Critical

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

The Hacker News
Actively Exploited

Overview

Forescout Research - Vedere Labs has successfully adapted a pre-authentication remote code execution (RCE) exploit from one model of WAGO programmable logic controller (PLC) to another, using Anthropic's Claude AI to assist in the process. This exploit targets CVE-2021-31886, which involves a stack-based buffer overflow in the Nucleus FTP server when processing the USER command. The researchers were able to execute attacker-supplied ARM shellcode on actual hardware, demonstrating the potential risks associated with this vulnerability. Companies using affected WAGO PLCs need to be aware of this exploit as it poses a significant risk of unauthorized access and control of their systems. This incident serves as a reminder of the vulnerabilities that can exist in industrial control systems and the need for robust security measures.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: WAGO programmable logic controllers (PLCs), Nucleus FTP server affected by CVE-2021-31886.
  • Action Required: Organizations should apply any available patches for CVE-2021-31886 from WAGO, if not already done.
  • Timeline: Disclosed on 2021-09-14

Original Article Summary

Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command

Impact

WAGO programmable logic controllers (PLCs), Nucleus FTP server affected by CVE-2021-31886.

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Disclosed on 2021-09-14

Remediation

Organizations should apply any available patches for CVE-2021-31886 from WAGO, if not already done. Regularly update and secure PLC firmware and ensure proper network segmentation to limit access to these devices. Implement monitoring for unusual activity that could indicate exploitation attempts.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Exploit, Vulnerability, and 1 more.

Related Coverage

How AI Agents Can Trigger Runaway Costs for Enterprises

darkreading

A new concern has emerged regarding the use of AI agents, particularly in the context of unbounded consumption, which OWASP ranks as a significant risk for large language model (LLM) applications. This issue arises when AI systems operate without proper constraints, potentially leading to excessive resource usage and runaway costs for enterprises. Companies leveraging LLM technologies could face financial strain as these agents consume resources beyond expected limits, which could impact budgets and operational efficiency. It’s crucial for organizations to implement controls and monitor AI usage to mitigate these risks effectively. Understanding and addressing this issue is essential for businesses to avoid unexpected expenses and ensure sustainable AI deployment.

Sep 21, 2026

BigCommerce alerts merchants of data breach linked to Ribon apps

BleepingComputer

BigCommerce has informed several merchants about data breaches linked to third-party Ribon applications. Attackers gained access to credentials for these apps and exploited them to insert malicious scripts into online stores. This breach poses a significant risk to affected merchants, potentially compromising customer data and undermining the integrity of their online platforms. The incident raises concerns about the security of third-party integrations and emphasizes the need for merchants to review their app permissions and security practices. Merchants using Ribon applications should take immediate action to secure their accounts and monitor for unusual activity.

Sep 21, 2026

CISA alerts of active exploitation of three Linux kernel flaws

BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of three vulnerabilities in the Linux kernel, with one being classified as critical. These flaws could allow attackers to gain unauthorized access or control over affected systems, posing significant risks to organizations that rely on Linux-based infrastructure. Users and administrators of Linux systems are urged to take immediate action to protect their environments. The vulnerabilities affect various distributions of Linux, and failure to address them could lead to serious security breaches. As these exploits are currently active, it is crucial for those using Linux to stay informed and apply necessary updates promptly.

Sep 21, 2026

ShinyHunters Hacked Clop. Now What About Clop's Victims?

darkreading

ShinyHunters, a notorious hacking group, has reportedly defaced Clop’s Dark Web site and claims to have stolen data belonging to Clop's victims. This action raises concerns for organizations that previously paid ransoms to Clop, as they could face renewed extortion attempts. The stolen data could expose sensitive information, putting these companies at further risk. This incident highlights the ongoing cycle of ransomware attacks and the challenges organizations face in protecting their data after paying ransoms. As the situation develops, affected organizations will need to assess their security postures and prepare for potential follow-up attacks.

Sep 21, 2026

Cybercriminals Are Hiding New Malware in Torrents for Popular Films

darkreading

Recent reports indicate that cybercriminals are embedding malware into torrent files of popular films, targeting users in Africa, particularly in Kenya and Uganda. These malicious files are designed to compromise the devices of individuals who download them, putting their personal information and security at risk. The trend of hiding malware in torrents is concerning, as many users may not be aware of the dangers associated with downloading files from unofficial sources. This incident serves as a reminder for users to be cautious when downloading content online and to consider using security software to detect potential threats. As this method of distribution becomes more common, it raises serious questions about the safety of torrenting and the need for increased public awareness about cybersecurity risks.

Sep 21, 2026

WordPress Click2Shell flaw lets hackers execute PHP on the server

BleepingComputer

A new vulnerability called 'Click2Shell' has been identified in the Core component of WordPress, allowing attackers to execute PHP code on affected servers. This cross-site request forgery (CSRF) flaw poses a significant risk as it could enable unauthorized actions on behalf of users, potentially leading to full server compromise. Technical details and a proof-of-concept exploit have already been published, raising concerns about its exploitation. WordPress users, particularly those running outdated versions, should take this threat seriously. Implementing security updates as soon as they become available is crucial to protect against potential attacks.

Sep 21, 2026