Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs

Presented by

James Wilson
James Wilson

Technology Editor

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:

  • Iranian hackers take down a small-scale power generator in the UK
  • Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too.
  • Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet
  • Prompt injection isn’t going away
  • LLMs are deceiving us meat sacks and it’s a worry
  • Much, much more…

This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line.

This episode is also available on YouTube

Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs
0:00 / 62:53

Show notes

Iran-linked hackers blamed for cyber-attack that shut down UK power plant | theguardian.com

Hackers using AI to target Siemens PLCs in critical US sectors | securityweek.com

Defending Against an Active Threat to Siemens S7 Series PLCs | IC3.gov Industry Alerts

US charges Iranians for sprawling hacking campaign on government agencies, universities | therecord.media

T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network | techcrunch.com

The long tail of Clop’s PTC hack is just beginning to emerge | cyberscoop.com

CISA: Medusa ransomware hit over 500 critical infrastructure orgs | BleepingComputer

Ransomware disproportionately targets medium-sized firms, straining customer relationships | Cybersecurity Dive

Microsoft warns of max severity Entra ID flaw exploited in attacks | BleepingComputer

Critical RCE flaw in Windows IKE Extension now actively exploited | BleepingComputer

Rust supply chain attack linked to North Korean hackers | securityweek.com

Grok exfiltrates user data when malicious instructions are encrypted | arstechnica.com

New phishing toolkit uses passkeys to maintain access after password resets | securityweek.com

Password spraying attacks surge 155x as hackers exploit MFA gaps | BleepingComputer

Hackers compromise 14,500 Dahua web cameras in 35-day campaign | BleepingComputer

Hackers infect Android car head units with proxy botnet malware | BleepingComputer

ToxicPanda Android malware uses VPN permissions to block Google Play | BleepingComputer

New Manic Android malware can exfiltrate data through nearby devices | BleepingComputer

Citrix urges admins to patch new NetScaler flaws as soon as possible | BleepingComputer

AliExpress caught fingerprinting visitors after sending inaudible sounds to browsers | arstechnica.com

EXCLUSIVE: How a Texas student blew the whistle on a rogue AI hacking attempt | reuters.com

Detections and customer notifications | Okta Threat Intelligence