Daniel dos Santos reports that Frontier AI can be used to exploit flaws in programmable logic controllers used in U.S. infrastructure.
Daniel dos Santos, VP of research at Vedere Labs, reported that frontier AI can be used to exploit vulnerabilities in programmable logic controllers. These devices are critical components in U.S. water utilities, energy companies, and factory operations.
Show the rest of this summary
Researchers used the Claude AI model to port a remote code execution vulnerability from one WAGO Corp. model to another. In a test environment, the AI helped confirm the existence of a vulnerability and construct an exploit, though it required human guidance to navigate false leads. While Claude Sonnet 4.6 struggled to write working code, Claude Opus 4.6 successfully identified why shellcode was not executing and created two functional payloads in 12 minutes. However, the AI bricked the device when it attempted to improve the exploit. This research follows a other hacking campaign where suspected Iran-linked hackers targeted drinking and wastewater utilities in 12 U.S. states. These attackers changed passwords and temporarily hindered system monitoring, causing some operators to be forced to suspend water service or manage sewage floods. The White House launched Project Watershed 250 to help water utilities harden their operational technology environments.
Sources
Paywall and unreadable sources
-
AI Burnout Hits the People Charged With Defending Hospitals and Banks From Hackers
Bloomberg.com
-
OpenAI and Other Tech Giants Call for Greater Defense Against A.I. Attacks
The New York Times
-
Major tech companies call for defensive surge to defeat AI-driven hacks
Reuters
-
Is ‘Around The Clock’ Too Much?
Forbes