LIVE · cybersecurity feed
Live wire
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsCritical Elementor Pro bug exposes WordPress sites to RCE attacksThe push to designate AI as the next critical infrastructure sectorCritical Zimbra RCE flaw now actively exploited in attacksExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerCVE-2026-19478 · Critical GitLab Flaw Exploited Shortly After DisclosureCVE-2026-32475 · Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
aicritical

NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs

NSA, CISA, FBI, DOE, and EPA warn of active AI-assisted attacks against Siemens S7 PLCs across US critical infrastructure sectors. Five U.S. federal agencies issued a joint advisory this week warning of an active hacking campaign against Siemens S7 Series programmable logic controllers. The advisory, CISA AA26-231A, is co-signed by NSA, FBI, DOE, and EPA […]

zeroday.news ·

Five U.S. federal agencies, including the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA), have issued a joint advisory warning of active, AI-assisted attacks targeting Siemens S7 Series programmable logic controllers (PLCs) across critical infrastructure sectors. The advisory, CISA AA26-231A, confirms that this is an ongoing threat, not a theoretical risk, impacting all S7 generations from the S7-200 to the S7-1500 F-series safety controllers.

Threat actors are reportedly conducting reconnaissance and developing capabilities against U.S.-based Siemens PLC installations. A key aspect of these attacks is the use of AI-generated exploitation scripts, which are disguised as legitimate operational technology (OT) monitoring tools to evade detection. The attackers leverage internet scanning services such as Censys and ZoomEye to identify internet-exposed PLCs running outdated software or those with inadequate security configurations.

The critical infrastructure sectors most affected by this activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. The Defense Industrial Base is also specifically named due to its reliance on S7-series hardware.

The attackers are not using custom malware but rather legitimate, open-source industrial automation tools, specifically the `snap7.dll` and `python-snap7` libraries. These libraries facilitate direct communication with Siemens PLCs over the S7comm protocol on TCP port 102, enabling access to PLC memory, configuration data, and ladder logic programs. The use of AI to generate exploitation scripts significantly reduces the technical expertise and time required for adversaries to develop functional ICS exploitation tools, allowing them to rapidly adapt to defensive measures and exploit additional attack vectors.

The observed attack activity unfolds in two distinct phases. Initially, actors use scanning services to locate internet-exposed PLCs. Following this, they perform read operations to understand the target environment, gathering information about specific CPU models and refining their techniques before attempting any write operations. The agencies assess this as a pre-positioning phase, where attackers are mapping environments and testing methods in preparation for potential disruptive actions.

Should these actors escalate from read to write operations, the potential consequences are severe. These include process disruption, equipment damage, and safety incidents through the manipulation of interlocks or emergency shutdown systems, potentially causing cascading effects across interconnected supply chains.

A particular concern highlighted in the advisory is third-party exposure. Asset owners who rely on system integrators or managed service providers for remote PLC access may be unaware that their controllers are internet-accessible. Organizations are urged to verify that connections maintained by external support partners are properly segmented and monitored.

Defenders are advised to monitor for several indicators of compromise. These include S7comm connections originating from devices not typically used for engineering, PLC read or write activity occurring outside of scheduled maintenance windows, and scans of multiple IP addresses on TCP port 102. The presence of Python processes loading `snap7.dll` on systems where it should not be present, along with connections from unexpected countries or locations, should also trigger alerts.

Mitigation strategies prioritize a comprehensive inventory of all controllers, followed by immediate patching, with internet-facing controllers receiving top priority. Organizations should block TCP port 102 at the perimeter firewall, enforce password protection on all controllers, and configure protection levels to restrict unauthorized or low-privilege sessions from reading or writing data. Deploying ICS-aware monitoring solutions capable of baselining legitimate S7comm behavior is also recommended.

Further guidance includes disabling the PLC web server when not needed, limiting simultaneous S7comm sessions, and utilizing TIA Portal's know-how protection and complete restart protection features. The advisory concludes by recommending direct engagement with Siemens ProductCERT for model-specific hardening advice and to verify patch compatibility, a critical step in OT environments where firmware updates can have complex interactions with third-party integrations and may not be easily reversible.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Detailed Timeline of OpenAI’s Cyberattack on Hugging Face

OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.

security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.

malwarehigh

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]

vulnerability

N-able Bug Exposes Password Vault Master Keys

The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?

security

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears

The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.