Skip to main content
Threat IntelligenceEmerging Threats

US Warns of AI-Powered Attacks on Siemens PLCs

Siemens PLC device mounted on a wall in an industrial control room with a cityscape visible through a window.

A dataset published on August 18, 2026, contains live Stripe API keys for 659 merchant accounts, along with roughly 35 GB of customer and payment data pulled from them.

U.S. Warning on AI-Powered Siemens S7 Series PLC Exploits

The U.S. government has warned that threat actors are using artificial intelligence to write exploit scripts against internet-exposed Siemens S7 Series programmable logic controllers (PLCs), devices present in water, energy, manufacturing, and other critical infrastructure sectors. "This is not a theoretical risk—it is an active threat," the agencies said, describing a workflow in which attackers use legitimate scanning services such as Censys and ZoomEye to find exposed or insufficiently segmented S7 PLCs.

According to the advisory, actors deploy AI-generated scripts that masquerade as legitimate monitoring tools to find and refine exploits. Researchers observed attackers conducting read operations to map environments and position themselves for future write operations that could cause disruption, safety incidents, equipment damage, or data compromise. The agencies did not identify who is behind the activity.

GitLab: CVE-2026-19478 and Rapid In-the-Wild Exploitation

A high-severity GitLab flaw, CVE-2026-19478 (CVSS 9.4), was publicly disclosed and came under active exploitation within days, according to watchTowr. The vulnerability permits unauthenticated code injection that can allow attackers to modify or delete publicly accessible projects and rewrite their data under certain conditions, without credentials or user interaction.

The speed from disclosure to exploitation underlines the shrinking window defenders face between patch publication and active attacks. Organizations running publicly accessible GitLab instances should prioritize mitigation for CVE-2026-19478.

Live Stripe Keys Leak: 659 Merchant Accounts and 35 GB of Data

On August 18, 2026, a dataset appeared on a data-trading forum containing live Stripe secret keys for 659 merchant accounts plus roughly 35 GB of associated customer and payment data, Ransomnews reported. The advisory notes that a Stripe secret key provides programmatic access to an account: anyone holding one can read customer records, create charges, issue refunds, and change payout destinations.

Ransomnews highlighted a cluster of 519 accounts that, by the collector’s own record, could both accept payments and move funds out. The publication framed this as a high-impact leak because programmatic keys bypass dashboard-only controls and enable automated abuse at scale.

Cl0p Exploits PTC Windchill with a Bespoke Java Web Shell

ReliaQuest reported that Cl0p has deployed a JavaServer Pages (JSP) web shell after exploiting a critical flaw in PTC Windchill and FlexPLM servers. The web shell is tailored for enterprise Product Lifecycle Management software and functions as a full extortion platform: it maps vault data, decrypts every credential in the Windchill keystore, and can run arbitrary code through a custom Java class loader.

ReliaQuest noted this continues Cl0p’s pattern of weaponizing zero-days in widely used SaaS platforms for mass exploitation and extortion; the group previously deployed DEWMODE and LEMURLOOT following other high-profile attacks. As of August 12, 2026, Cl0p had started releasing alleged victims' full names, and over 40 organizations were reported targeted.

Truffle Security Finds 768 Live Corporate AWS Keys with Full Admin Rights

Truffle Security verified 64,024 unique AWS key pairs across 431,875 public findings spanning git history, Hugging Face datasets, Docker images, package registries, and CI logs. Of those, 10,616 included complete credentials; 88% still authenticate. Importantly, 768 live keys belonged to companies and carried full control of their AWS accounts—526 root keys plus 242 IAM users with AdministratorAccess.

Truffle reported the median live leaked key is five years old and has never been rotated, underscoring the persistence and operational risk of long-lived credentials in public repositories and artifacts.

What this means for security teams, federal agencies, and merchants

  • Security teams: Prioritize rapid patching and access controls for high-risk, internet-exposed assets—especially PLCs and public GitLab instances—and hunt for exposed programmatic keys in code, CI logs, and datasets.
  • Federal agencies: Follow the CISA guidance in the Logging Reference Architecture to improve detection and response; CISA’s guidance stresses “robust logs” to provide the visibility needed to counter daily threats, as Chris Butera, CISA Acting Executive Assistant Director for Cybersecurity, put it.
  • Merchants and payment processors: Treat leaked Stripe secret keys as full account compromise; investigate the indicators of compromise in payment systems, rotate keys immediately, and review payout and refund history for abuse.

Between AI-accelerated exploit development against industrial controllers, fast-moving GitLab exploits, mass credential leaks, and tailored extortion tooling, the week’s incidents share a common lesson: attackers succeed by finding and abusing single points of exposure—one exposed service, one leaked key, one trusted tool turned hostile. That narrow focus is what defenders must close.

Source: The Hacker News — Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More