Cookie Consent by Free Privacy Policy Generator

Cyber Brief: AI-powered attacks, critical infrastructure risk

Today's stories reflect how quickly the operational security landscape is shifting. AI-generated attack code is now being used to target industrial control systems in critical infrastructure, a vulnerability in contactless payment systems allows expired credit cards to continue processing transactions, and a coordinated malware campaign is combining multiple techniques to compromise organisations. Meanwhile, the growing use of covert recording technology raises practical questions about workplace privacy and data protection obligations. Each of these developments has direct implications for how UK organisations manage risk, review controls and maintain operational resilience.

US agencies warn of AI-generated code targeting Siemens industrial controllers

CISA, the FBI and the NSA have issued a joint advisory warning that attackers are actively using AI-generated code to exploit vulnerabilities in Siemens S7 Series programmable logic controllers (PLCs) used across critical infrastructure sectors including water, energy and manufacturing. The Register reports that the agencies described this as "not a theoretical risk" but "an active threat", with evidence that adversaries are leveraging large language models to rapidly develop and deploy exploit code targeting these widely deployed industrial control systems. The advisory confirms that the threat extends beyond Siemens devices to other PLC manufacturers, and that attackers are specifically focusing on internet-exposed or poorly segmented operational technology environments.

For UK organisations operating industrial control systems, water treatment facilities, manufacturing plants or energy infrastructure, this represents a significant shift in how quickly attackers can now develop working exploits for operational technology. The use of AI to generate functional attack code reduces the technical skill barrier and accelerates the timeline from vulnerability disclosure to active exploitation. Many UK critical infrastructure operators still rely on legacy PLCs that were designed without modern security controls, and operational technology networks are often inadequately segmented from corporate IT environments. The advisory makes clear that this is not a future concern but an ongoing campaign targeting real systems in production environments.

Why it matters

For UK businesses operating or managing industrial control systems, this is a prompt to review whether PLCs are inventoried, segmented from corporate networks, and monitored for unauthorised access or configuration changes. Organisations should verify that operational technology environments are not directly exposed to the internet and that remote access is controlled through secure, monitored channels. This is also a reminder to ensure that incident response plans account for operational technology environments and that security teams understand the specific risks and constraints of industrial control systems.

Source: The Register

Researchers demonstrate expired contactless credit cards continue processing payments

Researchers from the University of Massachusetts Amherst have disclosed a vulnerability in contactless payment systems that allows expired credit cards to continue processing transactions even after their printed expiration date has passed and replacement cards have been issued. Help Net Security reports that the research team, presenting their findings at USENIX Security 2026, demonstrated what they call the "Zombie Card attack", showing that the contactless chip in an expired card remains functional and can authorise payments despite the card being officially invalid. The vulnerability exists because the contactless payment protocol does not consistently enforce expiration date validation at the point of transaction, and many cardholders retain expired cards rather than destroying them as instructed by issuers.

For UK organisations that handle payment processing, issue corporate credit cards, or manage expense systems, this finding highlights a gap in how payment security controls are implemented and enforced. The research demonstrates that the expiration date printed on a card is not a reliable security boundary in contactless transactions, and that organisations cannot assume an expired card is automatically disabled. This has implications for corporate expense policies, fraud detection systems, and the controls around card lifecycle management. Organisations that rely on card expiration as a control point for limiting employee spending authority or managing vendor payments may find that expired cards continue to function longer than expected, creating both financial and audit risk.

Why it matters

For many organisations, this is a prompt to review corporate card policies and ensure that card cancellation processes do not rely solely on expiration dates. Finance teams should verify that expense management systems actively validate card status and that employees are required to return or destroy expired corporate cards rather than retaining them. Organisations should also consider whether fraud detection rules account for the possibility of expired cards being used, and whether transaction monitoring includes checks for cards that should no longer be active.

Source: Help Net Security

Meta Glasses covert recording raises workplace privacy and data protection concerns

The Guardian has published an investigation into the growing use of Meta's smart glasses for covert recording, with individuals reporting being secretly filmed in their own homes, at concerts, in workplaces and in other private settings. The glasses, which are designed to look like ordinary eyewear, allow wearers to record video and audio without any visible indicator to those being recorded. The investigation includes accounts from people who have been filmed without consent in professional settings, and highlights the difficulty of detecting when recording is taking place. The article describes the technology as potentially representing "the final nail in the coffin of personal privacy", with the devices becoming increasingly popular and widely adopted despite significant concerns about surveillance and consent.

