<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ai-Threats on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ai-threats/</link><description>Recent content in Ai-Threats on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 21 Aug 2026 11:38:25 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ai-threats/index.xml" rel="self" type="application/rss+xml"/><item><title>AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-ai-generated-exploit-scripts-target-siemens-s7-plcs-in-u-s-c/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-ai-generated-exploit-scripts-target-siemens-s7-plcs-in-u-s-c/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Siemens S7 PLCs are OT/ICS territory outside typical cloud/AppSec scope, but the technique of using AI-generated scripts disguised as legitimate monitoring tools is a design-relevant threat model for anyone operating industrial or hybrid environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs are published yet, but a U.S. government active-threat designation warrants developing detections for anomalous PLC communication and tools impersonating legitimate monitoring agents in OT network segments; queue a hunt playbook now.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A formal U.S. government active-threat warning against critical infrastructure is board-question territory — confirm this week whether your organization or OT vendors operate Siemens S7 equipment and brief leadership before they read it elsewhere.&lt;/li>
&lt;/ul></description></item><item><title>Phishing 3.0: AI Agents vs. AI Defenses in Email Security</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-phishing-3-0-the-fight-moves-to-agent-versus-agent/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-phishing-3-0-the-fight-moves-to-agent-versus-agent/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No exploited vulnerability or configuration to change; this is a conceptual piece on how AI-generated sender agents are outpacing signature-based email filters — useful context when evaluating email security tooling this cycle.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or ATT&amp;amp;CK-mapped TTPs, but the framing — that phishing intent is now harder to detect because the sender is an AI agent, not a human — is worth internalizing when tuning behavioral email analytics.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> No breach or regulation trigger; the AI-on-both-sides framing is useful background for board-level conversations about whether current email security investment is keeping pace with AI-enabled adversaries.&lt;/li>
&lt;/ul></description></item><item><title>US warns of AI-powered attacks on Siemens S7 PLCs in critical infrastructure</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-i/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-i/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> AI-generated exploit scripts targeting Siemens S7 PLCs represents a novel offensive technique for ICS environments, but the thin summary offers no CVE, version range, or patch to act on. Engineers supporting OT/ICS should monitor for follow-on advisories with technical specifics.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, TTPs, or detection surface are described in this advisory, leaving nothing actionable to hunt or tune. Analysts in critical infrastructure sectors should track follow-up CISA publications for actor behaviors and log sources to enable.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A formal US government warning about AI-assisted attacks on critical infrastructure PLCs warrants a check of whether the organization operates or depends on Siemens S7 equipment, and a brief to OT security owners and relevant leadership before this surfaces in board-level news cycles.&lt;/li>
&lt;/ul></description></item><item><title>AI-Powered Phishing Renders Domain Blocklists Obsolete</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-how-ai-powered-phishing-killed-blocklists-for-good/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-how-ai-powered-phishing-killed-blocklists-for-good/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Browser-level, technique-based phishing detection is a useful design principle to evaluate when assessing IdP or SSO defenses, but no specific CVE or configuration change is required today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Evaluate whether current phishing detections rely heavily on domain blocklists and investigate adding technique-based behavioral signals (e.g., credential-harvest page patterns) to supplement IOC-driven coverage.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Useful framing for a board conversation about why threat intelligence investments have diminishing returns against AI-assisted phishing — relevant for future budget and vendor evaluation discussions.&lt;/li>
&lt;/ul></description></item><item><title>Dolphin X RAT claims AI-powered victim prioritization feature</title><link>https://curasec.metacog.co.kr/insights/2026-07-24-new-dolphin-x-malware-uses-ai-to-rank-high-value-targets/</link><pubDate>Fri, 24 Jul 2026 12:43:46 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-24-new-dolphin-x-malware-uses-ai-to-rank-high-value-targets/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No KEV, EPSS, or PoC signals; no patch or configuration action is available for a newly disclosed RAT. Worth tracking as AI-assisted triage by threat actors could accelerate post-compromise dwell time on high-value hosts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The summary lacks IOCs, ATT&amp;amp;CK mappings, or campaign details needed to write detections or run a hunt. Monitor for follow-on reporting with technical indicators before acting.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Signals a maturing trend of adversaries using AI to prioritize high-value victims, which could shorten the window between initial access and targeted impact — relevant context for board-level AI risk discussions but no immediate action warranted.&lt;/li>
&lt;/ul></description></item></channel></rss>