Find notable cyber news and cases, enriched with sources, timelines, and signals.

Claude-assisted porting of a WAGO 750-852 RCE exploit to WAGO 750-831

Technical Analysis
First reported
Last updated
Happening score
H score 14
1 unique sources, 1 articles

Summary

Hide ▲

Forescout’s Vedere Labs showed that Anthropic’s Claude could adapt a working RCE exploit from WAGO 750-852 to the related WAGO 750-831, increasing concern that adjacent OT targets can be escalated with AI-assisted experimentation. The exercise moved beyond simple proof of vulnerability and into controlled payload development, highlighting how PLC exploit porting can become faster once the initial analysis barrier is crossed. A later attempt to extend the work into a command-and-control implant went further and bricked the PLC, underscoring the operational risk of aggressive payload iteration. The effort also consumed hundreds of dollars and more than eight hours, showing that the workflow was slow but still practical enough to watch closely.

Related Happenings

U.S. agencies expand PLC-targeting warning and guidance

Public Sector Action
H score22 First: 29.07.2026 16:48 Last: 29.07.2026 16:48 Sources 1

About this happening: U.S. agencies and CISA expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers, raising immediate operational risk...

Apple A12/A13 SecureROM USB DMA underflow with public usbliter8 exploit security flaw

Vulnerability
H score0 First: 19.06.2026 21:37 Last: 19.06.2026 21:37 Sources 1

About this happening: A public usbliter8 exploit now reaches arbitrary code execution in Apple's SecureROM, exposing an unpatchable USB DMA underflow flaw across A12, A13, S4, and S5*...

AISI and NCSC guidance on cybersecurity basics after Mythos Preview testing

Public Sector Action
H score25 First: 14.04.2026 12:30 Last: 14.04.2026 12:30 Sources 1

About this happening: The UK AI Security Institute (AISI) and National Cyber Security Centre (NCSC) urged organizations to strengthen cybersecurity basics after evaluating Anthropic’s Myt...

CISA April 7 Rockwell Automation/Allen-Bradley PLC mitigation advisory

Advisory/Mitigation
H score32 First: 08.04.2026 11:15 Last: 08.04.2026 11:15 Sources 1

About this happening: CISA’s April 7 mitigation advisory on internet-facing OT assets now also covers an ongoing Iranian cyber campaign against US critical infrastructure. In the ...

Iranian-affiliated US CNI OT attack campaign

Campaign
H score33 First: 08.04.2026 11:15 Last: 08.04.2026 11:15 Sources 1

About this happening: An Iranian-affiliated campaign is targeting internet-exposed industrial systems at US critical infrastructure organizations, with activity seen against Rockwell Auto...

Timeline

  1. 01.09.2026 15:37 2 articles · 8h ago

    Claude ports a WAGO PLC exploit to a related model

    Initial Disclosure

    Researchers at Forescout’s Vedere Labs used Claude Code, Ghidra, and a physical target device to adapt a working remote code execution exploit from the WAGO 750-852 PLC to the related WAGO 750-831 PLC, building on CVE-2021-31886 in the Nucleus FTP server. Claude confirmed the flaw through live probing and static firmware analysis, generated a crashing payload, then—after guidance changes including a switch from Claude Sonnet 4.6 to Claude Opus 4.6 and instructions to ask for help on firmware details—produced two working payloads within 12 minutes. A later attempt to extend the work into a command-and-control implant wrote to flash-mapped memory and permanently bricked the device, and the final RCE development stage consumed over $500 in API usage across a session lasting more than eight hours.

    Show sources