<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ics-Ot on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ics-ot/</link><description>Recent content in Ics-Ot on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ics-ot/index.xml" rel="self" type="application/rss+xml"/><item><title>Claude Used to Port Pre-Auth RCE Exploit Across WAGO PLC Models</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-researchers-use-claude-to-port-pre-auth-rce-exploit-from-one/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-researchers-use-claude-to-port-pre-auth-rce-exploit-from-one/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> CVE-2021-31886 is a 2021 vulnerability with EPSS 0.03 and no KEV listing — exploitation pressure is low. WAGO PLCs are niche OT hardware outside most cloud/AppSec stacks, but the research technique (AI-accelerated exploit porting to embedded ARM targets) is worth understanding if you maintain any OT/ICS-adjacent environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, no active campaign, and no new detection surface are introduced by this research. The demonstrated method of using LLMs to port PLC exploits is context worth knowing for OT-adjacent threat hunting, but there is nothing actionable to write rules or run sweeps against today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This research is a concrete signal that AI tooling is meaningfully lowering the barrier for porting ICS/OT exploits — relevant if you have OT exposure on your risk register or are shaping a position on AI in offensive security for a board or customer briefing.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2021-31886 — CISA KEV: not listed, EPSS 0.03, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-ai-generated-exploit-scripts-target-siemens-s7-plcs-in-u-s-c/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-ai-generated-exploit-scripts-target-siemens-s7-plcs-in-u-s-c/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Siemens S7 PLCs are OT/ICS territory outside typical cloud/AppSec scope, but the technique of using AI-generated scripts disguised as legitimate monitoring tools is a design-relevant threat model for anyone operating industrial or hybrid environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs are published yet, but a U.S. government active-threat designation warrants developing detections for anomalous PLC communication and tools impersonating legitimate monitoring agents in OT network segments; queue a hunt playbook now.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A formal U.S. government active-threat warning against critical infrastructure is board-question territory — confirm this week whether your organization or OT vendors operate Siemens S7 equipment and brief leadership before they read it elsewhere.&lt;/li>
&lt;/ul></description></item><item><title>US warns of AI-powered attacks on Siemens S7 PLCs in critical infrastructure</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-i/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-i/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> AI-generated exploit scripts targeting Siemens S7 PLCs represents a novel offensive technique for ICS environments, but the thin summary offers no CVE, version range, or patch to act on. Engineers supporting OT/ICS should monitor for follow-on advisories with technical specifics.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, TTPs, or detection surface are described in this advisory, leaving nothing actionable to hunt or tune. Analysts in critical infrastructure sectors should track follow-up CISA publications for actor behaviors and log sources to enable.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A formal US government warning about AI-assisted attacks on critical infrastructure PLCs warrants a check of whether the organization operates or depends on Siemens S7 equipment, and a brief to OT security owners and relevant leadership before this surfaces in board-level news cycles.&lt;/li>
&lt;/ul></description></item><item><title>Hackers Breach Polish CHP Plant via Private Cellular APN, Shut Turbine</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-hackers-breach-polish-power-plant-controls-via-private-cellu/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-hackers-breach-polish-power-plant-controls-via-private-cellu/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The attack entered through a private cellular APN used for remote OT equipment access — a network path often assumed to be isolated. Any org running OT/SCADA with cellular-based remote access should audit that network segment for authentication controls and lateral-movement barriers, but no patch or CVE applies here.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, no ATT&amp;amp;CK-mapped TTPs, and no detection signatures are available from this item. The incident pattern — cellular APN pivot to industrial control systems — is worth noting for OT-aware threat models, but there is no actionable hunt or detection to write from current reporting.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A confirmed OT attack that disrupted heat for 50,000 residents is a strong board-level illustration of critical-infrastructure risk via unconventional network paths. Leaders at energy or utilities firms should review whether similar remote-access architectures exist in their estate; for general enterprise CISOs, this is useful context for OT risk conversations.&lt;/li>
&lt;/ul></description></item><item><title>4,400+ Rockwell PLCs Exposed Online; 22 Near Water Utility Attack Sites</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-over-4-400-rockwell-plcs-exposed-online-22-found-in-water-at/</link><pubDate>Fri, 07 Aug 2026 00:21:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-over-4-400-rockwell-plcs-exposed-online-22-found-in-water-at/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your organization runs Rockwell Automation PLCs, verify none are internet-facing — Forescout&amp;rsquo;s scan found 2,844 exposed in the US alone. No exploitation confirmed, but the attack surface is substantial; audit firewall rules and mobile-carrier connections to any OT assets this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The correlation of 22 internet-exposed Rockwell PLCs in water utility attack cities is noteworthy context, but no IOCs, TTPs, or detection opportunities are surfaced — file as threat-landscape awareness for critical infrastructure hunting programs.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> The pattern of water utility cyberattacks combined with thousands of internet-exposed industrial controllers warrants adding OT/ICS internet exposure to your next risk review; if your organization operates critical infrastructure or uses Rockwell equipment, request an exposure audit before this becomes a board question.&lt;/li>
&lt;/ul></description></item><item><title>CubePilot drone software dev hit by DNS hijacking</title><link>https://curasec.metacog.co.kr/insights/2026-07-29-cubepilot-drone-software-dev-hit-by-dns-hijacking-to-interce/</link><pubDate>Wed, 29 Jul 2026 13:07:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-29-cubepilot-drone-software-dev-hit-by-dns-hijacking-to-interce/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> DNS hijacking against a hardware/firmware vendor is a supply-chain attack vector worth understanding — audit your own domain registrar MFA and DNS provider controls, but no direct patch or action unless you&amp;rsquo;re a CubePilot customer integrating their software.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or TTPs published; file as a supply-chain DNS hijack case study for future detection design around suspicious DNS changes or unexpected certificate issuance for vendor domains.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Relevant as a vendor-risk illustration — DNS hijacking can compromise a software supplier&amp;rsquo;s delivery pipeline — but CubePilot is niche enough that most enterprise security leaders have no direct exposure to assess.&lt;/li>
&lt;/ul></description></item></channel></rss>