Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Utilized to Transfer PLC Exploit, Cost and Time Intensive

AI Utilized to Transfer PLC Exploit, Cost and Time Intensive

Posted on September 1, 2026 By CWS

Researchers at Forescout’s Vedere Labs recently leveraged Anthropic’s AI tool, Claude, to migrate a remote code execution (RCE) exploit between two models of WAGO programmable logic controllers (PLCs). The process, while ultimately successful, demanded significant oversight, several hours of labor, and incurred hundreds of dollars in API fees.

Background on the Experiment

The team began with an exploit crafted for the WAGO 750-852 PLC, which exploited CVE-2021-31886. This vulnerability is a pre-authentication buffer overflow in the Nucleus FTP server, enabling unauthorized attackers to execute arbitrary ARM shellcode on the affected PLC. The goal was to adapt this exploit for the WAGO 750-831 model, evaluating whether AI could advance it to a full command-and-control implant, particularly after recent PLC attacks in the water sector.

Technical Challenges and AI Intervention

Claude Code, the AI tool, was equipped with access to a terminal, reference files, the reverse-engineering tool Ghidra, and the PLC itself. It confirmed the vulnerability using live probing combined with static firmware analysis, eventually generating a payload that caused the PLC to crash. This confirmed the flaw’s presence, but converting it into a controlled code execution proved to be complex.

Initially, the AI chased misleading paths, necessitating researcher intervention to adjust its analysis. Progress was stagnant until the team switched AI versions from Claude Sonnet 4.6 to Claude Opus 4.6. This version was instructed to seek assistance when uncertain about firmware specifics. A significant breakthrough was achieved when the AI identified and corrected why the injected code was being erased.

Outcome and Future Implications

Following this adjustment, Claude rapidly produced two functional payloads within 12 minutes. Researchers observed that although the initial execution was labor-intensive, subsequent iterations were swift, highlighting the scalability potential of this approach.

A subsequent attempt to develop a command-and-control implant faced obstacles. During this process, one payload inadvertently wrote to a flash memory region, permanently damaging the PLC. The financial aspect was notable, with the final RCE development phase alone exceeding $500 in API costs over more than eight hours.

Forescout remarked that while a human researcher might achieve results faster and more economically without AI, the potential reduction in expert intervention needed over time could allow AI to significantly lower marginal costs across numerous targets simultaneously.

This experiment underscores the evolving role of AI in cybersecurity, prompting questions about its future efficiency and cost-effectiveness in similar tasks.

Security Week News Tags:AI, API costs, Claude, command-and-control, CVE-2021-31886, cyber-physical systems, Cybersecurity, Forescout, Ghidra, ICS, Nucleus FTP, PLC exploit, RCE, WAGO

Post navigation

Previous Post: Iranian Hackers Use Job Offers to Spread Cross-Platform Malware
Next Post: Stealthy Windows Backdoor Evades Detection Until Triggered

Related Posts

RubyGems Halts Registrations Amid Security Threat RubyGems Halts Registrations Amid Security Threat Security Week News
Coyote Banking Trojan First to Abuse Microsoft UIA Coyote Banking Trojan First to Abuse Microsoft UIA Security Week News
Over 100 Organizations Targeted in ShinyHunters Phishing Campaign Over 100 Organizations Targeted in ShinyHunters Phishing Campaign Security Week News
Emerging Banking Trojans Disrupt Global Cybersecurity Emerging Banking Trojans Disrupt Global Cybersecurity Security Week News
Exploited Vulnerability Impacts Over 80,000 Roundcube Servers Exploited Vulnerability Impacts Over 80,000 Roundcube Servers Security Week News
Reclaiming Control: How Enterprises Can Fix Broken Security Operations Reclaiming Control: How Enterprises Can Fix Broken Security Operations Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark