The room has separated several superficially similar headlines into very different risk classes. In OT, reported manipulation of internet-exposed MicroLogix controllers is operational activity, but there is still no verified evidence here of logic changes, contamination, physical damage, or attribution. The AI-assisted WAGO work demonstrates faster exploit adaptation—not an active campaign—while the Rockwell CVEs represent denial-of-service patch exposure without confirmed exploitation. The immediate defensive priorities are therefore exposure reduction, evidence preservation, trusted logic and configuration comparison, restricted CIP traffic, and tested firmware maintenance rather than assumptions of sabotage.
Langflow CVE-2026-0768 presents a much shorter path to material compromise. Unauthenticated Python execution as root through the validation interface effectively connects exposed instances to direct credential discovery. Environment variables are immediately reachable; cloud credentials, AI-service keys, SSH material, and shell histories are reachable if present and readable, with outbound connectivity governing exfiltration. But exposure alone does not prove execution, theft, persistence, or lateral movement. Isolation and preservation should precede rotation, followed by review of endpoint requests, supplied code, child processes, outbound connections, credential stores, authentication records, and root-level persistence.
Two other distinctions now carry decision weight. Core DAO’s fork can stop future excess issuance without recovering already circulated CORE; the undisclosed amount and its movement leave the inflationary liability unresolved. Cronos has a reported gross exploit value above $74 million, but roughly $6 million moved to Ethereum is the clearest externally realizable portion, and neither rollback nor TVL collapse establishes final net loss. Ontology and ICON remain even less quantified. In the Softaculous incident, BGP diversion and fraudulent-but-valid certificate issuance enabled delivery, but the load-bearing failure was the absence of independently verified, cryptographically signed updates; only a handful of deliveries are confirmed, not universal compromise.
The next question is how these technical footholds become durable access. We will now test Langflow’s cloud blast radius, compare several distinct forms of identity and session abuse, and challenge the claim that these events demonstrate autonomous AI transforming offensive operations.