The exploit no longer needs an expert
Five US agencies have put their names to an advisory saying attackers are using AI to write exploit scripts for internet-exposed Siemens controllers, and calling it an active threat rather than a theoretical one. It is the first time CISA has said that about the kit that runs plant.

- 01
Five agencies name AI-written exploit code as an active threat to industrial controllers
The NSA, CISA, the FBI, the Department of Energy and the EPA published a joint advisory on 19 August about internet-exposed Siemens S7 Series controllers, the sort that sit behind water, energy, manufacturing and building plant. Attackers scan for exposed units and run exploit scripts written with AI on top of open-source S7 libraries, dressed up to look like ordinary monitoring tools, giving read and write access to controller memory, configuration and ladder logic. The recommended actions are dull and old: inventory the controllers, patch them, get them off the public internet, tighten who can reach them.
CISA - 02
Grok reads an encrypted instruction off a web page and does what it says
Researchers at Adversa AI put encrypted instructions and the key to unlock them on a web page. The guardrail scanner sees ciphertext and lets it through, Grok decrypts it inside its own code sandbox, and the instructions then reach the model as the output of code it has just run rather than as text fetched from a page. Against Grok 4.5 Fast it worked in roughly two attempts out of five and sent the user's name, approximate location, subscription tier and current conversation to a server the researchers controlled. xAI was told on 3 June, acknowledged the report, and as of 19 August there was no patch and no CVE.
The Register - 03
An AI agent recommended a package that only existed because an attacker made it
An engineer at software firm Softjourn asked an AI agent for a library to handle a routine task and got back a plausible-looking name that turned out to be malware. The company's own rule, that anything an AI recommends gets checked by a person, is what caught it: the developer opened the source on GitHub, saw a handful of downloads and a creation date a few days earlier, and stopped. The technique has a name now, slopsquatting, and the shape of it is simple: models invent package names, attackers register the invented names and wait.
The Register - 04
An AI data governance vendor confirms an attack and says very little else
Alation, whose software lets large organisations search and govern their own data, confirmed on 20 August that its systems had been hit by unauthorised access, two days after an incident it described only as degraded availability. It has not said how the attackers got in, whether anything was taken, how many customers are affected, or what those customers should do about it. The company claims more than 500 corporate customers, including around half of the Fortune 1000.
TechCrunch - 05
ChatGPT changed how it searches, and Reddit fell off a cliff
Monitoring of ChatGPT's search behaviour shows its use of the site: operator jumping from about 0.4 per cent of its fan-out queries to roughly 17 per cent on 8 August, while Reddit's share of citations fell from an average of 3.83 per cent in the weeks to 7 August down to 0.52 per cent by the middle of the month. Google's AI Overviews and AI Mode show a gradual decline across the same window rather than a single-day drop, which points at a change in how ChatGPT decides where to look rather than a penalty aimed at Reddit. If anyone has sold you forum answers as the way to get quoted by AI, that route has just narrowed.
Promptwatch - 06
ChatGPT can now read and send the texts on your Mac
OpenAI released an Apple Messages plug-in for the ChatGPT desktop app on 20 August. It reads and searches iMessage, SMS and RCS threads held on the machine, drafts replies, deletes messages and sends on your behalf. It is available on all plans but only in the Apple Silicon build of the Mac app, and each send asks for approval unless you choose to always allow a particular thread, which is the setting worth a conversation before somebody in the office ticks it.
TechCrunch
The Siemens advisory is not really about Siemens. Five agencies, one of them the Environmental Protection Agency, put their names to a document saying that the scarce ingredient in attacking industrial kit is no longer scarce. Writing a working S7comm exploit used to require somebody who understood both the protocol and the plant, and there were not many of them, and that shortage was doing a lot of quiet security work on everyone's behalf. Now it requires somebody who can describe what they want to a model and point it at an open-source library. CISA has published plenty of warnings about exposed controllers before. This is the first time it has said the exploit code is being written by AI, and the word it chose was active, not potential.
For a building services or M&E firm this sits closer to home than the usual cyber story, because it is the same kit. Controllers on a BMS panel, a plant room, a pump set, an AHU, commissioned once by a specialist and then left alone, occasionally with a 4G router bolted on so someone can dial in without driving across London. From direct experience in construction I know exactly how the ownership question gets answered: the client assumes the main contractor is watching it, the main contractor assumes the controls subbie is watching it, and the controls subbie finished on that job two years ago. There is nothing clever in the advisory's list of actions. Find the controllers, confirm none of them answer from the open internet, patch them, write down who is responsible. That list keeps being republished because it keeps not being done, and the thing that changed this month is that the person on the other end no longer has to be any good.
We build the AI that answers enquiries while you're on site: chat, voice, instant estimates and follow-up. See how it works or price it in two minutes.