The Register
The Register
UK · 12 mins ago

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

Attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities, in what five US federal agencies on Wednesday called an “active threat.”In this latest round of intrusions against American critical infrastructure, the attackers use open source industrial automation libraries – specifically snap7.dll/python-snap7 – combined with AI coding assistants. Armed with the open source libraries and AI, the miscreants create custom tools that mimic operational technology (OT) monitoring software and provide read/write access to the PLC devices’ memory, configuration data, and ladder logic programs via the S7comm protocol.“This is not a theoretical risk – it is a
The Register
Do you trust The Register?
Sign in to rate
Discussion
?

No comments yet — be the first to start the discussion!