Risky Business Video
August 26, 2026
Risky Business (850): Widespread AI-enabled attacks target Siemens PLCs
Presented by
CEO and Publisher
Co-host at large
On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:
- Iranian hackers take down a small-scale power generator in the UK
- Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too.
- Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet
- Prompt injection isn’t going away
- LLMs are deceiving us meat sacks and it’s a worry
- Much, much more…
This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line.
Show notes:
Iran-linked hackers blamed for cyber-attack that shut down UK power plant | theguardian.com https://www.theguardian.com/world/2026/aug/23/iran-linked-hackers-blamed-cyber-attack-british-power-plant
Hackers using AI to target Siemens PLCs in critical US sectors | securityweek.com https://www.securityweek.com/hackers-using-ai-to-target-siemens-plcs-in-critical-us-sectors
Defending Against an Active Threat to Siemens S7 Series PLCs | IC3.gov Industry Alerts https://www.ic3.gov/CSA/2026/260819.pdf
US charges Iranians for sprawling hacking campaign on government agencies, universities | therecord.media https://therecord.media/iran-cyberattacks-us-doj
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network | techcrunch.com https://techcrunch.com/2026/08/19/t-mobile-chopped-a-cable-to-expel-chinese-hackers-from-its-network
The long tail of Clop’s PTC hack is just beginning to emerge | cyberscoop.com https://cyberscoop.com/clop-zero-day-attacks-ptc-windchill-flexplm
CISA: Medusa ransomware hit over 500 critical infrastructure orgs | BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs
Ransomware disproportionately targets medium-sized firms, straining customer relationships | Cybersecurity Dive https://www.cybersecuritydive.com/news/ransomware-mid-market-firms-black-kite/828257
Microsoft warns of max severity Entra ID flaw exploited in attacks | BleepingComputer https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks
Critical RCE flaw in Windows IKE Extension now actively exploited | BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-critical-windows-ike-extension-flaw-now-exploited-in-attacks
Rust supply chain attack linked to North Korean hackers | securityweek.com https://www.securityweek.com/rust-supply-chain-attack-linked-to-north-korean-hackers
Grok exfiltrates user data when malicious instructions are encrypted | arstechnica.com https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted
New phishing toolkit uses passkeys to maintain access after password resets | securityweek.com https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets
Password spraying attacks surge 155x as hackers exploit MFA gaps | BleepingComputer https://www.bleepingcomputer.com/news/security/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps
Hackers compromise 14,500 Dahua web cameras in 35-day campaign | BleepingComputer https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign
Hackers infect Android car head units with proxy botnet malware | BleepingComputer https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware
ToxicPanda Android malware uses VPN permissions to block Google Play | BleepingComputer https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play
New Manic Android malware can exfiltrate data through nearby devices | BleepingComputer https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices
Citrix urges admins to patch new NetScaler flaws as soon as possible | BleepingComputer https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible
AliExpress caught fingerprinting visitors after sending inaudible sounds to browsers | arstechnica.com https://arstechnica.com/security/2026/08/aliexpress-caught-fingerprinting-visitors-after-sending-inaudible-sounds-to-browsers
EXCLUSIVE: How a Texas student blew the whistle on a rogue AI hacking attempt | reuters.com https://www.reuters.com/world/how-texas-student-blew-whistle-rogue-ai-hacking-attempt-2026-08-20