חוקרים השתמשו ב-Claude להעברת אקספלויט RCE מ-PLC אחד לאחר
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

◆ סיכום AI
חוקרי אבטחה הצליחו להעביר בהצלחה אקספלויט מסוג RCE (Remote Code Execution) מ-PLC (בקר לוגי מיתכנת) אחד לדגם אחר, תוך שימוש בכלי AI של Anthropic, Claude. האקספלויט המקורי ניצל פגיעות CVE-2021-31886 מסוג Buffer Overflow בשרת FTP, ואיפשר הרצת קוד עוין על חומרה חיה. הדבר מדגים את היכולת של כלי AI להאיץ פיתוח והתאמת קוד זדוני.
# מהמקור
Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command