Risky Business Risky Business

Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs

Aug 26, 2026 · 1h 2m

Summary

Hosts Patrick Gray and James Wilson are joined by Olly Whitehouse, CTO of the UK’s NCSC, to discuss a cyberattack on a UK power generator and AI-enabled exploits targeting Siemens PLCs. The episode covers US indictments of Iranian hackers, T-Mobile’s physical response to Salt Typhoon, and CLOP’s predictable extortion tactics against enterprise software. They also analyze Medusa ransomware trends, a critical Microsoft Entra bug, Rust supply chain compromises, and novel prompt injection attacks.

Topics discussed

Intro: Welcome and guest Olly Whitehouse from NCSC Iranian-linked cyber attack on UK small-scale power generator AI used to target Siemens PLCs in critical US sectors Indictments of Iranian hackers and Salt Typhoon T-Mobile response CLOP ransomware targets PTC Windchill and FlexPLM Ransomware trends: Access brokers and medium-sized firms Microsoft patches CVSS 10 deserialization bug in Entra ID Microsoft IKE extensions double free bug and ArrayRef malware New prompt injection attack and phishing toolkit updates Mass exploitation of Dahua web cameras in Russia and Ukraine Car infotainment malware and Android Automotive vulnerabilities LLM deception, GitHub malicious commits, and AI alignment Sponsor Interview: Okta's Permisso acquisition and threat intel
Listen ad-free on Castria