For UK organisations, this development has direct implications for workplace privacy policies, data protection compliance, visitor management and employee conduct rules. Under UK GDPR and data protection law, organisations have obligations to ensure that personal data, including video and audio recordings, are collected lawfully and with appropriate consent. If employees, contractors or visitors are using covert recording devices in the workplace, organisations may be unaware that personal data is being captured, processed and potentially shared without proper legal basis or data protection safeguards. This creates risk around employee privacy, confidential business discussions, client meetings and sensitive operational environments. Organisations also need to consider how to manage situations where covert recording may be used for legitimate purposes such as whistleblowing or evidence gathering, balanced against the privacy rights of others.

Why it matters

For UK businesses, this is a prompt to review workplace policies on recording devices and ensure that employees, contractors and visitors understand what is and is not permitted. Organisations should consider whether acceptable use policies, visitor agreements and employee handbooks clearly address covert recording technology, and whether data protection impact assessments account for the risk of unauthorised recording in the workplace. This is also a reminder to review how confidential meetings, client discussions and sensitive operational areas are managed, and to ensure that security and privacy controls reflect the reality of widely available covert recording technology.

Source: The Guardian

Coordinated malware campaign combines ClickFix, ErrTraffic and Cruciferra techniques

Infosecurity Magazine reports that cybersecurity firm eSentire has uncovered a coordinated malware-as-a-service campaign that combines ClickFix social engineering lures with ErrTraffic and Cruciferra malware delivery techniques. The campaign uses fake error messages and system prompts to trick users into executing malicious code, often disguised as legitimate troubleshooting steps or software updates. eSentire's research shows that the attackers are using a modular approach, combining multiple well-established attack techniques into a single campaign that can adapt to different targets and environments. The malware-as-a-service model means that the infrastructure and techniques are being sold or rented to multiple threat actors, increasing the scale and reach of the campaign.

For UK organisations, this type of coordinated, modular malware campaign represents a practical challenge for detection and response. The use of social engineering lures that mimic legitimate system messages makes it harder for users to distinguish between genuine prompts and malicious ones, and the combination of multiple techniques in a single campaign can bypass security controls that are designed to detect individual attack methods. The malware-as-a-service model also means that the same infrastructure and techniques may be used by different threat actors with different objectives, making attribution and pattern recognition more difficult. Organisations need to ensure that security awareness training reflects the current state of social engineering tactics, and that endpoint detection and response tools are capable of identifying behaviour patterns rather than relying solely on signature-based detection.

Why it matters

For many organisations, this is a prompt to review whether security awareness training includes examples of current social engineering techniques, particularly fake error messages and system prompts that instruct users to take specific actions. IT teams should verify that endpoint protection tools are configured to detect and block suspicious script execution and that email security controls are capable of identifying malicious links and attachments that use these techniques. Organisations should also consider whether incident response playbooks account for multi-stage attacks that combine social engineering with malware delivery, and whether security monitoring includes behavioural detection rather than relying solely on known indicators of compromise.

Source: Infosecurity Magazine

Today's Key Actions

  • Review whether operational technology environments, including PLCs and industrial control systems, are inventoried, segmented from corporate networks, and monitored for unauthorised access or configuration changes.
  • Verify that corporate card policies require employees to return or destroy expired cards, and that expense management systems actively validate card status rather than relying solely on expiration dates.
  • Update workplace policies to clearly address covert recording technology, and ensure that data protection impact assessments account for the risk of unauthorised recording in the workplace.
  • Review security awareness training to ensure it includes current social engineering techniques, particularly fake error messages and system prompts, and verify that endpoint protection tools are configured to detect suspicious script execution.
  • Ensure that ownership and accountability for these areas is clearly assigned across IT, security, finance, HR and operational teams, and that review actions are tracked and completed rather than deferred.

Secarma Insight

The common thread across today's stories is that effective security depends on understanding how controls actually work in practice, not just how they are supposed to work in theory. Expired cards that continue processing payments, covert recording devices that look like ordinary glasses, and AI-generated exploit code that bypasses traditional defences all highlight the gap between assumed protections and operational reality. Mature security practice comes from regularly testing assumptions, reviewing whether controls are still fit for purpose, and ensuring that policies reflect the current threat landscape rather than outdated models. Organisations that build these review habits into their routine operations are better positioned to identify and address gaps before they become incidents.

News and blog posts
Today's stories reflect how quickly the operational security landscape is...
CISA, the FBI and the NSA have issued a joint cybersecurity advisory warning...
Researchers from the University of Massachusetts Amherst have disclosed a...
The Guardian has published an investigation into the growing use of Meta's...