Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Threats Emerge in the Shadows: A Looming AI-Powered Cybersecurity Crisis




A surge in AI-powered cyber threats has emerged, targeting critical infrastructure and leaving a trail of disruption, data breaches, and compromised systems in its wake. From Siemens PLC attacks to GitLab exploits and AI-powered malware, the latest wave of threats highlights the growing concern of AI-driven cybersecurity risks. As the use of AI continues to expand in various industries, it is essential to stay vigilant and take proactive measures to mitigate these threats.



  • AI-powered attacks on critical infrastructure are a growing concern.
  • Threat actors are leveraging AI to create sophisticated exploit scripts targeting internet-exposed Siemens S7 Series PLCs.
  • Legitimate scanning services are being used to identify vulnerable PLCs, which can lead to disruption of critical industrial processes and safety incidents.
  • A security flaw in GitLab allowed for active exploitation within days of public disclosure.
  • A set of 14 trojanized npm packages were found to deliver an AI-powered Linux implant dubbed RedC2 4.0.
  • A Zombie Card attack can bypass cryptographic checks to complete contactless payments using physically expired Visa credit cards.
  • Suspected Russian hackers are using legitimate authentication workflows to compromise personal accounts.
  • A remote Spectre attack against Cloudflare Workers leaked a JWT from a co-located Worker.
  • A JavaServer Pages (JSP) web shell was deployed in PTC Windchill attacks, capable of mapping sensitive vault data and decrypting credentials.
  • A security flaw in Unisoc T612 modem firmware allows for elevated access to the Android kernel.



  • The latest wave of cyber threats highlights the growing concern of AI-powered attacks on critical infrastructure. According to recent reports, threat actors are leveraging AI to create sophisticated exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across various sectors, including water, energy, and manufacturing. The U.S. government has issued a warning, stating that this is not a theoretical risk but an active threat.

    Threat actors are using legitimate scanning services to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs. Once vulnerable systems have been identified, AI-generated scripts masquerading as legitimate monitoring tools are deployed to find exploits. The exploitation of poorly secured PLCs could result in disruption of critical industrial processes, safety incidents, downtime, or equipment damage, compromise of sensitive data, and compliance violations.

    In addition to the Siemens PLC attacks, other notable security incidents have been reported. A newly disclosed security flaw in GitLab came under active exploitation within days of public disclosure. The vulnerability, CVE-2026-19478, is a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring credentials, user interaction, or obscure configuration.

    Furthermore, a set of 14 trojanized npm packages were found to masquerade as functional calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. RedC2 4.0, marketed on cybercrime forums as a cross-platform toolkit for Windows, macOS, and Linux, offers surveillance, credential theft, payload loading, and mass-operation capabilities.

    Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

    Academic researchers demonstrated a new Zombie Card attack that bypasses cryptographic checks to complete contactless payments using physically expired Visa credit cards. By taking advantage of a smartphone relay setup to alter the expiration date fed to the point-of-sale (PoS) terminal without breaking the card's cryptography, it is possible to make real in-store purchases.

    Suspected Russian Hackers Abuse Legitimate Authentication Workflows

    Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. "These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms," Google said.

    Cloudflare Workers Spectre Attack Leaks JWT

    A remote Spectre attack against Cloudflare Workers has been found to leak a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of a previous attack demonstrated in 2021. Cloudflare Workers is one of the top three edge-computing solutions and handles millions of HTTP requests per second worldwide across tens of thousands of websites every day.

    Cl0p Deploys Bespoke Web Shell in PTC Windchill Attacks

    A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software. Per ReliaQuest, the web shell is a fully equipped extortion platform capable of mapping sensitive vault data, decrypting every credential in the Windchill keystore, and running additional code by means of a custom Java class loader.

    Security Flaw in Unisoc

    Researchers disclosed a new unpatched flaw in Unisoc T612 modem firmware that, when combined with a previously disclosed remote code execution (RCE) vulnerability, could allow a threat to obtain elevated access to the Android kernel on affected devices. The exploit can be triggered by first delivering a malicious payload to the phone's modem via the RCE vulnerability and then placing a video call to the device, which the victim would need to answer.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Threats-Emerge-in-the-Shadows-A-Looming-AI-Powered-Cybersecurity-Crisis-ehn.shtml

  • https://thehackernews.com/2026/08/weekly-recap-ai-powered-plc-attacks.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-19478

  • https://www.cvedetails.com/cve/CVE-2026-19478/


  • Published: Mon Aug 24 11:53:42 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us