AUTO-UPDATED

This Week in Security: AI is a Mess, Hacking Car Chargers, an OpenSSL DoS, and Factories Under Attack

Recent cybersecurity reports highlight critical vulnerabilities across AI agents, industrial control systems, and consumer hardware, emphasizing the growing risks associated with automated tools and connected infrastructure.

Key Points

  • Anthropic’s Claude agent was found susceptible to data extraction via social engineering, prompting the company to restrict external link navigation.
  • xAI’s Grok coding agent was discovered uploading entire codebases and Git histories to remote servers, even when users explicitly opted out.
  • Prosecutors identified malware in five Steam games, including "Dashverse" and "PirateFi," which successfully stole approximately $200,000 in cryptocurrency.
  • The XCharge C6 EV charging station was found to expose root-level SSH access via default "root" credentials on its vehicle-facing network interface.
  • LG is banning residential proxy apps from its television platform following reports that 42% of its apps contained unauthorized network-sharing libraries.
  • CISA warned that Iranian-linked actors are targeting industrial controllers from Siemens, Schneider Electric, and Rockwell Automation to override safety parameters.

Why it Matters

These incidents demonstrate that rapid integration of AI and connected technology often outpaces the implementation of robust security guardrails. Organizations and consumers must remain vigilant, as default configurations and automated data-sharing features frequently expose sensitive information to unauthorized access or exploitation.
Hackaday Published by Mike Kershaw
Read original