Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Researchers at Forescout Research - Vedere Labs leveraged Claude to successfully adapt a pre-authentication RCE exploit targeting CVE-2021-31886 across different WAGO programmable logic controller models, demonstrating the ability to execute arbitrary ARM shellcode on active hardware. The vulnerability exploits a stack-based buffer overflow in the Nucleus FTP server's USER command handling, highlighting how AI tools can accelerate the weaponization of known PLC vulnerabilities across multiple device variants.
Threat actors are actively exploiting CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3, to achieve remote code execution and deploy reverse shells without requiring credentials. With a CVSS score of 9.3, this flaw in the enterprise VoIP platform poses a severe risk to organizations running affected versions. Security teams should prioritize patching Switchvox deployments immediately to prevent unauthorized access and code execution attacks.
F5 announced enhancements to its AI-powered web application firewall designed to counter AI-driven threats through faster virtual patching and real-time protections positioned in the data path. The updates include new anomaly detection and agentic threat intelligence capabilities that enable security teams to make informed risk-based decisions rather than rushing into reactive measures. These improvements to F5 WAF for Distributed Cloud aim to give organizations more time to respond to emerging threats effectively.
National Life Group's CISO warns that AI-driven attacks could surface more vulnerabilities in the next six months than have appeared over the past three decades, outpacing traditional patch cycles designed for human-speed remediation. The discussion highlights compensating controls as a critical interim strategy when immediate fixes are unavailable, and notes that agentic AI in security operations is successfully auto-closing four out of five cases without human intervention.
SonicWall has disclosed two zero-day vulnerabilities in its SMA1000 appliance that are currently being exploited in active attacks. The flaws, tracked as CVE-2026-83549 and CVE-2026-83548, can be chained together to achieve unauthenticated remote code execution, posing a critical risk to organizations running affected devices.