AI Aids PLC Attacks as GitLab, Stripe Breach Add to Cyber Underbelly

This week’s cybersecurity landscape shows attackers leveling up: threat actors are using artificial intelligence to exploit programmable logic controllers (PLCs), GitLab security holes are under mass attack, and live Stripe API keys have leaked — exposing private and payment data from hundreds of merchants. Below is what organizations need to know to stay ahead.

⚠️ AI-Driven Attack on Industrial Control Systems

The U.S. government issued alerts over active campaigns using AI-generated exploit scripts to target Siemens S7 Series PLCs that are exposed to the internet. These devices control essential sectors like water treatment, energy, and manufacturing. The issue isn’t a theoretical one — it’s happening now. Key risks include operational downtime, safety incidents, privacy breaches, and regulatory penalties. Using scanning tools like Censys and ZoomEye, attackers are mapping vulnerable systems. Once located, they deploy scripts disguised as monitoring tools, gaining read access to understand environments before launching destructive write actions. No specific threat group has yet been confirmed behind these efforts.

🔥 Major Incidents and Vulnerabilities

GitLab Injection Exploit – CVE-2026-19478. Just days after its disclosure, this flaw came under active exploitation. It allows unauthenticated attackers to inject code into or delete public GitLab projects and alter data without credentials or user input. With a CVSS score of 9.4, this issue demands immediate patching.

RedC2 4.0 Linux Backdoor via Trojaned npm Packages. Fourteen seemingly normal packages — utilities like calendars and streak trackers — were discovered embedding an AI-powered implant called RedC2 4.0. Designed for cross-platform deployment (Linux, Windows, macOS), it delivers credential theft, surveillance, payload distribution, and large-scale operations. A hacker known as “MarlboroMan” promoted it earlier this summer.

Zombie Card Payment Fraud. Researchers found a way to perform contactless payments using expired Visa cards. By relaying signals through a relay device to change the expiration date shown to the payment terminal — without tampering with the actual card cryptography — attackers can make in-person purchases. Most major banks’ systems were fooled. No proof yet this has occurred outside of experiments.

Misuse of Authentication Chains by Russian-Linked Actors. Threat clusters UNC6293, UNC7005, and UNC5976 are targeting academia, defense, and government officials in Europe and the U.S., using phishing, social engineering, and hijacked captive Wi-Fi portals. One incident reportedly involved compromises at managed service providers to facilitate access.

Cloudflare Workers Spectre Attack. A remote Spectre-class side-channel leak targeting co-located Workers in Cloudflare’s edge environment exposed a JSON Web Token at rates up to 12 bits per second. That’s 360 times faster than prior similar research. Experts warn this could affect millions of HTTP requests across many websites.

New Unisoc Firmware Flaw in Android Devices. An unfixed vulnerability in modem firmware, when exploited with another remote code execution bug, can allow attackers kernel-level access. This exploit requires a combination of payload delivery to the modem and a user answering a video call — an uncommon but dangerous vector.

🔍 Other Worrying Developments

  • Stripe Key Leak. Live API keys tied to 659 merchant accounts revealed thousands of customer records and payment histories.
  • CISA’s New Logging Guidance. The agency rolled out a structured approach for federal entities to consolidate logging practices and strengthen threat detection.
  • Judicial Review Tweaks Ex-Google Engineer’s Case. A judge partially overturned a conviction, citing lack of evidence that the defendant intended to assist China.
  • ScreenConnect Used for RMM-based Attacks. Phishing, SEO-poisoning, and installer deception are pushing attackers to harness ScreenConnect, disguised as system tools, to deploy persistent attacks.
  • DCRat via Phishing and Signed Utilities. A multi-stage campaign involving phishing, archive extraction, DLL sideloading, and process evasion leads to remote control of impacted systems.
  • Find My Network Misuse and Audio Fingerprinting. A Linux machine enrolled in Apple’s Find My network can leak live location. Separately, browser audio fingerprinting appeared in a retailer’s site, disrupting Bluetooth streaming.
  • OpenAI and Anthropic Push Tools for Secure AI. Anthropic’s Claude Mythos 5 is expanding into enterprise security-product integrations. OpenAI is using its Agentic Vulnerability Discovery Harness to uncover serious bugs — over 100 critical vulnerabilities in major platforms like Drupal.
  • Thousands of AWS Keys Leaked. Truffle Security found tens of thousands of AWS key pairs in public codebases, with hundreds still valid and some granting full admin access. Most have never been rotated.

🛠 What You Need To Do

Your fastest path to resilience is reevaluating what currently seems secure. If PLCs, remote code injection, or programmatic access keys are exposed — they’re risk vectors. Patch CVE-2026-19478 immediately. Audit and rotate leaked keys. Invest in visibility tools for critical infrastructure. Enforce strict authentication. Prioritize logging aligned with mature architecture. Use AI defensively — to test, spot, and secure weak spots, rather than letting it power rogue actions.

This week’s key lesson: in cybersecurity, it takes just one weak link, one misconfigured device, or one overlooked secret to open a doorway for serious attacks. The new frontier is not just which threats are coming, but where our assumptions about safety are breaking down.