US agencies warn of AI-generated attacks on Siemens controllers
The NSA, CISA, FBI, the Department of Energy and the Environmental Protection Agency issued a joint advisory on 19 August describing an active campaign against internet-exposed Siemens S7 Series programmable logic controllers. The agencies said threat actors are using AI-generated exploitation scripts, disguised as legitimate monitoring tools, to conduct reconnaissance and develop attack capability against PLC installations across manufacturing, energy, water and wastewater, chemical, and food and agriculture facilities.
The advisory, designated AA26-231A, attributes the activity to an Iranian IRGC-affiliated group publicly tracked as CyberAv3ngers, which US authorities have linked to industrial-control-system attacks against American water, energy and manufacturing facilities since at least November 2023. Officials said a successful intrusion could disrupt industrial processes, damage equipment or compromise sensitive operational data.
Generative tools that once mainly sped up reconnaissance are now producing exploit code aimed at systems built decades before anyone had to think about either.