Historical intelligence backfill. This assessment covers reporting originally published on 2026-06-02 and was added to the RWP archive on 2026-09-07.
Team82 ran Claude Opus on a video intercom they already owned — the LLM found bugs, not a new ICS weapon
Claroty's 2 June 2026 "Hands Free" note is a research-methods piece — Anthropic Claude Opus 4.6 against Zenitel TCIV-3+ after Team82 had already disclosed five flaws. Treat it as a tempo warning, not as confirmed adversary tradecraft on a plant floor.
Bottom line up front
CONFIRMED Team82 published 2 June 2026 that they re-ran vulnerability research on Zenitel's TCIV-3+ IP video intercom using Anthropic Claude Opus 4.6 via Claude Code after they had already found and disclosed five issues (command injection, OOB write, XSS) the prior November. The experiment asked whether an LLM could match or beat the manual campaign, find new bugs, or chain existing ones. That is a lab methods result. It is not evidence that an adversary used the same pipeline against your BMS. Forescout's 1 September 2026 WAGO porting exercise (CVE-2021-31886, heavy human steering, a bricked PLC, hundreds of dollars of API spend) is the corroborating "AI can help, humans still drive" datapoint. Dragos's Monterrey water brief is a different claim — AI used during an IT intrusion to identify an OT interface — and is not this post. Process compromise: UNKNOWN / not applicable. Exposure of industrial intercoms: REPORTED as Team82's prior Zenitel work, not as a 2 June mass exploit.
Historical backfill of 2 June 2026 reporting; added 7 September 2026.
What happened
A controlled redo of known research with a frontier coding agent. Hours of human work vs a same-target LLM pass. Team82's own framing: "hands-free" is the next phase of the discipline, not a product launch.
Why it mattered
Vendor PSIRT clocks assume human researchers. If LLM-assisted finding compresses the same firmware from days to hours, patch SLAs that already miss ICS maintenance windows get worse. That is a tempo problem, not a new CVE class.
Who / what was affected
Zenitel TCIV-3+ as the test article. Broader XIoT/intercom estates that still run the November-disclosed bugs. Not a sector-wide incident.
Technical context
Do not treat "Claude found a bug" as "unauthenticated RCE in every PLC." Forescout needed disassembly context and still bricked hardware. Inventory internet-facing intercoms and jump hosts; that is the same advice as before the LLM demo.
Exploitation / threat status at the time
CONFIRMED Team82 methods write-up.
REPORTED prior Zenitel five-bug disclosure.
ASSESSED criminal/state actors will try similar tooling; not demonstrated here on ICS malware.
What defenders should have done
- Patch the already-disclosed Zenitel issues if those units are still in high-security doors.
- Assume researchers and some adversaries now have coding agents on firmware.
- Do not rewrite OT IR around "AI malware."
RWP assessment
Confidence: High that this is methods research. Low that it changes Monday's PLC hunt list.
Defensive actions
- XIoT intercom and badge-reader attack surface.
- Watch PSIRT mail for LLM-accelerated duplicates of last year's bugs.
- Keep Dragos's Mexico AI-on-SCADA brief as a separate incident if you brief the board.
Sources
- Claroty Team82 — Hands Free — LLM driven vulnerability research
- Forescout — Can AI create PLC attacks? Yes, but not that easy yet
- Dragos — AI-assisted identification of OT during a Mexican water-utility IT intrusion (intel brief)