Risky Business Podcast
August 26, 2026
Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs
Presented by
Technology Editor
CEO and Publisher
On this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including:
- Iranian hackers take down a small-scale power generator in the UK
- Siemens PLCs in critical US sectors are also being targeted… We’re stumped on who could be behind that one, too.
- Microsoft fixed a CVSS 10 deserialisation bug in Entra before someone else found it and owned the planet
- Prompt injection isn’t going away
- LLMs are deceiving us meat sacks and it’s a worry
- Much, much more…
This week’s show is brought to you by Okta. VP of Threat Intel Brett Winterford joins the show in this week’s sponsor interview to talk James through how the company is turning its plethora of accumulated data into free alerting for its customers. They also chat about Okta’s new threat intelligence product line.
This episode is also available on YouTube
Brought to you by Okta
Employee and Customer Identity Solutions
Show notes
Iran-linked hackers blamed for cyber-attack that shut down UK power plant | theguardian.com
Hackers using AI to target Siemens PLCs in critical US sectors | securityweek.com
Defending Against an Active Threat to Siemens S7 Series PLCs | IC3.gov Industry Alerts
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network | techcrunch.com
The long tail of Clop’s PTC hack is just beginning to emerge | cyberscoop.com
CISA: Medusa ransomware hit over 500 critical infrastructure orgs | BleepingComputer
Microsoft warns of max severity Entra ID flaw exploited in attacks | BleepingComputer
Critical RCE flaw in Windows IKE Extension now actively exploited | BleepingComputer
Rust supply chain attack linked to North Korean hackers | securityweek.com
Grok exfiltrates user data when malicious instructions are encrypted | arstechnica.com
New phishing toolkit uses passkeys to maintain access after password resets | securityweek.com
Password spraying attacks surge 155x as hackers exploit MFA gaps | BleepingComputer
Hackers compromise 14,500 Dahua web cameras in 35-day campaign | BleepingComputer
Hackers infect Android car head units with proxy botnet malware | BleepingComputer
ToxicPanda Android malware uses VPN permissions to block Google Play | BleepingComputer
New Manic Android malware can exfiltrate data through nearby devices | BleepingComputer
Citrix urges admins to patch new NetScaler flaws as soon as possible | BleepingComputer
EXCLUSIVE: How a Texas student blew the whistle on a rogue AI hacking attempt | reuters.com
