Return to Threats

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

thehackernews.com 2026-09-02 malicious AI use Critical

What Happened

Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command

Why It Matters

According to the report, Forescout Research – Vedere Labs used Anthropic's Claude to help port an existing pre-authentication RCE exploit for CVE-2021-31886 from one WAGO PLC model to another, successfully achieving execution of attacker-supplied ARM shellcode on live hardware. The factual report shows a concrete case where a general-purpose LLM accelerates adaptation of OT/ICS exploit code across device variants, lowering the skill and time required for exploitation. From RealGround's perspective, this demonstrates how LLMs can be repurposed as capability amplifiers for offensive cyber operations, particularly in critical infrastructure environments where exploit portability is traditionally a barrier. Practically, organizations should assume adversaries can similarly leverage LLMs to refine or repurpose exploits and should prioritize continuous AI-aware red teaming, hardening of AI-assisted development workflows, and explicit governance for how staff may use LLMs in vulnerability research and exploit handling.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/researchers-use-claude-to-port-pre-auth.html

Talk to AI CISO