Claude-assisted porting of a WAGO 750-852 RCE exploit to WAGO 750-831
Technical Analysis
Summary
Hide ▲
Show ▼
Forescout’s Vedere Labs showed that Anthropic’s Claude could adapt a working RCE exploit from WAGO 750-852 to the related WAGO 750-831, increasing concern that adjacent OT targets can be escalated with AI-assisted experimentation. The exercise moved beyond simple proof of vulnerability and into controlled payload development, highlighting how PLC exploit porting can become faster once the initial analysis barrier is crossed. A later attempt to extend the work into a command-and-control implant went further and bricked the PLC, underscoring the operational risk of aggressive payload iteration. The effort also consumed hundreds of dollars and more than eight hours, showing that the workflow was slow but still practical enough to watch closely.
Related Happenings
U.S. agencies expand PLC-targeting warning and guidance
Public Sector Action
H score22
First: 29.07.2026 16:48
Last: 29.07.2026 16:48
Sources 1
About this happening:
U.S. agencies and CISA expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers, raising immediate operational risk...
U.S. agencies expand PLC-targeting warning and guidance
Public Sector ActionAbout this happening: U.S. agencies and CISA expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers, raising immediate operational risk...
Apple A12/A13 SecureROM USB DMA underflow with public usbliter8 exploit security flaw
Vulnerability
H score0
First: 19.06.2026 21:37
Last: 19.06.2026 21:37
Sources 1
About this happening:
A public usbliter8 exploit now reaches arbitrary code execution in Apple's SecureROM, exposing an unpatchable USB DMA underflow flaw across A12, A13, S4, and S5*...
Apple A12/A13 SecureROM USB DMA underflow with public usbliter8 exploit security flaw
VulnerabilityAbout this happening: A public usbliter8 exploit now reaches arbitrary code execution in Apple's SecureROM, exposing an unpatchable USB DMA underflow flaw across A12, A13, S4, and S5*...
AISI and NCSC guidance on cybersecurity basics after Mythos Preview testing
Public Sector Action
H score25
First: 14.04.2026 12:30
Last: 14.04.2026 12:30
Sources 1
About this happening:
The UK AI Security Institute (AISI) and National Cyber Security Centre (NCSC) urged organizations to strengthen cybersecurity basics after evaluating Anthropic’s Myt...
AISI and NCSC guidance on cybersecurity basics after Mythos Preview testing
Public Sector ActionAbout this happening: The UK AI Security Institute (AISI) and National Cyber Security Centre (NCSC) urged organizations to strengthen cybersecurity basics after evaluating Anthropic’s Myt...
CISA April 7 Rockwell Automation/Allen-Bradley PLC mitigation advisory
Advisory/Mitigation
H score32
First: 08.04.2026 11:15
Last: 08.04.2026 11:15
Sources 1
About this happening:
CISA’s April 7 mitigation advisory on internet-facing OT assets now also covers an ongoing Iranian cyber campaign against US critical infrastructure. In the ...
CISA April 7 Rockwell Automation/Allen-Bradley PLC mitigation advisory
Advisory/MitigationAbout this happening: CISA’s April 7 mitigation advisory on internet-facing OT assets now also covers an ongoing Iranian cyber campaign against US critical infrastructure. In the ...
Iranian-affiliated US CNI OT attack campaign
Campaign
H score33
First: 08.04.2026 11:15
Last: 08.04.2026 11:15
Sources 1
About this happening:
An Iranian-affiliated campaign is targeting internet-exposed industrial systems at US critical infrastructure organizations, with activity seen against Rockwell Auto...
Iranian-affiliated US CNI OT attack campaign
CampaignAbout this happening: An Iranian-affiliated campaign is targeting internet-exposed industrial systems at US critical infrastructure organizations, with activity seen against Rockwell Auto...
Timeline
-
01.09.2026 15:37 2 articles · 8h ago
Claude ports a WAGO PLC exploit to a related model
Initial DisclosureResearchers at Forescout’s Vedere Labs used Claude Code, Ghidra, and a physical target device to adapt a working remote code execution exploit from the WAGO 750-852 PLC to the related WAGO 750-831 PLC, building on CVE-2021-31886 in the Nucleus FTP server. Claude confirmed the flaw through live probing and static firmware analysis, generated a crashing payload, then—after guidance changes including a switch from Claude Sonnet 4.6 to Claude Opus 4.6 and instructions to ask for help on firmware details—produced two working payloads within 12 minutes. A later attempt to extend the work into a command-and-control implant wrote to flash-mapped memory and permanently bricked the device, and the final RCE development stage consumed over $500 in API usage across a session lasting more than eight hours.
Show sources
- Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars — www.securityweek.com — 01.09.2026 15:37
- Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars — www.securityweek.com — 01.09.2026 15:37