Attackers are increasingly abusing exposed infrastructure, trusted software ecosystems, and AI-assisted tooling, with active exploitation seen against Siemens PLCs, GitLab, PTC Windchill, and trojanized npm packages. Researchers also highlighted fresh techniques and leaks affecting Visa contactless payments, Cloudflare Workers, Unisoc modem firmware, and corporate cloud credentials. #Siemens #S7Series #GitLab #PTCWindchill #RedC2 #Cl0p #Unisoc #CloudflareWorkers #Visa #AWS #ScreenConnect #DCRat
Keypoints
- AI is being used to generate exploit scripts against internet-exposed Siemens S7 PLCs.
- A critical GitLab flaw was actively exploited shortly after disclosure.
- Trojanized npm packages delivered the RedC2 4.0 Linux backdoor.
- Cl0p used a custom web shell in attacks against PTC Windchill and FlexPLM.
- Researchers exposed new attack methods against Visa cards, Cloudflare Workers, Unisoc firmware, and leaked AWS keys.
Read More: https://thehackernews.com/2026/08/weekly-recap-ai-powered-plc-attacks.html