Ethical Hacking News
US federal agencies warn of an active threat as attackers use AI-generated code to hack critical infrastructure controllers, posing a significant risk to national security and critical infrastructure.
The US federal agencies have issued a security alert warning of the growing threat of AI-generated code in hacking critical infrastructure controllers. The attackers use AI-coded scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at critical facilities. The attack vector involves open-source industrial automation libraries and AI coding assistants to create custom tools that mimic operational technology (OT) monitoring software. The use of AI-generated code in these attacks is a significant escalation in the threat landscape, and organizations must take proactive measures to secure their critical infrastructure. The attackers use internet-scanning services to find exposed PLCs, and the AI boost enables them to generate exploitation scripts using publicly available information. The impact of this threat is far-reaching, and organizations must ensure that PLCs are not accessible from the internet and apply security patches as needed. The use of AI in these attacks indicates an evolution in threat actor capabilities, reducing the need for advanced technical knowledge about OT. Organizations must take proactive measures to secure their critical infrastructure, including inventorying PLCs, applying security patches, and reducing the OT attack surface.
The recent security alert issued by the US federal agencies, including the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA), has highlighted the growing threat of AI-generated code in hacking critical infrastructure controllers. The alert warns that attackers are using AI-made exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities.
The attack vector involves the use of open-source industrial automation libraries, specifically snap7.dll/python-snap7, combined with AI coding assistants. This allows the attackers to create custom tools that mimic operational technology (OT) monitoring software, providing read/write access to the PLC devices' memory, configuration data, and ladder logic programs via the S7comm protocol. This is not a theoretical risk, but an active threat, as the alert emphasizes.
The use of AI-generated code in these attacks is a significant escalation in the threat landscape. The attackers use internet-scanning services such as Censys and ZoomEye to find exposed, "poorly protected" PLCs running outdated software or using default passwords. The AI boost enables the attackers to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives.
The impact of this threat is far-reaching, as the Siemens S7 Series PLCs are used in various critical sectors, including the Defense Industrial Base (DIB), and could be targeted there as well. The real lesson for organizations is to stop giving attackers a path to the critical system in the first place. This means ensuring that PLCs are not accessible from the internet and applying security patches as needed.
The use of AI in these attacks also indicates an evolution in threat actor capabilities, reducing the need for advanced technical knowledge about OT, and allowing the attacker to more rapidly develop working industrial control system malware and attack chains. According to Cynthia Kaiser, Halcyon Ransomware Research Center SVP, "Iran-affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society."
The incident highlights the need for organizations to take proactive measures to secure their critical infrastructure. This includes inventorying all Siemens S7 Series PLCs in their environment, applying security patches as needed, and ensuring that no PLCs are accessible from the internet. Additionally, organizations should check for anomalous S7comm behavior, including connections from non-engineering workstations, unusual data block access patterns, or write operations outside change windows.
The use of AI in these attacks also underscores the need for a more comprehensive approach to security. According to Benny Czarny, CEO and founder of critical infrastructure security firm Opswat, "AI makes it much easier for an attacker to create and modify scripts targeting PLCs, so the barrier to attacking industrial systems continues to fall." Czarny emphasizes the importance of reducing the OT attack surface, which can be achieved by using data diodes and ensuring that there is no network path back to the PLC for an attacker to exploit.
In conclusion, the recent security alert highlights the growing threat of AI-generated code in hacking critical infrastructure controllers. The use of AI in these attacks is a significant escalation in the threat landscape, and organizations must take proactive measures to secure their critical infrastructure. This includes applying security patches, ensuring that PLCs are not accessible from the internet, and using data diodes to reduce the OT attack surface.
Related Information:
https://www.ethicalhackingnews.com/articles/AI-Generated-Code-Hack-Critical-Infrastructure-Controllers-A-Growing-Threat-to-National-Security-ehn.shtml
https://www.theregister.com/security/2026/08/19/not-a-theoretical-risk-feds-warn-as-attackers-use-ai-made-code-to-hack-critical-infrastructure-controllers/5289960
Published: Wed Aug 19 18:28:58 2026 by llama3.2 3B Q4_K_M