Weekly Cybersecurity Roundup: AI-Enhanced PLC Exploitation, GitLab Attacks and Supply-Chain Risks
Security researchers and government agencies reported several developments this week spanning industrial systems, software supply chains, cloud infrastructure and payment security. The incidents highl...
Security researchers and government agencies reported several developments this week spanning industrial systems, software supply chains, cloud infrastructure and payment security. The incidents highlight how attackers are combining legitimate services, trusted development tools and newly disclosed vulnerabilities to broaden their reach.
AI-assisted attacks target industrial controllers
U.S. agencies warned that threat actors are using artificial intelligence to develop exploit scripts aimed at internet-exposed Siemens S7 Series programmable logic controllers. The devices are widely used in sectors including energy, water and manufacturing. Investigators said attackers have used public scanning services to locate exposed or poorly segmented systems, then tested AI-generated tooling against specific PLC models. Current activity appears to include read access for reconnaissance and preparation for possible disruptive write operations. The agencies did not identify those responsible.
Critical software and supply-chain activity
A GitLab vulnerability rated critical was reportedly exploited shortly after disclosure. CVE-2026-19478 may allow unauthenticated attackers, under certain conditions, to alter or delete publicly accessible project data. Organizations should review vendor guidance and examine exposed GitLab instances for suspicious changes.
Researchers also identified 14 malicious npm packages disguised as calendar and streak-tracking utilities. The packages delivered RedC2 4.0, a Linux backdoor advertised as a cross-platform toolkit capable of surveillance, credential theft and payload execution. The discovery reinforces the need to pin dependencies, verify package provenance and monitor build environments.
Espionage and infrastructure compromise
Google linked three suspected Russian espionage clusters to phishing campaigns that abuse legitimate authentication workflows. Targets reportedly include academics, defense and aerospace personnel, government staff and think tanks. Another investigation attributed captive Wi-Fi portal hijacking to compromises involving managed service providers, allowing users to be redirected to credential-stealing infrastructure.
Researchers demonstrated that a remote Spectre technique against Cloudflare Workers could extract data from a co-located workload at a substantially higher rate than earlier demonstrations, including potential exposure of JSON Web Tokens. The practical risk depends on deployment conditions and isolation controls.
Additional findings
Researchers showed that a relay-based “Zombie Card” technique could make contactless purchases with physically expired Visa cards, although there is no indication of real-world abuse. Separately, the Cl0p extortion group reportedly deployed a custom web shell against PTC Windchill and FlexPLM systems, enabling credential decryption, sensitive-data discovery and further code execution after exploiting server vulnerabilities.
