LIVE · cybersecurity feed
Live wire
NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewMedusa ransomware gang has hit over 500 organizations, CISA warnsCritical RCE flaw in Windows IKE Extension now actively exploitedOracle August 2026 Critical Security Patch Update Addresses 925 CVEsOpenAI Overhauls Safety Protocols After Its AI Agents Went RogueCVE-2026-68820 · CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
ai

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.

zeroday.news ·

U.S. government agencies have issued a joint warning regarding active threats to critical infrastructure sectors, including water, food, energy, chemical, manufacturing, and commercial facilities. The alerts specify that attackers are targeting Siemens S7 Series programmable logic controllers (PLCs) and are employing artificial intelligence to generate exploitation scripts.

The advisory, released by the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), FBI, Department of Energy (DOE), and Environmental Protection Agency (EPA), highlights the use of AI-generated scripts as an evolution in threat actor capabilities. This method is said to significantly reduce the technical expertise and time required to develop working industrial control system (ICS) exploitation tools. AI also enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures.

Attackers are reportedly using internet scanning services to identify exposed PLCs that are running outdated software or are otherwise poorly protected. The AI-generated scripts are designed to mimic legitimate monitoring tools, allowing them to blend in with normal network traffic. This approach could enable attackers to disrupt industrial processes, cause safety incidents, or compromise sensitive data.

While the current advisory specifically mentions Siemens S7 Series PLCs, experts note that the underlying exposure patterns are not brand-specific. An adversary who understands a system's data blocks and processes could potentially apply similar tactics to other PLC manufacturers.

This warning marks a significant development, as it is reportedly the first time CISA has stated in a cybersecurity advisory that a malicious actor is using AI scripts to target operational technology (OT) systems. The advisory emphasizes traditional defensive measures rather than recommending AI-based responses.

The agencies did not attribute the attacks to any specific nation-state or group. This alert follows a previous government warning about a campaign against water and wastewater systems, which the government attributed to Iran, though Iran was not mentioned in the current advisory.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.

security

ICE boss to agents: Leave the Meta spy glasses at home

'Personally owned body-worn cameras are prohibited,' ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct

breach

Electronic health record company CareCloud says 3.7 million people affected by breach

Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.

security

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]

security

41 deceptive download sites show a real link, then send you somewhere else

A legitimate-looking link or valid digital signature can offer false reassurance. Here’s why familiar download safety checks aren’t always enough.

phishing

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China's APTs.