Risky Business (850): Widespread AI-enabled attacks target Siemens PLCs

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Co-host at large

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:

  • Iranian hackers take down a small-scale power generator in the UK
  • Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too.
  • Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet
  • Prompt injection isn’t going away
  • LLMs are deceiving us meat sacks and it’s a worry
  • Much, much more…

This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line.

Show notes:

Iran-linked hackers blamed for cyber-attack that shut down UK power plant | theguardian.com https://www.theguardian.com/world/2026/aug/23/iran-linked-hackers-blamed-cyber-attack-british-power-plant

Hackers using AI to target Siemens PLCs in critical US sectors | securityweek.com https://www.securityweek.com/hackers-using-ai-to-target-siemens-plcs-in-critical-us-sectors

Defending Against an Active Threat to Siemens S7 Series PLCs | IC3.gov Industry Alerts https://www.ic3.gov/CSA/2026/260819.pdf

US charges Iranians for sprawling hacking campaign on government agencies, universities | therecord.media https://therecord.media/iran-cyberattacks-us-doj

T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network | techcrunch.com https://techcrunch.com/2026/08/19/t-mobile-chopped-a-cable-to-expel-chinese-hackers-from-its-network

The long tail of Clop’s PTC hack is just beginning to emerge | cyberscoop.com https://cyberscoop.com/clop-zero-day-attacks-ptc-windchill-flexplm

CISA: Medusa ransomware hit over 500 critical infrastructure orgs | BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs

Ransomware disproportionately targets medium-sized firms, straining customer relationships | Cybersecurity Dive https://www.cybersecuritydive.com/news/ransomware-mid-market-firms-black-kite/828257

Microsoft warns of max severity Entra ID flaw exploited in attacks | BleepingComputer https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks

Critical RCE flaw in Windows IKE Extension now actively exploited | BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-critical-windows-ike-extension-flaw-now-exploited-in-attacks

Rust supply chain attack linked to North Korean hackers | securityweek.com https://www.securityweek.com/rust-supply-chain-attack-linked-to-north-korean-hackers

Grok exfiltrates user data when malicious instructions are encrypted | arstechnica.com https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted

New phishing toolkit uses passkeys to maintain access after password resets | securityweek.com https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets

Password spraying attacks surge 155x as hackers exploit MFA gaps | BleepingComputer https://www.bleepingcomputer.com/news/security/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps

Hackers compromise 14,500 Dahua web cameras in 35-day campaign | BleepingComputer https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign

Hackers infect Android car head units with proxy botnet malware | BleepingComputer https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware

ToxicPanda Android malware uses VPN permissions to block Google Play | BleepingComputer https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play

New Manic Android malware can exfiltrate data through nearby devices | BleepingComputer https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices

Citrix urges admins to patch new NetScaler flaws as soon as possible | BleepingComputer https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible

AliExpress caught fingerprinting visitors after sending inaudible sounds to browsers | arstechnica.com https://arstechnica.com/security/2026/08/aliexpress-caught-fingerprinting-visitors-after-sending-inaudible-sounds-to-browsers

EXCLUSIVE: How a Texas student blew the whistle on a rogue AI hacking attempt | reuters.com https://www.reuters.com/world/how-texas-student-blew-whistle-rogue-ai-hacking-attempt-2026-08-20