ZeroHour
CyberScooppublished ()ingested @timstarks1

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

highAdvisory exploited in the wildimportance 72
AI summary · glm-5.3-flash

NSA, CISA, FBI, DOE and EPA warn hackers are using AI-generated scripts to actively attack Siemens S7 PLCs across critical-infrastructure sectors.

A joint cybersecurity advisory from the NSA, CISA, FBI, Department of Energy and EPA warns of an active threat campaign targeting water, food, energy, chemical, manufacturing and commercial facilities via Siemens S7 Series programmable logic controllers. The actors use internet scanning to find exposed or poorly protected PLCs, then deploy AI-generated exploitation scripts disguised as legitimate monitoring tools, an OT first that dramatically lowers the expertise required for ICS attacks. Siemens says no new S7 vulnerabilities are involved, only exploitation of misconfigurations, and it is coordinating with CISA's ProductCERT. The warning follows a joint FBI-EPA advisory confirming attacks at water and wastewater utilities in at least 12 states since July 27.

  • Advisory calls the attacks an 'active threat' that could disrupt industrial processes or compromise data.
  • First CISA cybersecurity advisory to flag AI-generated scripts for ICS/OT exploitation.
  • Siemens says no new S7 vulnerabilities; attackers exploit misconfigurations and outdated software.
  • Scans found 4,400 internet-exposed PLCs, including 22 in recently targeted cities.
Full article951 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first.

Listen to this article

0:00

Learn more.

Programmable Logic Controller PLC System in Industrial Cabinet - stock photo, Ivan Shevchenko, Getty Images

Hackers are targeting water, food, energy, chemical, manufacturing and commercial facilities by taking aim at Siemens S7 Series programmable logic controllers (PLCs) and making use of artificial intelligence in the attacks, U.S. government agencies warned Wednesday.

It’s the latest government warning about attacks on critical infrastructure as the United States wages war against Iran, which the government blamed for a recent campaign against water and wastewater systems— but doesn’t mention in Wednesday’s alert. 

The National Security Agency didn’t immediately respond to a request for comment about who was behind the attacks on the PLCs, which are used to control manufacturing processes.

The agencies said the attacks were an “active threat,” rather than a theoretical one. The attacks could disrupt critical industrial processes, cause safety incidents or lead to the compromise of sensitive data.

Wednesday’s alert from the NSA, Cybersecurity and Infrastructure Security Agency, FBI, Energy Department and Environmental Protection Agency makes special note of the hackers using AI-generated exploitation scripts in the attacks.

“Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools,” the alert states. “In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information.”

A former top CISA official, Michael Garcia, thought that it was a first for the agency in one of its cybersecurity advisories (CSAs) about operational technology (OT).

“It is the first alert I have seen where CISA is saying in a CSA that a malicious actor is using AI scripts to target OT systems,” Garcia, now vice president of the cybersecurity practice at Monument Policy Advocacy, said on LinkedIn. But the advisory doesn’t recommend using AI in response, instead focusing on well-known, traditional defensive measures, he added.

Frenos, an OT penetration testing company, found another element of the alert troubling: The method by which the attackers could use the approach beyond Siemens-made PLCs.

“Siemens S7 is the subject here, but the exposure pattern is not brand specific,” Brian Proctor, CEO of the company, said in an email. “An adversary who has mapped your data blocks understands your process. They know what normal looks like, which means they know what an operator would fail to notice.”

The AI-generated scripts are disguised as legitimate monitoring tools, the advisory said of the hackers behind them.

“The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected,” the advisory reads.

Siemens said it was “aware” of the alert and “is coordinating closely with CISA.”

“This advisory does not describe new vulnerabilities within the S7 Series programmable logic controllers (PLC). Instead, this reflects threat actors employing new techniques to exploit potential misconfigurations,” the company continued, noting a security bulletin it issued last month.

“Siemens will provide updates around this issue to potentially affected customers through our ProductCERT team,” it said. “At this point in time, we have not identified increased attack levels or unknown vulnerabilities in Siemens ICS products.”

Updated 8/20/2026: to include Siemens comment.

More Scoops

The FBI and Environmental Protection Agency issued a joint advisory last week confirming attacks at water and wastewater utilities in at least 12 states since July 27. (Getty Images)

Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online

A scan of internet-connected industrial equipment found 4,400 exposed PLCs, including 22 in cities recently targeted by water system attacks.

Miguel Escamilla Jr., mannufacturing manager of ShayoNano, demonstrates the operation of programmable logic controller at the company’s production plant July 25, 2017, in Stafford. The Singapore-based company chose Stafford to be their U.S. headquarters. (Photo by Yi-Chin Lee/Houston Chronicle via Getty Images)

Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn

Wind turbines are seen on a wind farm on a field between agricultural produce in a countryside in a village near Radom, Poland on May 19, 2025. (Photo by Dominika Zarzycka/NurPhoto)

After major Poland energy grid cyberattack, CISA issues warning to U.S. audience

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/hackers-use-ai-target-siemens-plcs-critical-infrastructure/