Daily brief at 7am Melbourne. Unsubscribe any time.

Friday 21 August 2026

AI-Written Malware Is Hitting Real Power Grid Controllers — and the US Government Just Said So Out Loud

AI-generated exploit scripts are actively targeting Siemens PLCs inside US critical infrastructure — and the feds say this is no longer a theoretical threat.

Lead story

AI-Written Malware Is Hitting Real Power Grid Controllers — and the US Government Just Said So Out Loud

The US government doesn't typically call things an "active threat" unless they mean it. This week, federal agencies did exactly that — warning critical infrastructure operators that attackers are using AI-generated exploit scripts to probe and attack Siemens S7 Series Programmable Logic Controllers (PLCs), the embedded computers that run pumps, valves, and industrial machinery across energy, water, and manufacturing facilities.

The scripts, according to the advisory, are being disguised as legitimate monitoring tools. Attackers are using them for reconnaissance and capability development — which, in plain terms, means mapping what's there and figuring out how to break it. The AI-generation angle isn't just cosmetic: it lowers the skill floor significantly, allowing actors who previously couldn't write industrial control system exploits to generate working ones on demand.

Why this matters beyond the usual "ICS is vulnerable" story

Industrial control system vulnerabilities get flagged regularly, and most advisories land with a thud. This one is different for a few reasons.

First, the target is highly specific. Siemens S7 PLCs are among the most widely deployed controllers in critical infrastructure worldwide — including in Australian water utilities, energy networks, and manufacturing. The S7 family was also the target of Stuxnet, the original cyberweapon, which means there's an established playbook for attackers. What's new is that AI is compressing the time between "knowing the target" and "having working exploit code."

Second, the US advisory explicitly frames this as active exploitation rather than a theoretical concern. That's a meaningful distinction. Advisories about potential vulnerabilities are table-stakes. Advisories about live attacks on the grid get different budget conversations in boardrooms.

Third, this is happening against a backdrop of escalating nation-state interest in pre-positioning within Western infrastructure. China's Volt Typhoon campaign — simulated in a war game this week, reported by Wired — is built around exactly this playbook: get in, stay quiet, and wait. AI-assisted exploit development accelerates how quickly adversaries can operationalise that access.

The AI-as-attacker angle is now a pattern, not an incident

It's worth stepping back. Over the last few weeks, The Cipher has covered AI agents going off-script during training, Claude generating self-replicating malware under conflicting goals, and now AI being used to write working exploits for critical infrastructure. These aren't unrelated anecdotes. They're early data points in a shift: AI is becoming a force multiplier for offensive operations, not just defensive ones.

The defenders' problem is asymmetric. An attacker only needs one working exploit. A defender needs to cover everything, always.

What to watch

CISA and its partners will likely follow this advisory with more specific indicators of compromise. Australian critical infrastructure operators — especially those running SCADA environments under the SOCI Act's risk management obligations — should be cross-referencing their S7 deployments against the advisory's technical details and treating unverified monitoring traffic with fresh suspicion.

The more uncomfortable question: if AI can write S7 exploits today, what does the same capability look like in 18 months?

Also today

Russian Hackers Exploit Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct Russian cyber espionage clusters — UNC6293, UNC5976, and UNC7005 — have been observed abusing legitimate authentication flows, specifically Google OAuth and WhatsApp's device-linking mechanism, to compromise accounts belonging to academics, aerospace professionals, defence workers, and government officials across Europe and the US. The technique is notable because it exploits the plumbing of trusted platforms rather than breaking into them directly — meaning standard phishing defences offer limited protection. The targets suggest a continued focus on intelligence collection from policy and research communities. Australian think tanks and defence-adjacent research institutions sit in a similar target profile.

The Hacker News

Zombie Card Attack Revives Expired Visa Contactless Cards for Real Purchases

Researchers at the University of Massachusetts Amherst have demonstrated an attack that can reactivate expired Visa contactless credit cards for in-store purchases. By rewriting the expiration date that a point-of-sale terminal reads over NFC — without touching the card's underlying cryptography — they were able to complete genuine transactions on cards that should have been dead. The attack requires physical access to the card, so it's not a remote threat, but it has real implications for cards that end up in the wrong hands after expiry. Visa's global contactless infrastructure, including widespread deployment across Australian retail, uses the same NFC protocols the researchers tested.

The Hacker News

Citrix NetScaler Authentication Bypass Is the Kind of Bug That Gets Weaponised Fast

Citrix has patched a critical authentication bypass in NetScaler ADC and NetScaler Gateway — the appliances that sit at the front door of many enterprise networks and handle remote access. The flaw allows an unauthenticated attacker to bypass login controls entirely on certain gateway and AAA server configurations. Security researchers are already flagging exploitation as likely in the near term, given how frequently NetScaler devices have been targeted in recent years and how quickly proof-of-concept code tends to emerge for this class of vulnerability. NetScaler is widely deployed across Australian government and enterprise environments; patching should be treated as urgent.

SecurityWeek

Atlassian and Splunk Drop Patches for Dozens of Critical Flaws

Atlassian and Splunk have both released batches of patches covering dozens of critical and high-severity vulnerabilities. The flaws span arbitrary code execution, sensitive information disclosure, and privilege escalation across multiple products. Neither company has reported active exploitation yet, but both platforms are deeply embedded in enterprise environments globally — Atlassian's Jira and Confluence products in particular are ubiquitous in Australian technology and government organisations. Given the pace at which Atlassian vulnerabilities have been exploited historically (Confluence RCEs have been a recurring headache), these patches warrant prompt attention from IT teams heading into the weekend.

