View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

U.S. Agencies Warn of AI-Assisted Attacks on Siemens S7 PLCs

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • U.S. Agencies Warn of AI-Assisted Attacks on Siemens S7 PLCs
    Federal agencies warn of an active AI-assisted campaign targeting Siemens S7 PLCs.

    • The activity targets U.S. critical manufacturing, energy, water, chemical, food and agriculture, and commercial facilities.
    • Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 PLCs are targeted, including S7-1500 F-series safety controllers.
    • Threat actors use Censys and ZoomEye to find internet-exposed PLCs running outdated software or using weak authentication.
    • AI-generated Python scripts incorporating snap7.dll or python-snap7 mimic legitimate monitoring tools and provide read/write access through S7comm.
    • The actors can read or modify PLC memory, configuration data, data blocks, and ladder logic programs.
      πŸ“„ Source: media.defense.gov Β· πŸ“Ž Coverage: cyberscoop.com Β· πŸ‘ via SecurityWeek
  • Claude Opus uncovers SAML authentication bypasses across four projects
    Oblique Security used Claude Opus to uncover SAML authentication bypasses.

    • Affected projects included Authentik, litesaml/lightsaml, OneUptime, and Java saml-client.
    • Authentik’s CVE-2026-57580 enabled account takeover under non-default USERNAME_LINK or EMAIL_LINK matching; fixed in 2026.2.6 and 2026.5.5.
    • Signature-wrapping flaws caused applications to trust unsigned identity data despite valid XML signatures.
    • Signature-validation bypasses in authentication requests, attribute queries, and logout requests enabled information disclosure or arbitrary logouts.
    • Unauthenticated XML processing also exposed multiple libraries to excessive-memory denial-of-service conditions.
      πŸ“„ Source: oblique.security Β· πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News

πŸ“‹ CVEs & KEV

  • CVE-2026-49420 β€” CVSS 8.8 β€” Buffer overflow in libalias RTSP handlerThe RTSP handler in libalias rewrote ...

  • CVE-2026-49422 β€” CVSS 8.4 β€” Use-after-free in TCP RACK stack option handlerThe RACK setsockopt(2) handler...

  • CVE-2026-49429 β€” CVSS 7.8 β€” Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctlThe ZFS_IOC_USERSPACE_MAN...

  • CVE-2026-19582 β€” CVSS 7.8 β€” Binutils: stack buffer overflow in gnu binutils in rsrc_print_name from an un...

  • CVE-2026-75963 β€” CVSS 7.5 β€” Events Made Easy through 3.2.5 - Authenticated (Contributor+) Local File Inclusion...

  • CVE-2026-76956 β€” CVSS 7.5 β€” In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's r...

πŸ“‹ ADVISORIES

  • πŸ“„ Source for Zimbra CVE-2026-73570 RCE Exploited in the Wild β€” cyber.gc.ca

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check