Wire Observer.
Technology

Researchers Leverage Anthropic’s Claude to Adapt PLC Exploit Across Models

Researchers Leverage Anthropic’s Claude to Adapt PLC Exploit Across Models

Security researchers at Forescout’s Vedere Labs have demonstrated a novel use of artificial intelligence to adapt a pre‑authentication remote code execution (RCE) vulnerability from one WAGO programmable logic controller (PLC) model to a different one, successfully running attacker‑controlled ARM shellcode on operational hardware.

The team employed Anthropic’s large language model, Claude, to translate the exploit code originally crafted for a specific WAGO PLC into a version compatible with another model in the same product line. By feeding the model detailed technical descriptions of the target device’s firmware and architecture, the researchers guided Claude to generate the necessary modifications, effectively “porting” the exploit without manual reverse‑engineering of the second controller.

According to the lab’s findings, the adapted exploit bypasses authentication mechanisms, allowing arbitrary code execution directly on the PLC’s ARM processor. In a controlled lab environment, the researchers verified that the payload could be delivered over the network and that the shellcode executed reliably on live hardware, confirming the practical risk posed by such cross‑device exploit migration.

The demonstration underscores growing concerns about the intersection of AI tools and industrial control system (ICS) security. While large language models have been touted for accelerating software development and vulnerability analysis, their capability to automate exploit generation may lower the barrier for threat actors targeting critical infrastructure. Experts note that PLCs, which manage processes in manufacturing, energy, and utilities, often run outdated firmware and lack robust patch management, making them attractive targets for sophisticated attacks.

Vedere Labs plans to disclose the technical details to the affected vendor and coordinate remediation efforts, following responsible disclosure practices. The incident also prompts calls for manufacturers to adopt secure development lifecycles, implement strict authentication, and provide timely updates for legacy devices. As AI continues to evolve, security professionals anticipate a need for new defensive strategies that account for automated exploit creation, alongside traditional threat‑intelligence measures.

Source: feedburner
Diya Sharma — AI & research desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related