LIVE · cybersecurity feed
Live wire
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewMedusa ransomware gang has hit over 500 organizations, CISA warnsCritical RCE flaw in Windows IKE Extension now actively exploitedOracle August 2026 Critical Security Patch Update Addresses 925 CVEs
aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

zeroday.news ·

Five U.S. federal agencies have issued a joint alert regarding an active threat in which attackers are utilizing AI-generated exploitation scripts to compromise internet-exposed Siemens S7 Series programmable logic controllers (PLCs). The targeted facilities include critical infrastructure in the water, manufacturing, energy, chemical, food and agriculture, and commercial sectors, with potential implications for the Defense Industrial Base.

The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA) confirmed that this is an ongoing threat, not merely theoretical. The attackers are reportedly combining open-source industrial automation libraries, specifically snap7.dll/python-snap7, with AI coding assistants to develop custom tools. These tools mimic operational technology (OT) monitoring software, enabling read/write access to PLC memory, configuration data, and ladder logic programs via the S7comm protocol.

While the alert does not attribute the attacks to a specific group, there is suspicion that Iranian cyber operatives are involved. This activity is believed to be a continuation of previous attacks targeting PLCs at water and wastewater facilities across at least 12 states, including an incident in late July that affected over 30 community water systems in Minnesota. Experts suggest that state-sponsored adversaries are increasingly leveraging AI for tasks such as code checks and scripting to enhance the speed and scale of their operations.

The use of AI in these attacks signifies an evolution in threat actor capabilities, potentially lowering the technical expertise required to develop industrial control system malware and attack chains. Attackers are using internet-scanning services like Censys and ZoomEye to identify poorly protected PLCs that are internet-exposed, running outdated software, or using default passwords. They then employ AI assistance to generate exploitation scripts based on publicly available information about Siemens S7 Series PLCs. This allows them to achieve initial access, credential access, denial of service, and other objectives.

To mitigate this threat, critical infrastructure owners and operators are advised to immediately inventory all Siemens S7 Series PLCs within their environments. Essential steps include applying necessary security patches and ensuring that no PLCs are directly accessible from the internet.

Detection strategies include monitoring for anomalous S7comm behavior, such as connections originating from non-engineering workstations, unusual data block access patterns, or write operations occurring outside of designated change windows. Sequential IP scanning on port 102 and repeated connection attempts with varying parameters could indicate reconnaissance activities. Furthermore, the use of the Snap7.dll library outside of approved workstations may signal an intrusion.

Beyond specific indicators of compromise, experts emphasize the importance of reducing the overall OT attack surface. This includes implementing data diodes for data flow that only needs to leave an OT network, thereby preventing a return network path for attackers to exploit. The increasing ease with which AI allows attackers to create and modify PLC-targeting scripts underscores the urgency of these foundational security measures.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.

ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

cloud

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

breach

Healthtech firm CareCloud data breach impacts 3.7 million patients

U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]

security

ICE boss to agents: Leave the Meta spy glasses at home

'Personally owned body-worn cameras are prohibited,' ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct

breach

Electronic health record company CareCloud says 3.7 million people affected by breach

Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.