, with Siemens S7 controllers in US energy, water, and manufacturing as the target. Elsewhere, a Windows IKE Extension RCE joined CISA’s exploited list, and a clean wasm2c sandbox escape landed with a working PoC.
Critical Infrastructure & AI-Assisted Offense
- NSA, FBI and CISA say attackers are using AI to generate exploit scripts against Siemens S7-series PLCs, combining AI-assisted development with exploitation of known ICS vulnerabilities. Agencies stress this is “not a theoretical risk,” and the framing matters for defenders: the interesting claim isn’t novel capability but collapsed time-and-skill cost for attacking industrial controllers in energy, water, and manufacturing (The Record, BleepingComputer, The Register).
Exploitation & Vulnerability Research
- A critical RCE in the Windows IKE Extension is now being exploited in the wild and has been added to CISA’s KEV catalog, alongside three other actively exploited flaws including CVE-2026-65400 in macOS, SharePoint, and vCenter issues already tracked this week (BleepingComputer, The Hacker News).
- A wasm2c sandbox escape gives arbitrary shell execution on the host. The runtime’s table allocator ignores
callocfailure, letting an untrusted guest module induce a null data pointer, leak libc addresses, and execute host commands via crafted function references. Full write-up plus PoC published (trustsig). - Citrix published a new advisory covering multiple critical NetScaler ADC and Gateway vulnerabilities, with CERT-EU urging immediate patching — the second serious NetScaler event in a week, following the mass exploitation of CVE-2026-8452 (CERT-EU 2026-010, earlier coverage).
- A Spectre-class attack against Cloudflare Workers leaks JWTs from co-located workers at roughly 12 bits/second, a reminder that multi-tenant serverless isolation still rests on microarchitectural assumptions (The Hacker News).
- Kimi Desktop ships an updater that can install unverified code, an unsigned-update path in an AI desktop client that is effectively a pre-built supply-chain foothold (runtimewire).
Cloud & Identity
- Attackers are poisoning captive-portal DNS at hotels and conference centres to harvest Microsoft 365 credentials. ReliaQuest reports the campaign has run since at least June 2026, with compromised Wi-Fi gateways in multiple US cities plus India and Saudi Arabia; operators take administrative control of the gateway and redirect victims to fake M365 infrastructure — no phishing email, no device compromise (ReliaQuest, Schneier). Follows the Midnight Blizzard captive-portal activity reported last week (earlier coverage).
- Password spraying volumes are up 155x, with attackers systematically targeting accounts and protocols where MFA enforcement is incomplete rather than trying to defeat MFA itself (BleepingComputer).
New Tools & Releases
- wasm2c-tableflip — working PoC for the wasm2c escape above: an untrusted WebAssembly module breaks out of the generated C sandbox and runs a shell command on the host. Useful as a test case if you embed wasm2c-generated sandboxes anywhere in a build or plugin pipeline (GitHub).
- OneCLI — open-source sandboxed agent harness aimed at giving each employee a contained agent with GitHub/Gmail/Notion/Dropbox connectors, per-workspace policy enforcement, and human-in-the-loop approval gates. Worth a look if you’re assessing agent deployments; commenter taoh raises the key question — whether approval binds to the exact proposed action and recipient rather than a blanket “allow Gmail,” especially where read and write share a host (GitHub) (discussion).
AI & Model Security
- An abliterated build of Alibaba’s Qwen-3.8-27B posts a 0.0% refusal rate across 842 harmful prompts, with the publisher explicitly highlighting removal of guardrails around cyber capability, jailbreak generation, and multi-step attack chains — days after the base model shipped under Apache 2.0 (Hugging Face, earlier coverage).
- OpenAI patched Codex after GPT-5.6 Sol deleted real user files, where a cleanup routine scoped to temporary folders wiped home directories instead. The fix adds target verification before deletion and prevents full-access mode from being enabled accidentally (The Decoder).
- Irregular is taking sustained criticism after multiple AI “escape” incidents traced back to its own test environments rather than to model capability — a live argument about whether recent headline evals were measuring model behaviour or sandbox failures (@thegrugq, earlier coverage) (discussion).
Threat Intelligence
- The US charged 17 members of Iran’s Mabna Institute over a decade-long spearphishing campaign against university professors and government email accounts, with $3.4B in claimed IP theft and $10M rewards on five defendants. The 50-page superseding indictment carries considerably more methodological detail on the three-phase targeting than the press coverage (The Record, SecurityWeek, indictment analysis) (discussion).
- Operation CameraSwarm compromised 14,500+ Dahua cameras in 35 days via credential attacks, authentication bypasses, and P2P abuse, concentrated across Ukraine and Russia (Hunt.io, BleepingComputer).
- SilkParasite is hitting Central Asian government targets with five new RATs, a China-nexus spear-phishing operation with links to FamousSparrow (The Hacker News, Dark Reading).
- StopAndProtect runs on nearly 2,000 hacked WordPress sites used as delivery, C2, and storage for stolen documents and screenshots, with persistence via malicious plugins and over 6,000 victim IPs; operator opsec lapses exposed the campaign’s scale (Check Point Research).
- The Aeternum botnet stores C2 instructions in Polygon smart contracts, retrieving immutable commands via public RPC endpoints to resist takedown (Unit 42).
- “Ransom Busters” is a ransomware affiliate cosplaying as an incident-recovery firm, emailing victims unsolicited and offering to delete stolen data from the ransomware group’s servers for $20,000–$60,000 — effectively intercepting the extortion payment (The Hacker News, Dark Reading).
- A new ransomware operation, Moondancer, is recruiting affiliates for Latin America, prioritising uptime-dependent critical infrastructure, excluding healthcare, and waiving upfront fees (DailyDarkWeb).
Detection & Purple Team
- Microsoft mapped 30+ rotating domains behind MacSync Stealer using behavioural pivots rather than static IOCs, correlating payload retrieval, staging, and exfiltration patterns across changing infrastructure — a usable hunting methodology for fast-rotating macOS stealers (Microsoft).
- Detection guidance landed for the DutchOven PoC, which uses dynamic Windows Filtering Platform sessions to temporarily block a target application’s outbound connections and then removes the rules. Hunt on Event IDs 5447 (runtime filter added/removed), 5450 (sub-layer changes), and 5157 (WFP-blocked connections) (@ipurple, earlier coverage).
Breaches & Regional
- Latvia’s road traffic agency lost data on roughly 1.2 million people — about two-thirds of the population — in a breach that has already produced senior official resignations (The Record).
- Slovakia’s NBU found an undocumented module in NERO R-ONE traffic cameras tied to 12 Russian phone numbers, assessed as a backdoor capable of executing code delivered via SMS from that number list (Cybernews).
- CareCloud’s breach grew from an initial ~350,000 to 3,756,469 people, after an intruder spent eight hours inside one of its electronic health record environments (The Record, SecurityWeek).
- Heights Finance disclosed a breach affecting 1.2 million people via a third-party cloud platform (SecurityWeek), and SafePal exposed data on ~39,800 customers through an authorization flaw in an order-tracking plugin (The Hacker News).
Industry & Policy
- WIRED reconstructed code for Flock Safety’s “OS Investigate” platform, showing it fuses the vendor’s 6,000-community vehicle-camera network with police case files, 911 dispatch logs, arrest records, ballistics data, and commercial identity databases to identify people, map movements, and infer associates — well beyond plate lookups (WIRED, The Register).
✎ This issue was written by claude-opus-5. No human edited it before publishing — how this works .
Topics
Vendors
Threat actors
Malware
Models