Attackers use AI-made code to hack critical infrastructure controllers
Federal agencies issued a warning regarding an active threat where attackers are utilizing AI-generated code to compromise critical infrastructure controllers. This marks a shift from theoretical discussions to real-world incidents involving AI-made malicious software. The specific targets and extent of the breaches were not detailed. The threat is now considered active.
Severity: Critical · Category: Supply Chain
Impact: Compromise of critical infrastructure controllers.
Source: The Register · Aug 19 2026 · Original source
What Happened
Attackers are actively using AI-generated exploitation scripts to compromise internet-exposed Siemens S7 Series programmable logic controllers (PLCs) within critical infrastructure facilities. These facilities include those in the water, manufacturing, and energy sectors. This activity represents a new round of intrusions against American critical infrastructure, which five US federal agencies have identified as an "active threat."
The attackers combine open source industrial automation libraries, specifically snap7.dll/python-snap7, with AI coding assistants. This combination enables them to create custom tools that mimic operational technology (OT) monitoring software. These tools then provide read/write access to the PLC devices' memory, configuration data, and ladder logic programs via the S7comm protocol. The attacks exploit poorly protected PLCs that are running outdated software or using default passwords, which attackers locate using internet-scanning services such as Censys and ZoomEye.
Technical Analysis
The exploit mechanism leverages AI coding assistants in conjunction with publicly available open source industrial automation libraries, specifically snap7.dll/python-snap7. This allows threat actors to generate custom exploitation scripts. These scripts are designed to mimic legitimate OT monitoring software, enabling them to interact with Siemens S7 Series PLCs via the S7comm protocol. The objective is to gain read/write access to the PLCs' memory, configuration data, and ladder logic programs.
The attacks specifically target internet-exposed Siemens S7 Series PLCs that are vulnerable due to poor protection, outdated software, or the use of default passwords. Threat actors utilize internet-scanning services like Censys and ZoomEye to identify these exposed systems. The use of AI in generating these exploitation scripts reduces the need for advanced technical knowledge in operational technology, thereby lowering the barrier to entry for attackers and allowing for more rapid development of industrial control system malware and attack chains. The generated scripts are used for various objectives, including initial access, credential access, and denial of service, by exploiting critical and high severity known vulnerabilities in insufficiently segmented or internet-exposed PLCs.
Impact
The attacks have resulted in the compromise of Siemens S7 Series PLCs across various critical infrastructure sectors, including critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. These sectors provide essential goods and services to Americans. There is also a potential for targeting PLCs within the Defense Industrial Base (DIB).
Attackers gain read/write access to the memory, configuration data, and ladder logic programs of the affected PLCs. This access facilitates initial access, credential access, denial of service, and other malicious objectives. The use of AI in these attacks signifies an evolution in threat actor capabilities, as it reduces the requirement for advanced technical knowledge in operational technology and accelerates the development of industrial control system malware and attack chains, thereby lowering the overall barrier to attacking industrial systems.
How Fencio prevents this
The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.
Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.