US Agencies Warn of AI Exploits Targeting Siemens PLCs
US agencies warn that attackers are using AI to write exploit scripts targeting Siemens PLCs, drastically lowering the technical barrier to hacking critical infrastructure.

A coalition of United States government agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI), has issued a joint advisory warning that threat actors are actively leveraging artificial intelligence to develop exploit scripts. These malicious tools specifically target Siemens S7 programmable logic controllers (PLCs), which are widely used to manage physical machinery across various industrial sectors.
According to the federal agencies, the integration of AI into the cyberweapon development process represents a significant shift in adversary capabilities. By using generative AI models, attackers can significantly lower the technical barrier and accelerate the timeline for creating functional code to compromise industrial control systems (ICS). This democratization of cyber warfare allows less skilled actors to quickly gather public vulnerability data, locate internet-exposed PLCs, and deploy automated scripts to compromise them.
The advisory classifies this activity as an active threat, with critical infrastructure sectors such as energy, water, chemical processing, and manufacturing facing the highest risk. Security practitioners are urged to ensure that PLCs and other operational technology (OT) systems are not directly exposed to the public internet.
While the threat is growing, current AI models still face limitations when operating autonomously. The agencies highlighted recent simulations conducted by the United Kingdom's AI Safety Institute, which revealed that AI models failed to successfully compromise OT systems on their own. Interestingly, the models did not fail because of the industrial devices themselves, but rather because they were unable to navigate the enterprise IT security systems protecting those devices. For security practitioners, this underscores the vital importance of maintaining robust perimeter defenses and strict IT-OT network segmentation to block automated attacks before they reach physical controllers.
This is our own summary of reporting by The Decoder



