<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ai-Assisted-Exploit on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ai-assisted-exploit/</link><description>Recent content in Ai-Assisted-Exploit on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ai-assisted-exploit/index.xml" rel="self" type="application/rss+xml"/><item><title>Claude Used to Port Pre-Auth RCE Exploit Across WAGO PLC Models</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-researchers-use-claude-to-port-pre-auth-rce-exploit-from-one/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-researchers-use-claude-to-port-pre-auth-rce-exploit-from-one/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> CVE-2021-31886 is a 2021 vulnerability with EPSS 0.03 and no KEV listing — exploitation pressure is low. WAGO PLCs are niche OT hardware outside most cloud/AppSec stacks, but the research technique (AI-accelerated exploit porting to embedded ARM targets) is worth understanding if you maintain any OT/ICS-adjacent environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, no active campaign, and no new detection surface are introduced by this research. The demonstrated method of using LLMs to port PLC exploits is context worth knowing for OT-adjacent threat hunting, but there is nothing actionable to write rules or run sweeps against today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This research is a concrete signal that AI tooling is meaningfully lowering the barrier for porting ICS/OT exploits — relevant if you have OT exposure on your risk register or are shaping a position on AI in offensive security for a board or customer briefing.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2021-31886 — CISA KEV: not listed, EPSS 0.03, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Linux Kernel LPE CVE-2026-53264 Gets Public PoC via AI-Assisted Research</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-researcher-says-ai-helped-develop-linux-traffic-control-race/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-researcher-says-ai-helped-develop-linux-traffic-control-race/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public PoC on GitHub for a use-after-free root LPE (CVSS 7.8) in the Linux kernel traffic-control subsystem warrants immediate attention even without KEV listing; audit which systems run CentOS Stream 9 and apply kernel updates as soon as patches are available, prioritizing multi-tenant or shared-access Linux hosts where local code execution is easier to achieve.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No active exploitation evidence yet (EPSS 0.00), but the published PoC provides behavioral reference for building Linux privilege-escalation detections; develop Sigma or EDR rules targeting anomalous tc/netlink operations followed by UID transitions to root on CentOS Stream 9 endpoints.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The more strategically significant signal here is that AI tooling materially accelerated exploit development from bug discovery to working root exploit — a trend that compresses the window between patch release and weaponization and should inform how your team prioritizes patch SLAs for critical Linux systems.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-53264 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>