Forescout just published the bill for a second industrial kill chain. Researchers used Claude to port a remote code execution exploit between WAGO PLC models. The work took hours. The compute cost landed in the hundreds of dollars. If you own a plant network, that figure should rearrange your week. A cybersecurity program that still treats each controller CVE as a one-off fire drill is buying time you no longer have.

You already knew industrial exploits get copied. The new number is the price. A specialist used to burn days mapping a sibling firmware image, chasing instruction offsets, and rebuilding the payload by hand. That labor was the real control. Forescout compressed it into an afternoon and a cloud invoice you could lose in a travel report.

One Working Exploit Now Clones Across Models

The source was a working remote code execution exploit. The destination was a related WAGO PLC. Claude handled the translation: structures, offsets, the glue that used to live in a researcher’s notes. Treat that as a capability any motivated actor can rent this quarter. Public advisories plus downloadable firmware plus a coding assistant equals a variant.

Industrial control equipment in a plant environment illustrating OT systems now subject to AI-assisted exploit porting
Once a PLC exploit works on one model, related hardware is a translation job, not a research program.

Your CMDB row that says the unit is patched is incomplete if the compact cousin on line three is two revisions behind. Attackers don’t respect SKU spreadsheets. They respect shared code, shared protocol stacks, and shared download paths from the engineering workstation.

Most plant diagrams still pretend a firewall and a historian jump box deliver threat-protection. This payload speaks the same protocol your engineers use on Tuesdays. Brute-force alarms on the VPN stay green. Threat detection that only counts failed logins files the session under normal operations and moves on.

Hours of work. Hundreds of dollars. A second WAGO PLC remote code execution path on related hardware.

That’s the experiment, not a forecast. Once the first advisory is public, the port is a prompt-and-verify problem. You should assume a competent operator can repeat the loop against any controller family with documentation, a firmware image, and a lab bench. The expensive part used to be the human who understood both models. That person now has a copilot that never sleeps and never forgets a struct layout.

Security hardening on a single patched SKU doesn’t travel automatically to the rest of the family. Firmware branches diverge in annoying ways, then reconverge in the exact function an exploit needs. If you only track the CVE string in the vendor note, you’ll miss the units that share the vulnerable parser under a different marketing name.

The engineering workstation is the real console. Once a ported payload runs on the PLC, your Windows stack is a spectator. Containment lives in who can download logic, which VLANs carry native protocols, and whether you can island a line without guessing.

Patch-First Cybersecurity Can’t Absorb Cheap Variants

CISA’s latest review names the losing strategy. The industry queues weaknesses as tickets. You close one CVE on model A, then model B, then last year’s runtime. Attackers, and now assistants, treat them as one class. The queue never empties because the class keeps minting new IDs.

“By reducing these root causes during software development, providers can help prevent vulnerabilities that are more likely to be targeted by threat actors.”

Software code on a screen representing recurring vulnerability classes that survive individual CVE patching
CISA’s argument is blunt: if you only fix instances, you will keep paying for the same weakness under new names.

You still have to operate while vendors argue about memory safety. Scanners remain excellent at counting. They are weak at telling you that four “distinct” ICS advisories are one unsafe pattern with four compiler flags. Cyber security leadership that reports 95 percent of criticals closed can still be exposed on the floor. The metric measured tickets. The adversary measured a family.

Look sideways at how intrusion sets already ship. Mirage Kitten’s newest work against aviation and FinTech targets across the Middle East and Africa arrived as a set: NodeRabbit in Node.js, PollCat in JavaScript. Kaspersky catalogued families, not a single unique implant. Adversaries think in kits and ports. Too many incident response plans still think in CVE IDs and a Friday change window.

Defense in depth fails when every layer is tuned to the first published sample. Signatures trail the port. Network allowlists bless the engineering protocol. The historian still trusts the PLC that just started talking a little differently. You need a control strategy that assumes the sibling is guilty until firmware provenance says otherwise.

When the next PLC advisory hits, stop asking whether you patched the listed model. Ask which controllers share the runtime, the protocol stack, or the logic-download path. If you can’t answer in an hour, the assistant already has a head start.

Assume the Sibling Controller Is Already Vulnerable

You can’t wait for every ICS vendor to ship a memory-safe runtime. You can change how you scope, contain, and hunt. Do this on the plant you have, with the people you already staff on nights and weekends.

This week, pull every controller, HMI, and protocol gateway into a family map. Group by vendor, runtime, firmware branch, and who can push logic. Mark any unit that can speak to a sibling over the process network as in-scope for the next public RCE, even if the advisory never named it. That map is now your incident response pre-work, not a diagram in a drawer.

  • Immediate: freeze internet egress from engineering workstations and PLC programming hosts; force downloads through a monitored jump path you actually log.
  • Immediate: restrict who can put a controller into stop or program mode, and alert on unexpected logic downloads after hours.
  • Immediate: treat a public ICS RCE as a family event; open one incident that covers every related model, not a ticket per SKU.
  • Ongoing: hunt for native protocol anomalies and new project files, rather than waiting for a signature pack that knows the ported variant.
  • Ongoing: demand vendors show how they are eliminating the class (memory safety, dead protocol parsers, signed logic) instead of mailing another CVE spreadsheet.

Keep the plant firewall. Stop asking it to identify a payload that looks like legitimate engineering traffic. Put identity and command logging on the people and hosts that can change controller logic. If your only high-fidelity sensor is a failed VPN password, you’ll learn about a ported exploit from production downtime, not from a console.

Run the tabletop with the second model already owned. Cheap ports make CVE-chasing a dead control. Family containment, firmware provenance, and a rehearsed islanding plan still shrink the blast radius while CISA argues with software vendors about root causes you can’t patch from the floor.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.