View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

AI-generated scripts target internet-exposed Siemens S7 PLCs

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Suspected Russian Hackers Abuse Google OAuth and WhatsApp to Hijack Accounts
    Suspected Russian hackers are using Google OAuth and WhatsApp linking to hijack accounts.
    • Targets include academia, aerospace and defense, governments, and think tanks in Europe and the United States.
    • Threat clusters UNC6293, UNC7005, and UNC5976 are involved.
    • The activity abuses legitimate Google authentication flows and WhatsApp device-linking processes.
    • The clusters have singled out individuals in cyber espionage operations.
      ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ“‹ ADVISORIES

  • AI-generated scripts target internet-exposed Siemens S7 PLCs
    Attackers are using AI-generated scripts to target Siemens S7 PLCs in critical infrastructure.
    • The threat affects water, manufacturing, energy, chemical, food and agriculture, commercial, and defense sectors.
    • Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 PLCs are targeted.
    • Attackers scan for exposed PLCs using Censys and ZoomEye, including systems with outdated software or weak authentication.
    • AI coding assistants and snap7.dll/python-snap7 libraries create tools disguised as OT monitoring software.
    • The tools use S7comm to read and write PLC memory, configuration data, and ladder logic programs.
      ๐Ÿ“Ž Coverage: theregister.com ยท ๐Ÿ‘ via r/cybersecurity

๐Ÿ”“ CVEs & KEV

  • CVE-2026-19586 โ€” CVSS 9.3 โ€” Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server i...

  • CVE-2026-73256 โ€” CVSS 9.1 โ€” Mongoose HTTP/1.0 Reverse-Proxy Request Smuggling (CVE-2026-73256)

  • CVE-2026-66001 โ€” CVSS 8.5 โ€” Frappe: Improper Authorization in OAuth2 Consent EndpointFrappe is a full-sta...

  • CVE-2026-53587 โ€” CVSS 7.5 โ€” libgit2 - Unauthenticated network-reachable heap out-of-bounds read in transp...

  • CVE-2026-62315 โ€” CVSS 7.1 โ€” Frappe: Mass assignment via set_valueFrappe is a full-stack web application f...

  • CVE-2026-66002 โ€” CVSS 6.9 โ€” Frappe: User Enumeration via PDDRFrappe is a full-stack web application frame...

  • CVE-2026-63654 โ€” CVSS 6.9 โ€” Frappe: Unauthenticated Workflow approval via confirm_actionFrappe is a full-...

  • CVE-2026-49976 โ€” CVSS 6.5 โ€” Snipe-IT: User Account Escalation via CSV ImportSnipe-IT is an IT asset/licen...

  • CVE-2026-53586 โ€” CVSS 6.5 โ€” libgit2: HTTP transport can leak credentials to an offsite redirect targetlib...

  • CVE-2026-53583 โ€” CVSS 6.5 โ€” libgit2: Inverted IP SubjectAltName Comparison in OpenSSL Backendlibgit2 is a...

  • CVE-2026-55482 โ€” CVSS 6.3 โ€” Snipe-IT: Multi-Tenancy Bypass via Bulk Asset UpdateSnipe-IT is an IT asset/l...

  • CVE-2026-19683 โ€” CVSS 6.3 โ€” Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authenticati...

  • CVE-2026-9033 โ€” CVSS 6.0 โ€” Unauthenticated Captive Portal Session Termination and Forced Logout in Omada...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check