Published · yesterdayBuild2 min read
Five agencies, one Siemens S7 warning, and a claim that AI is writing the exploit scripts
CISA's advisory describes a mechanism, not a vulnerability: commercial scanners find the exposed PLC, and the agencies say AI tooling closes the distance from found to controlled.
Written for builders.See today for builders

What happened
- According to a CISA advisory, threat actors are targeting Siemens S7-series programmable logic controllers, using publicly available information on these widely used devices to develop exploits that would enable remote access and control.
- The advisory was co-authored by CISA, the National Security Agency, the Federal Bureau of Investigation, the Department of Energy and the Environmental Protection Agency.
- CISA said in the warning: "The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected."
- CISA named the most targeted U.S. critical infrastructure sectors as Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities.
- CISA said of the activity: "This is not a theoretical risk - it is an active threat."
Compiled by The EngineerSomething wrong?How this is made
Why it matters
The reconnaissance in this advisory is not performed by the attacker. According to CISA, the actors use internet scanning services to find internet-exposed PLCs that are running outdated software or are otherwise poorly protected [3]. The quoted language describes a version-and-configuration condition rather than a single named flaw [3], which means the target list is generated continuously by third parties and refreshed without anyone attacking anything.
What historically sat between appearing in a scan result and being under someone else's control was labour: learning the protocol, matching firmware behaviour, building tooling that does not crash the device. The agencies say the actors are using publicly available information on these widely used controllers to develop exploits that permit remote access and control [1], and that AI tools are helping them identify additional attack vectors and possibly adapt to defensive measures operators have already put in place [7]. Read as an engineering statement, that is a claim about cost. The scanning half of the kill chain was already cheap; the advisory says the bespoke half is getting cheaper too.
The detail that undercuts the mitigation list is further down. Agencies say AI tooling can make malicious files look and behave like legitimate monitoring tools, built on open-source industrial automation libraries [8]. The fourth item operators are told to do is deploy cybersecurity measures that monitor industrial control systems for anomalies and possible malicious activity [9]. An anomaly detector tuned to spot malformed or unusual S7 traffic is being asked to flag a well-formed client using the same libraries an integrator would use. Of the four recommended controls, patching, isolation, access control and monitoring [9], the one that still works cleanly against the described adversary is the one that removes the device from the scan results in the first place.
The advisory also puts the loss in two ledgers at once: disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems [6]. CISA states plainly that this is not a theoretical risk but an active threat [5].
On attribution, the reporting is not internally consistent. Tom's Hardware describes the warning as concerning Iranian hackers, then states the agencies did not specify where the attacks could originate [10]. It also notes the advisory landed less than a month after water infrastructure in several states was hit by cyberattacks thought to have come from Iran [11]. For an operator with an S7 answering on a public address, the flag on the origin changes nothing about the work.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
According to a CISA advisory, threat actors are targeting Siemens S7-series programmable logic controllers, using publicly available information on these widely used devices to develop exploits that would enable remote access and control.
- [2]
The advisory was co-authored by CISA, the National Security Agency, the Federal Bureau of Investigation, the Department of Energy and the Environmental Protection Agency.
ReportedView cited source - [3]
CISA said in the warning: "The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected."
ReportedView cited source - [4]
CISA named the most targeted U.S. critical infrastructure sectors as Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities.
ReportedView cited source - [5]
CISA said of the activity: "This is not a theoretical risk - it is an active threat."
ReportedView cited source - [6]
CISA said exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.
ReportedView cited source
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- letsdatascience.com4d agoCISA and FBI Warn of Iranian PLC Attacks on Critical Infrastructure
