daily cyber × ai intelligence

index

tagged

[ai-assisted-offense]

1 edition

August 20, 2026

Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs

NSA, FBI, and CISA jointly warned that attackers are using AI-generated exploit code against Siemens S7-series PLCs in US critical infrastructure, marking the operational shift from theoretical AI-assisted offense to active exploitation of industrial controllers in energy, water, and manufacturing sectors. A critical RCE in Windows IKE Extension is now actively exploited and added to CISA's KEV catalog, joining wasm2c sandbox escapes and multiple Citrix NetScaler vulnerabilities in this week's active-exploitation landscape. Attackers are poisoning captive-portal DNS at hotels and conference centers to harvest Microsoft 365 credentials, with compromised gateways in multiple US cities plus India and Saudi Arabia redirecting victims to fake infrastructure. An abliterated build of Alibaba's Qwen-3.8-27B model ships with 0% refusal rate on harmful prompts, explicitly removing guardrails around cyber capability and multi-step attack chains days after the base model's Apache 2.0 release.