'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

US federal agencies have warned that attackers are using AI-generated code to target Siemens S7 programmable logic controllers used in critical infrastructure, including water, ene

By The Register

US federal agencies have warned that attackers are using AI-generated code to target Siemens S7 programmable logic controllers used in critical infrastructure, including water, energy, manufacturing and other facilities. The agencies described it as an active threat and said the attackers are using publicly available information, open-source industrial automation libraries and AI coding tools to create exploitation scripts.

The warning focuses on internet-exposed controllers and systems that are poorly segmented or inadequately protected. According to the report, the tooling can give attackers read and write access to PLC memory, configuration data and ladder logic via the S7comm protocol.

The federal advice is for critical infrastructure owners and operators to inventory Siemens S7 devices, apply patches, and make sure PLCs are not directly accessible from the internet. They are also being urged to look for unusual S7comm traffic, suspicious scanning on port 102 and use of Snap7-related libraries outside approved workstations.

Open article on Cheshire Today