| ~7 MIN READ |
|
This week the machines started doing more of the hacking themselves, and the humans in charge are still catching up. Here's what changed, what got worse, and one thing you can fix before lunch.
PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe → |
|
In this edition
|
CRITICAL INFRASTRUCTURE
🤖 AI Is Now Writing the Exploit Code for Attacks on Power and Water Plants
Intro
Five federal agencies just confirmed what researchers have been dreading for two years: attackers are using AI to write working exploit code against the equipment that keeps the lights and water running.
What Happened
NSA, CISA, FBI, DOE, and EPA issued a joint advisory (AA26-231A) warning that unidentified attackers are using AI-generated scripts, disguised as monitoring tools, to gain read-write access to Siemens S7 programmable logic controllers across water, energy, manufacturing, and agriculture. The agencies call it "an evolution in threat actor capabilities" that slashes the skill needed to build a working ICS exploit.
Why It Matters
PLCs run the physical machinery behind critical infrastructure, and AI just erased the expertise barrier that used to protect them. Officials call this an active threat happening now, not a future risk.
The Other Side
No attribution to a specific nation or group yet, and no confirmed disruption, just reconnaissance and capability-building against exposed Siemens S7 gear specifically.
TL;DR: Feds warn AI is writing real exploit code against power and water plant controllers; no attribution yet, but the threat is active now.
Further reading: The Record
|
|
Stop making AI decisions in the dark.
Leadership is asking: are we getting value from AI? Which tools are worth the spend? Where are we exposed? Right now, most teams have no idea.
Harmonic Security Usage Explorer changes that.
You get a complete picture of how your organization uses AI, automatically categorized into custom tasks and use cases.
You’ll see the projects being worked on, who’s using what tools, where AI investments are driving value, and where employees are engaging in risky behavior.
CIOs can rationalize spending and cut wasted licenses. CISOs can pinpoint where risk exists and neutralize it. AI committees can show exactly how their efforts are paying off.
|
|
|
Stop Paying for 6 Tools. One AI Does It All.
Most e-commerce sellers juggle 6–8 tools and pay hundreds monthly to keep operations running. StoreClaw replaces the stack with one autonomous AI engine that monitors competitors, optimizes listings, automates marketing, and tracks profit 24/7. Connect your store and let AI handle the work — no prompts, no complex setup, no credit card required.
Strange but real
🔓 CISA Spent Six Months Ignoring Alerts About Its Own Leaked Passwords
Intro
Back in July, a CISA contractor accidentally proved the agency's own advice wrong in the most on-the-nose way possible.
What Happened
A public GitHub repository titled "Private CISA" sat exposed for nearly six months, containing 844 MB of the agency's data, including admin credentials to three AWS GovCloud servers and a spreadsheet of plaintext passwords. Security firm GitGuardian sent nine automated alerts. CISA read none of them.
Why It Matters
This is the agency that tells the country to patch fast and monitor alerts. The gap between that guidance and its own response says something uncomfortable about how hard this is, even for the people who write the rulebook.
The Other Side
No evidence the exposed credentials were exploited before the leak was closed, and CISA moved to fix it once Krebs on Security reached out directly.
TL;DR: CISA's own contractor leaked the agency's AWS passwords on GitHub for six months, and nobody read the nine alerts warning them.
Further reading: Krebs on Security
|
The best candidate for your next role might not live in the same country. Oyster helps you hire globally in 180+ countries. Payroll, compliance, and benefits included.



