Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Rise of AI-Powered PLC Exploits: A Growing Concern for Industrial Security




A recent study by Forescout has shown that AI can successfully port a working exploit from one PLC model to another with no source code and no debugger access. The research highlights the growing concern for the security of industrial control systems and the potential for AI-powered PLC exploits to make sophisticated attacks easier to reproduce. As AI continues to improve, it is essential to take proactive measures to secure industrial control systems and prevent potential breaches.

  • The recent research by Forescout on porting a PLC exploit using AI has shed light on the vulnerabilities of industrial control systems (ICS) and the growing threat of advanced persistent threats (APTs).
  • The PLC exploit was successfully ported from one PLC model to another with no source code and no debugger access, using AI-generated payloads and tools like Claude Code and Ghidra.
  • The process required extensive guidance and took several attempts to complete, costing $535.74 in API fees.
  • The final exploit development stage consumed $535.74 in API usage, based on 2.6k input tokens and 1.3M output tokens.
  • The study highlights the growing concern for the security of industrial control systems and the potential for AI-powered PLC exploits to make sophisticated attacks easier to reproduce.
  • The study emphasizes the importance of improving security measures to protect industrial control systems and serves as a wake-up call for industries and organizations to take proactive measures to secure their systems.



  • The recent research by Forescout on the porting of a PLC exploit using AI has shed new light on the vulnerabilities of industrial control systems (ICS) and the growing threat of advanced persistent threats (APTs). The study, which involved the use of AI-generated payloads to attack a different PLC model, has significant implications for the security of critical infrastructure.

    The PLC (Programmable Logic Controller) is a common device used in industrial settings to control and automate processes. However, its lack of security features and vulnerability to exploitation have made it a prime target for hackers. The research, conducted by Forescout, aimed to determine whether AI could successfully port a working exploit from one PLC model to another with no source code and no debugger access.

    The researchers started by exploiting the CVE-2021-31886 vulnerability in the Nucleus FTP server, which is commonly used in PLCs. They then ported the exploit to a related but distinct PLC model, the WAGO 750-831, using the Claude Code and Ghidra tools. The process required extensive guidance and took several attempts to complete.

    The final exploit development stage cost $535.74 in API fees during an 8-hour, 32-minute session, and the researchers had to guide Claude through several dead ends, provide disassembly details, and switch to a larger context model when the smaller sessions ran out of space. The final RCE (Remote Code Execution) development stage consumed $535.74 in API usage, based on 2.6k input tokens and 1.3M output tokens.

    The researchers were able to successfully extend the working ICMP and UDP payloads into a full command-and-control implant, but the process was fragile and prone to error. The researchers also discovered that the PLC's memory layout was not designed to handle the AI-generated payloads, which led to the permanently bricking of the device.

    The study highlights the growing concern for the security of industrial control systems. The use of AI to port PLC exploits has the potential to make sophisticated attacks easier to reproduce across exposed devices. The researchers' findings suggest that the idea that industrial systems are simply too difficult to hack may not hold for much longer.

    The study also emphasizes the importance of not dismissing vulnerabilities on OT (Operational Technology) devices merely because exploitation appears difficult today. As AI continues to reduce the time, cost, and expertise needed to develop more advanced attacks against PLCs, the risk of successful exploitation increases.

    The researchers' study demonstrates the potential of AI-powered PLC exploits and highlights the need for improved security measures to protect industrial control systems. The study serves as a wake-up call for industries and organizations to take proactive measures to secure their systems and prevent potential breaches.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Rise-of-AI-Powered-PLC-Exploits-A-Growing-Concern-for-Industrial-Security-ehn.shtml

  • https://securityaffairs.com/198296/hacking/536-and-8-hours-ai-learns-to-attack-a-different-plc.html


  • Published: Wed Sep 2 08:52:28 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us