Urgent.News

What's breaking now, across thousands of outlets.

Tech

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

A federal warning has been issued regarding the risks posed by attackers utilizing AI-generated code to infiltrate critical infrastructure controllers. Five US federal agencies have deemed this an active threat. The attackers employ open source industrial automation libraries, namely snap7.dll and python-snap7, in conjunction with AI coding assistants to generate customized tools that mimic operational technology (OT) monitoring software.

These tools provide read and write access to PLC devices' memory, configuration data, and ladder logic programs via the S7comm protocol. While the agencies attribute the threats to unknown perpetrators, Iranian cyber operatives are suspected of initiating recent attacks on PLCs at water and wastewater facilities in 12 states, including a cyberattack that disrupted over 30 community water systems in Minnesota in late July.

Cynthia Kaiser, SVP of the Halcyon Ransomware Research Center, stated that Iranian-affiliated actors are actively targeting a broad range of operational technology, including PLCs, due to their critical role in essential health, safety, and infrastructure across society. National security and cybersecurity experts previously warned of this threat, expressing concern that attackers would soon incorporate AI into their arsenal for attacking critical infrastructure.

Siemens S7 Series PLCs are the primary focus of the latest attacks, as they are widely used across various critical industries, including manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. The agencies advised internet-exposed PLCs to be immediately inventoried, security patches applied, and exposure to the internet eliminated.

Anomalies in S7comm behavior, such as connections from non-engineering workstations or unusual data block access patterns, should also be monitored for potential intrusions.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

My Wi-Fi router

Access restrictions My router has been configured to allow only three devices to login to its management console (Web UI): my PC, laptop, and mobile phone.

More from Wednesday 19 August →