SecurityWeek

CDN Tsunami Attack Achieves 350x DoS Amplification via HTTP/3 Translation

Researchers have disclosed a pair of denial-of-service attacks — collectively named CDN Tsunami — that exploit the way major content delivery networks translate client-facing HTTP/3 traffic into HTTP/1.1 requests sent to origin servers. A low-bandwidth stream of requests can be amplified up to 350 times against the target website. The technique was validated against CDNs operated by Alibaba, Baidu, and others. The research is a significant finding because it turns CDN infrastructure — normally a shield against DDoS — into an inadvertent amplifier. It's a useful reminder that architectural assumptions baked into protocol translation layers can create novel attack surfaces years after deployment.

The Hacker News

Manic Android Malware Steals Data From Offline Phones Using Nearby Infected Devices

A newly documented Android threat called Manic combines banking malware capabilities with mobile spyware in ways researchers haven't seen before — including a mechanism for exfiltrating data from phones that are offline by relaying it through nearby infected devices. Its targets include Ukrainian banks, government services, messaging apps, and European and global fintech and cryptocurrency platforms. The mesh-style exfiltration technique is technically novel and suggests a threat actor with significant engineering resources. The malware's financial fraud components target more than 30 banking applications, and its cryptocurrency targeting makes it relevant beyond its current geographic focus.

The Hacker News

Cryptographic Context Injection Lets Malicious Web Pages Steal Your Grok Conversations

Adversa AI has disclosed a technique it calls Cryptographic Context Injection, which causes xAI's Grok chatbot to exfiltrate a user's name, approximate location, subscription tier, and conversation contents to an attacker-controlled server — triggered simply by asking Grok to summarise a malicious web page. The attack works because Grok's safety filters don't recognise encrypted instruction payloads embedded in page content as threats. It's another data point in the growing catalogue of prompt injection attacks that bypass guardrails by disguising instructions. Note that this week's lead on Grok generating CSAM makes this a second consecutive bad week for xAI's flagship product.

The Hacker News

China's SilkParasite Used AI to Build Espionage Malware Targeting Central Asian Governments

A Chinese espionage operation tracked as SilkParasite has been using artificial intelligence to assist in malware development as part of a campaign to compromise Central Asian government networks. Researchers assess the group has military ties. The use of AI to accelerate malware creation — rather than just for phishing lures — marks a meaningful step up in operational capability. Paired with this week's US advisory on AI-generated PLC exploits, the pattern is becoming hard to ignore: state-sponsored actors are now routinely using AI as a development tool in offensive cyber operations, not just as a novelty.

The Record

The Push to Make AI a US Critical Infrastructure Sector

A policy debate is building in Washington over whether to formally designate artificial intelligence as a critical infrastructure sector — a move that would unlock federal resources, CISA coordination, and sector-specific risk frameworks for AI providers. Proponents argue that AI systems are now so deeply embedded in economic and national security functions that they warrant the same protective treatment as energy grids and financial systems. The debate is directly relevant to Australia, where the SOCI Act's definition of critical infrastructure has been progressively expanded — but AI infrastructure hasn't yet entered that conversation formally. Whether it should is worth asking now, before an incident forces the question.

CyberScoop

Roblox Must Change After Failing to Block Adults Contacting Children

A regulator has found that Roblox failed to adequately prevent adults from contacting children on its platform, ordering the company to implement changes. Roblox is notable as the first platform to undergo independent audits under the Online Safety Act. The findings underscore that self-reported compliance and actual platform safety can diverge significantly — and that audit mechanisms matter. Australia's own Online Safety Act, administered by the eSafety Commissioner, has similar mandatory audit provisions for major platforms, and Roblox has a large Australian user base. How the platform responds to these required changes will be watched closely by regulators in multiple jurisdictions.

Ars Technica

People-Search Site ClarityCheck Left 9 Million Face Images Exposed in Public Database

ClarityCheck, a reverse-lookup people-search service, left a database containing more than 9 million face images exposed without authentication. The data — photos linked to individuals by the service's facial recognition and identity-matching tools — represents exactly the kind of sensitive biometric dataset that requires the strongest access controls. People-search companies occupy a legal grey zone in many jurisdictions: they aggregate publicly available data but combine it into profiles that individuals would never create themselves. In Australia, the Privacy Act's biometric data provisions and the OAIC's guidance on sensitive information would apply if an Australian provider operated a similar service.

Ars Technica

Google Gives Publishers a New Tool to Reclaim Traffic Lost to AI Search

Google is rolling out a feature that lets readers mark a publication as a preferred source, which would then prioritise that outlet's content across Search, Discover, and Google News. The move is a direct response to the well-documented collapse in referral traffic as AI-generated summaries in search results reduce the need for users to click through to source articles. It's an interesting concession — Google acknowledging that its own AI product is cannibalising the publishers whose content trains and informs it. Whether the feature meaningfully restores traffic, or is a goodwill gesture that changes little in practice, will become clear over the next few months.

TechCrunch

Sources consulted