
AI-GENERATED exploit scripts have been observed targeting Siemens S7 Series programmable logic controllers in water and energy facilities, according to a joint advisory from US agencies the advisory.
Reports from Infosecurity Magazine and SecurityOnline provide further detail on the activity.
The advisory notes that no CVE identifiers have been assigned yet, as the threat relies on artificially generated code rather than a known vulnerability.
Attackers use AI to create tailored scripts that probe for poorly protected S7 PLCs, then leverage default or weak login credentials to gain a foothold.
Once inside, the malicious scripts can alter ladder logic, interrupt physical processes, or trigger unsafe conditions that may lead to service outages or safety incidents.
The advisory warns that the use of AI enables threat actors to rapidly adapt their tools, increasing the speed and scale of potential compromise across multiple sites.
The warning comes from NSA, CISA, FBI, the Department of Energy and the Environmental Protection Agency, which have observed active exploitation in the field.
While the actors remain unnamed, the advisory highlights that water treatment plants, power generation sites and manufacturing facilities are among the sectors most at risk.
Cascading effects from a compromised PLC could disrupt downstream processes and threaten public safety.
Operators should immediately restrict direct internet exposure of S7 devices and place them behind strong firewalls with strict allow‑lists.
Multifactor authentication must be enforced for any remote access, and third‑party service providers should be limited to privileged‑access workstations that are monitored continuously.
Network traffic between IT and OT zones ought to be inspected for anomalous script transfers or unexpected command sequences.
Applying the latest firmware patches from Siemens, disabling unused services and changing default passwords are basic steps that reduce the attack surface.
Organizations are encouraged to deploy OT‑focused intrusion detection systems that can flag AI‑generated payloads and to share indicators of compromise with ISACs and government partners.
Following the guidance in the CISA advisory helps maintain resilience against this evolving threat.