AI Ported PLC Exploit in 8.5 Hours for $536, but Bricked Hardware in the Process
Cybersecurity firm Forescout Vedere Labs used Anthropic's Claude AI models alongside Ghidra and physical hardware to port a known exploit (CVE-2021-31886) from the WAGO 750-852 PLC to the similar 750-831 model. The experiment achieved unauthenticated remote code execution on the target device, but the process took 8 hours and 32 minutes and cost $535.74 in API usage. Human experts were required throughout to correct AI errors, supply disassembly context, and redirect dead ends — raising questions about true AI autonomy in exploit development. During a follow-on attempt to expand the exploit into a command-and-control implant, an incorrect flash memory write permanently destroyed the physical PLC. The researchers concluded that AI-assisted exploit porting must be assessed not just on success, but also on human effort required, financial cost, time consumed, and the risk of physical hardware damage.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in