AI is getting closer to being able to exploit OT, and that's very bad news for critical infrastructure
The situation is not disastrous just yet, but it's definitely time to start paying attention, Forescout hints.
Forescout researchers have discovered that AI can be used to transfer remote code execution (RCE) exploits to Programmable Logic Controllers (PLCs), resulting in Denial of Service (DoS) and shellcode execution. However, the effort required to achieve this is significant, involving substantial researcher input and over $500 in API usage. The researchers noted that while the attack is possible, the difficulty, cost, and specialized expertise required make it less attractive for cybercriminals compared to other options.
The researchers emphasize that the threat from nation-state actors with substantial resources remains a major concern. The 2025 Sandworm attack on Poland's power grid serves as a prime example of the risks posed by such adversaries. These attackers are unlikely to be deterred by the cost of $500 in API usage, as it is a small fraction of their overall budget.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.