CISOOnline

What happens when AI models take aim at ICS exploits

This is an important challenge because different PLC models from the same vendor or even different manufacturers might share a vulnerable component, with the rest of the firmware being significantly different. Furthermore, vendors sometimes patch a vulnerability reported in one model without comprehensively assessing whether the same flaw affects others in their product line.

For example, back in June, Forescout reported seeing exploit attempts for a vulnerability they found and reported in serial-to-IP converters from Lantronix (CVE-2025-67038). The manufacturer originally released patches only for the EDS5000 and EDS3000 series of controllers, but after in-the-wild exploitation came to light four months later, it identified and released patches for additional device models: G520 series, X300 series, E210 and E220 series.

“I do believe that in case manufacturers do not perform a comprehensive assessment of models affected by a vulnerability, AI can now help attackers to do it and to port exploits to models that may not have been patched,” Daniel dos Santos, VP of research at Forescout, tells CSO.



Source link