Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
The Hacker News
Read full postForescout Research's Vedere Labs used Anthropic's Claude AI to port a pre-authentication remote code execution exploit from one WAGO PLC model to another, enabling ARM shellcode execution on live hardware. The process involved interactive sessions with Claude, using reverse-engineering tools and cost $535.74 in API usage over 8.5 hours. Attempts to extend the exploit caused permanent damage to a PLC, and no patches exist for the vulnerability, prompting recommendations to disable FTP and monitor




