CyberSecurity News
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
AI summary
Researchers at Forescout Research - Vedere Labs have successfully used Claude to adapt a pre-authentication remote code execution exploit from one model of WAGO programmable logic controller to another. The exploit targets a stack-based buffer overflow vulnerability in the Nucleus FTP server. This allowed the researchers to execute attacker-supplied ARM shellcode on live hardware. The vulnerability being exploited is related to the handling of the USER command. The exploit specifically targets a known vulnerability, which was previously identified. The researchers were able to achieve this using Anthropic's Claude.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

