חזרה לפיד
newsמקור: The Hacker News2.9.2026

חוקרים השתמשו ב-Claude להעברת אקספלויט RCE מ-PLC אחד לאחר

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

חוקרים השתמשו ב-Claude להעברת אקספלויט RCE מ-PLC אחד לאחר

◆ סיכום AI

חוקרי אבטחה הצליחו להעביר בהצלחה אקספלויט מסוג RCE (Remote Code Execution) מ-PLC (בקר לוגי מיתכנת) אחד לדגם אחר, תוך שימוש בכלי AI של Anthropic, Claude. האקספלויט המקורי ניצל פגיעות CVE-2021-31886 מסוג Buffer Overflow בשרת FTP, ואיפשר הרצת קוד עוין על חומרה חיה. הדבר מדגים את היכולת של כלי AI להאיץ פיתוח והתאמת קוד זדוני.

# מהמקור

Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command

#ai-security#rce#plc-security#exploit-development
קרא במקור