September 3, 2026
- Forescout ported a pre-auth PLC exploit to new hardware using Claude. Vedere Labs adapted a working exploit for CVE-2021-31886 (stack overflow in the Nucleus FTP server's
USERhandling) from one WAGO PLC model to another, landing attacker-supplied ARM shellcode on live hardware (The Hacker News). The cost framing matters as much as the result: hours of iteration, hundreds of dollars, and expert oversight throughout (SecurityWeek). · AI-Enabled Attacks & Agent Security
in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion