The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That

The U.S. government has issued a warning regarding an active threat targeting critical infrastructure organizations within the United States. This threat involves the use of artificial intelligence (AI)-generated exploit scripts. These scripts are reportedly being used to target Siemens S7 Series Programmable Logic Controllers (PLCs).
The reported activity focuses on reconnaissance and the development of capabilities against these industrial control systems. The AI-generated scripts are described as being disguised as legitimate monitoring tools, likely to evade detection by operational technology (OT) security systems or personnel. This suggests an attempt to blend malicious activity with normal network traffic and system operations, making identification more challenging.
Siemens S7 PLCs are widely deployed in various critical infrastructure sectors globally, including energy, water, manufacturing, and transportation. These devices are fundamental to the automation and control of industrial processes. A compromise of such systems could lead to disruption of services, equipment damage, or even safety incidents depending on the specific function of the PLC and the nature of the exploit.
Exploits targeting PLCs often aim to manipulate logic, alter operational parameters, or disable the controller entirely. Reconnaissance in this context would involve mapping the network, identifying specific PLC models and firmware versions, and understanding the industrial processes they control. Capability development would then involve crafting specific commands or sequences to achieve a malicious objective, potentially leveraging known vulnerabilities or misconfigurations.
Mitigation for such threats typically involves a multi-layered approach. This includes robust network segmentation to isolate OT networks from IT networks and the internet, regular patching and firmware updates for PLCs and associated systems, and strict access controls. Furthermore, implementing intrusion detection systems (IDS) and security information and event management (SIEM) solutions tailored for OT environments can help detect anomalous activity, including the presence of disguised scripts or unusual communication patterns. Employee training on social engineering and phishing awareness is also crucial, as initial access often relies on human factors.
The emergence of AI-generated exploit scripts represents an evolving challenge in cybersecurity. While the core attack vectors against industrial control systems often remain consistent, the use of AI could potentially accelerate the development of sophisticated exploits, improve their evasiveness, and lower the barrier to entry for attackers. This development underscores the ongoing need for critical infrastructure operators to continuously adapt their security postures and invest in advanced threat detection and prevention technologies.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed