US federal agencies have warned of an active threat where attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at critical facilities. The attackers are combining open source industrial automation libraries with AI coding assistants to create custom tools that mimic operational technology (OT) monitoring software.
Key Insights
The attacks specifically target internet-exposed Siemens S7 Series PLCs at water, manufacturing, energy, and other critical facilities, with Iranian cyber operatives suspected of being behind recent attacks targeting PLCs at water and wastewater facilities. The use of AI-generated code in these attacks highlights the evolving nature of cyber threats to critical infrastructure.









