It's happening! Attackers are using AI to build exploit scripts targeting Siemens S7 programmable logic controllers, according to a joint advisory from the NSA, CISA, FBI, and other U.S. agencies. AI is drastically cutting both the skill level and time needed to attack industrial control systems (ICS), the agencies say.

Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information. If PLCs are exposed to the Internet, they are at high risk for exploitation.

Joint Cybersecurity Advisory

Affected sectors include energy, water, chemical, and manufacturing. The agencies classify this as an active threat. The full advisory with recommended mitigations is available as a PDF. In simulations by the UK's AI Safety Institute, models have so far failed to hack operational technology (OT) systems on their own. They didn't fail at the devices themselves, though, but got stuck on the IT systems in front of them.