ICS

Hello All. The emergence of Claude Mythos is forcing a rethink across the cybersecurity landscape. Unlike earlier tools that assisted analysts, this new class of AI is capable of autonomously identifying and chaining together previously unknown vulnerabilities. What makes this particularly significant is not just speed, but depth—these systems can analyze legacy codebases and uncover flaws that may have existed, unnoticed, for decades.

This raises an uncomfortable question for OT environments that still rely heavily on legacy infrastructure. Consider a typical HMI running Windows XP: long past end-of-life, unpatched, and often deeply embedded into operations. For years, the assumption has been that most meaningful vulnerabilities were discovered before vendor support ended, and that residual risk could be managed through isolation and compensating controls. That assumption no longer holds.

The reality is that vendors like Microsoft never “found everything.” Vulnerability discovery has always been constrained by human effort, available tooling, and prioritization. AI changes that equation entirely. Systems like Claude Mythos can now revisit old platforms with fresh analytical capability, identifying flaws that were previously invisible—not because they were impossible to find, but because no one had the means to find them efficiently.

The real challenge emerges when new vulnerabilities are discovered in systems that are no longer supported. There are no patches, no vendor fixes, and often no practical way to upgrade without significant operational disruption. In effect, organizations are left running infrastructure where newly discovered weaknesses may persist indefinitely, potentially exploited without ever being publicly disclosed.

For OT environments, the impact is amplified. These systems are designed for stability and uptime, not rapid change. They often rely on insecure-by-design protocols, lack modern endpoint protections, and cannot be easily segmented or monitored using traditional IT approaches. When AI accelerates both discovery and exploitation, the window between vulnerability identification and active use shrinks dramatically—sometimes to near zero.

This shifts the risk model entirely. Security teams can no longer rely solely on known vulnerabilities or published CVEs. Instead, they must assume that unknown weaknesses exist and may already be discoverable by adversaries using similar AI capabilities. The focus moves from patching to containment, from prevention to detection, and from trust in legacy stability to acceptance of continuous exposure.

Ultimately, Claude Mythos represents more than a technological advancement—it exposes a long-standing blind spot in how organizations think about legacy risk. Systems like Windows XP were never “fully secured”; they were simply no longer being examined. Now, with AI re-opening that examination at scale, OT leaders must confront a new reality: the greatest risks may be the ones that have been sitting quietly in their environments all along.

Read more

I recently had the privilege of joining an amazing group of cybersecurity professionals on a panel discussion organized by Mike Holcomb, Dylan Williams, Kate Johnson, Cooper Wilson, Tom Morgan, Tahmeed Khan, George A., Ahmed Al Saleh and of course Ezz who was the moderator.

Read more

Reposting a post from Manjunath Hiregange from GE Vernova (thanks Manjunath!).

Are you interested in learning more about industrial control system (ICS) security, but struggling to find practical training opportunities?

Look no further than GRFICS (Graphical Realism Framework for Industrial Control Simulations) – free and open-source framework.

𝐖𝐢𝐭𝐡 𝐆𝐑𝐅𝐈𝐂𝐒, 𝐲𝐨𝐮 𝐜𝐚𝐧 𝐯𝐢𝐫𝐭𝐮𝐚𝐥𝐢𝐳𝐞 𝐞𝐧𝐭𝐢𝐫𝐞 𝐈𝐂𝐒 𝐧𝐞𝐭𝐰𝐨𝐫𝐤𝐬 𝐚𝐧𝐝 𝐩𝐫𝐚𝐜𝐭𝐢𝐜𝐞 𝐞𝐱𝐩𝐥𝐨𝐢𝐭𝐢𝐧𝐠 𝐯𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐢𝐞𝐬 𝐰𝐡𝐢𝐥𝐞 𝐬𝐞𝐞𝐢𝐧𝐠 𝐭𝐡𝐞 𝐩𝐡𝐲𝐬𝐢𝐜𝐚𝐥 𝐢𝐦𝐩𝐚𝐜𝐭 𝐢𝐧 𝐚 3𝐃 𝐠𝐚𝐦𝐞 𝐞𝐧𝐠𝐢𝐧𝐞.

The GRFICS framework is designed to virtualize entire ICS networks, including realistic 𝐩𝐡𝐲𝐬𝐢𝐜𝐚𝐥 𝐩𝐫𝐨𝐜𝐞𝐬𝐬 𝐬𝐢𝐦𝐮𝐥𝐚𝐭𝐢𝐨𝐧𝐬. While the initial version of GRFICS virtualizes a chemical process control network with a flat, un-segmented network architecture, the framework is modular and can be customized and expanded to include other types of ICS networks.

Here is a link to the 5 VMs: https://github.com/Fortiphyd/GRFICSv2
5 VirtualBox VMs (𝐚 3𝐃 𝐬𝐢𝐦𝐮𝐥𝐚𝐭𝐢𝐨𝐧, 𝐚 𝐬𝐨𝐟𝐭 𝐏𝐋𝐂, 𝐚𝐧 𝐇𝐌𝐈, 𝐚 𝐩𝐟𝐬𝐞𝐧𝐬𝐞 𝐟𝐢𝐫𝐞𝐰𝐚𝐥𝐥, 𝐚𝐧𝐝 𝐚 𝐰𝐨𝐫𝐤𝐬𝐭𝐚𝐭𝐢𝐨𝐧) communicating with each other on host-only virtual networks.

A video series walking through VM setup and example attacks is available on the Fortiphyd YouTube channel at https://www.youtube.com/playlist?list=PL2RSrzaDx0R670yPlYPqM51guk3bQjFG5

Read more