{
  "id": 2188550,
  "title": "Hackers are using “evolved” capabilities in AI-generated malware to hit US critical infrastructure at an unprecedented scale — “active threat” currently hitting energy, water and agricultural industries",
  "url": "https://urgent.news/2026/08/20/hackers-are-using-evolved-capabilities-in-ai-generated-malware-to-hit",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-20T17:15:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/hackers-are-using-evolved-capabilities-in-ai-generated-malware-to-hit-us-critical-infrastructure-at-an-unprecedented-scale-active-threat-currently-hitting-energy-water-and-agricultural-industries"
  },
  "original_language": "en",
  "account": "Hackers are employing advanced AI-generated malware to launch attacks on US critical infrastructure, targeting energy, water, and agricultural industries. The threat is currently active, according to a warning from federal agencies including the NSA and FBI. The malicious software infiltrates Programmable Logic Controllers (PLCs) – widely used in energy, water, and agricultural operations to control pumps and monitor systems.\n\nThe attackers are utilizing \"AI-assisted development\" to chain exploitations, allowing them to gain control of PLCs. This marks a significant evolution in attacker capabilities, with AI systems reducing the technical expertise and time needed to create malicious tools and scripts. The advisory warns that exploitation of poorly protected PLCs could lead to disruption of industrial processes, safety incidents, downtime, equipment damage, data compromise, compliance violations, and cascading impacts across interconnected systems.\n\nWhile the attackers' identities remain unknown, critical infrastructure systems are a prime target for state-sponsored groups. They identify vulnerable PLCs through internet scanning platforms and disguise the malware as monitoring tools to avoid detection. To defend against these attacks, the advisory recommends isolating PLCs from the internet and promptly applying software updates.\n\nThe surge in attacks against critical infrastructure is linked to the ongoing US conflict with Iran. In July 2026, an attack against 30 Minnesota community water systems showed evidence of Iranian involvement. Shortly before this, the Cybersecurity and Infrastructure Security Agency (CISA) had issued a warning about active attacks on Rockwell Automation, Schneider Electric, and Siemens PLCs. In April, Rockwell Automation/Allen-Bradley-manufactured PLCs were exploited in attacks targeting water, energy, and government systems. Automatic Tank Gauge (ATG) systems also faced attacks, posing risks to fuel monitoring, temperature control, and leak detection. Russia has also been implicated in global attacks on critical infrastructure, targeting broken and poorly configured networking devices that had reached their End-of-Life (EoL) and stopped receiving updates.",
  "summary": "The attackers are exploiting internet-facing Siemens S7 Series programmable logic controllers to scout for potential targets.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}