Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

Five US federal agencies have issued an active threat warning, stating that attackers are using AI-generated exploitation scripts to hack into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at critical infrastructure facilities. These facilities include water, manufacturing, energy, and other essential services across the United States.

Attackers are utilizing open-source industrial automation libraries, such as snap7.dll/python-snap7, alongside AI coding assistants to create custom tools that mimic operational technology (OT) monitoring software and gain read/write access to PLC devices' memory, configuration data, and ladder logic programs. While the joint alert does not attribute the threats to a specific entity, Iranian cyber operatives are suspected of being behind recent attacks targeting PLCs at water and wastewater facilities in at least 12 states.

The agencies warn that this is not a theoretical risk but an active threat, and state-sponsored adversaries are leveraging AI across various sectors to increase their efficiency and scale operations.

Brief written by urgent.news from The Register Science's own syndicated text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

My Wi-Fi router

Access restrictions My router has been configured to allow only three devices to login to its management console (Web UI): my PC, laptop, and mobile phone.

More from Wednesday 19 August →