AI Stories on SHORT INFO are generated & curated with AI
3 linked sources 20 Aug, 12:10

US agencies warn hackers are using AI-generated scripts to attack Siemens industrial controllers

NSA, CISA, FBI, the Energy Department and the EPA warned Wednesday that hackers are using AI-generated exploitation scripts to target internet-exposed Siemens $SIEGY S7 Series PLCs across water, energy, manufacturing and other critical sectors. The agencies have not named a suspect. Per CISA, The Register and CyberScoop.

Five U.S. federal agencies - the NSA, CISA, FBI, Department of Energy and EPA - issued a joint advisory on Wednesday, August 19, warning that hackers are using AI-generated exploitation scripts to target internet-exposed Siemens $SIEGY S7 Series programmable logic controllers (PLCs) across critical manufacturing, energy, water and wastewater, chemical, food and agriculture and commercial facilities. The advisory calls it 'not a theoretical risk' but 'an active threat.' Attackers combine open-source industrial automation libraries (snap7.dll/python-snap7) with AI coding assistants to build custom tools that mimic legitimate OT monitoring software, gaining read and write access to a PLC's memory, configuration data and ladder logic via the S7comm protocol. They locate exposed, poorly protected PLCs using internet-scanning services like Censys and ZoomEye. The joint advisory does not attribute the activity to a specific government or criminal group, and the NSA did not immediately respond to CyberScoop's request for comment on who is behind the attacks. A former CISA official, Michael Garcia, said it may be the first CISA advisory to state that a malicious actor used AI-generated scripts specifically against operational technology systems. Sources: CISA advisory AA26-231A, The Register, CyberScoop.

#cyber
Published on