Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Hong Kong Tiananmen activists found guilty of national security charges | Hong Kong Protests News

    August 21, 2026

    Sánchez has one year until Spain’s election deadline. The odds are against him. – POLITICO

    August 21, 2026

    French becoming more effective in stopping small boat crossings, UK says

    August 21, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Hong Kong Tiananmen activists found guilty of national security charges | Hong Kong Protests News
    • Sánchez has one year until Spain’s election deadline. The odds are against him. – POLITICO
    • French becoming more effective in stopping small boat crossings, UK says
    • Trump Officials Impose More Sanctions to Pressure Cuba
    • Riot is ending development on its League of Legends fighting game
    • New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
    • MANTRA Token Plunges to All-Time Low During Chain Outage
    • I’ll admit it: I’ve cycled through red lights. But Britain’s traffic laws are to blame, not me | Simon Jenkins
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 21
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 21, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The U.S. government on Wednesday warned of an “active threat” targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts.

    The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That said, the ongoing PLC targeting activity is assessed to be broader in scope than Siemens PLCs.

    “The actors leverage internet scanning services like Censys and ZoomEye to identify internet-exposed PLCs running outdated software or that are otherwise poorly protected,” according to the advisory published by the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA).

    Targets of the activity include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. The agencies did not attribute the attacks to a known threat actor or group.

    The exploitation of poorly secured PLCs could result in disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, and compliance violations, not to mention have cascading impacts across interconnected systems.

    Cybersecurity

    The activity has been found to have singled out the following Siemens PLC models –

    • S7-200 Series (all CPU variants)
    • S7-300 Series (all CPU variants including 314, 315, 317 models)
    • S7-400 Series (all CPU variants)
    • S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, 1217C variants)
    • S7-1500 Series (all CPU variants, including F-series safety controllers)

    “Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives,” the agencies said. “If these PLCs are exposed to the internet or insufficiently segmented, then threat actors can exploit various critical and high severity known vulnerabilities in these PLCs.”

    Among the tools deployed by the threat actor is a custom Python script that incorporates open-source industrial automation libraries like “snap7.dll” or “python-snap7,” thereby mimicking legitimate monitoring utilities that provide read/write access to PLC memory, configuration data, and ladder logic programs via the S7comm protocol.

    The use of AI to generate exploitation scripts and rapidly iterate them marks an “evolution” in offensive capabilities, lowering technical barriers to Industrial Control System (ICS) attacks, as well as the technical expertise and time required to develop them.

    To counter the threat, the authoring agencies are urging operational technology (OT) system owners and operators using Siemens S7 Series and other PLC devices to ensure they are running the latest versions, isolated from the internet wherever possible, have strong access controls, and employ security tooling to monitor ICS environments for signs of anomalous or malicious activity.

    “The combination of known vulnerabilities, accessible exploitation libraries, and AI-assisted development creates a high-probability attack scenario against inadequately protected PLC installations,” the agencies said.

    Multi-Agent Autonomous Attack Targets Taiwan

    The development comes as threat actors are increasingly harnessing the power of AI to carry out cyber attacks. In a report published last week, Israeli cybersecurity company Dream detailed a near-autonomous attack targeting government entities in Asia. Although the research did not disclose which government was attacked, The Financial Times and Reuters said Taiwan was the target.

    “The investigation found clear indications that the attacks originated overseas and involved a hybrid approach in which hackers combined conventional operations with AI agents such as OpenClaw,” Taiwan’s Ministry of Digital Affairs said.

    The activity, observed between July 1 and 4, 2026, across 12 attack waves and likely undertaken by a Chinese-language operator, leverages an AI-powered framework built on the Hermes and OpenClaw agents to deploy up to eight lettered sub-agents in parallel to automate various aspects of the intrusion.

    This includes performing reconnaissance, cracking government employee credentials, exfiltrating data, discovering a signature validation flaw in a personal authentication service, and installing persistent backdoors on government web applications. The eight sub-agents, although run concurrently, target different attack surfaces –

    • A – SSO exploitation and credential attacks
    • B – JWT bypass testing and CAPTCHA brute-force
    • C – Reconnaissance across multiple government portals
    • D – API scanning and admin panel bypass
    • E – CVE research and vulnerability chain testing
    • F – Supply chain target assessment
    • I – Password spraying with CAPTCHA bypass using Tesseract OCR
    • Q – Deep API endpoint exploitation

    For initial access, the framework is said to have found hidden API endpoints that returned a valid authenticated session irrespective of the request body. These endpoints were then used to harvest employee usernames and then attack one of the government portals to crack 85 accounts using password spraying techniques.

    Cybersecurity

    In all, the illicit access allowed the attacker to exfiltrate more than 2,564 personnel records, a database of all department system users, seven SSO client secrets, six internal database credentials across MSSQL, Oracle, and Sybase, and internal network IP ranges.

    “The attacker didn’t stop at primary targets,” Dream explained. “It expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies – scanning them all in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities.”

    The framework also implements a learning engine to look up vulnerability databases, GitHub repositories, and security research to zero in on techniques that could be adapted to the target infrastructure.

    “In roughly four days, the agentic attacker produced 1,395 files, 85 cracked credentials, thousands of exfiltrated personnel records, and gained a persistent foothold inside state infrastructure,” Dream said. “It spells out one thing loudly – the cost of running a competent attack has collapsed, but the cost of defending against one has not.”

    AIGenerated critical exploit infrastructure PLCs Scripts Siemens Target U.S
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

    ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

    Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

    U.S. Bond Crisis Highlights Deeper Fiscal Rot

    Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

    New CUSTODY Framework Constrains AI Agents Inside the Network

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Hong Kong Tiananmen activists found guilty of national security charges | Hong Kong Protests News

    August 21, 2026

    Sánchez has one year until Spain’s election deadline. The odds are against him. – POLITICO

    August 21, 2026

    French becoming more effective in stopping small boat crossings, UK says

    August 21, 2026

    Trump Officials Impose More Sanctions to Pressure Cuba

    August 21, 2026
    Latest Posts

    New Dysphoria DDoS botnet spreads to 200k devices worldwide

    July 28, 2026

    OpenAI’s biggest threat may just be open AI

    July 28, 2026

    6 Takeaways From Michigan’s Senate Debate Between Abdul El-Sayed and Haley Stevens

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Hong Kong Tiananmen activists found guilty of national security charges | Hong Kong Protests News

    August 21, 2026

    Sánchez has one year until Spain’s election deadline. The odds are against him. – POLITICO

    August 21, 2026

    French becoming more effective in stopping small boat crossings, UK says

    August 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.