Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

Five US federal agencies have issued a warning that attackers are using AI-generated scripts to hack internet-connected Siemens S7 Series programmable logic controllers (PLCs) at critical infrastructure facilities. The agencies, including the NSA, CISA, FBI, DOE, and EPA, stated that this is an "active threat" and not a theoretical risk.

The attackers utilize open-source industrial automation libraries, such as snap7.dll and python-snap7, along with AI coding assistants to create custom tools that mimic OT monitoring software and grant read/write access to PLC devices' memory, configuration data, and ladder logic programs through the S7comm protocol. While the source of the attacks remains unidentified, Iranian cyber operatives are suspected of recent intrusions targeting PLCs at water and wastewater facilities in at least 12 US states, including a cyberattack that disrupted more than 30 community water systems in Minnesota.

The agencies advise critical infrastructure owners and operators to inventory all Siemens S7 Series PLCs, apply security patches, and ensure no PLCs are accessible from the internet. They also recommend checking for anomalous S7comm behavior and using data diodes to reduce the OT attack surface.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

My Wi-Fi router

Access restrictions My router has been configured to allow only three devices to login to its management console (Web UI): my PC, laptop, and mobile phone.

More from Wednesday 19 August →