This Week in AI Security: Rogue Packages, PLC Hacks by Chatbot, and Leaky Stripe Keys
A weekly roundup of the AI and infrastructure security stories that actually matter, translated into plain English.

Key points
- Researchers this week showed AI models can write working attacks against industrial control computers, the machines that run factories and water plants.
- GitLab, a popular tool for storing software code, is under active attack through flaws its maker has already patched.
- Thousands of live Stripe payment keys have been found leaking on the public internet, giving criminals a direct line to merchant accounts.
- Malicious software packages keep sneaking into open-source code libraries that ordinary apps quietly depend on.
- The common thread: attackers are using AI to make old attacks cheaper and faster, not to invent science fiction.
A package gets installed. A login box opens. A server sits quietly on the open internet. Nothing looks wrong. That was the mood across security research this week, and it was busy. Trusted tools turned hostile, old weak spots got fresh attention, and AI kept lowering the price of doing crime.
What was the biggest AI security story this week?
Researchers showed that large language models can write functional attack code against PLCs, the small industrial computers that control things like factory floors and water treatment pumps. The same chatbots that help students with homework can help an attacker meddle with a bottling plant.
This isn't a Hollywood scenario. PLCs, short for programmable logic controllers, have been notoriously weak for years. Stuxnet targeted them back in 2010. What changed is the effort required. A skilled specialist used to be needed; now a competent hobbyist with a good prompt gets uncomfortably close. We've covered PLC threats seven times in the last 90 days, starting with our 3 August report on water systems under attack, and the direction of travel is consistent: the barrier keeps dropping.
For the rest of us, this matters because these boxes sit behind tap water, medicines and food packaging. None of it fell over this week. But the cost of trying just fell.
Are GitLab users in danger?
Yes, if they haven't patched. GitLab, a widely used platform where software teams store and review their code, is being actively attacked through flaws the company has already fixed in recent updates. Our 17 August story on a critical GitLab flaw rated 9.4 out of 10 showed exactly what unauthenticated access to that platform looks like in practice.
The risk isn't abstract. If criminals get into a company's GitLab, they can quietly slip malicious code into products that company later ships to its customers. That's how supply-chain attacks work, and it's why patching a code repository isn't an internal IT chore; it's a customer safety issue.
Admins should be on the latest release. Everyone else should ask their vendors when they last updated theirs.
The Stripe key leak, in plain English
Security researchers found thousands of live Stripe API keys, the secret credentials that let a website charge your card through Stripe, sitting exposed on the public internet. Some turned up in code posted to GitHub, others were baked into mobile apps or left on unprotected servers.
A leaked live key is roughly equivalent to a shop owner taping their card machine's PIN to the front window. Anyone who spots it can start pulling money or reading customer data until someone notices. Stripe rotates keys quickly when told, but the pattern repeats across every payment provider. It's the modern version of hardcoded passwords, which developers have been warned about since the 1990s.
The rest of the week, briefly
| Story | What happened | Who should care |
|---|---|---|
| Malicious npm packages | Fake code libraries kept appearing in the npm registry, aimed at developers | Anyone running a software team |
| AI-written exploits | Multiple write-ups showed models generating working attack code from public bug reports | Defenders, patch teams |
| Exposed admin panels | Scanners found thousands of login pages sitting on the open internet | IT admins, small businesses |
The pattern across all of it is dull and important: the attacks aren't new, the tooling is just cheaper. As we noted in our 17 August roundup, exposed servers and old bugs still do most of the damage.
Should you worry?
Not obsessively. Keep your phone and laptop updated. Turn on two-step login, where a code from your phone is needed alongside your password, for anything connected to your money or your email.
Run a small shop that uses Stripe or a similar service? Ask whoever built your website when they last rotated the keys. A blank stare is your answer.



