Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

    August 19, 2026

    Sakura Internet hack exposes data of up to 1.36 million accounts

    August 19, 2026

    Rogue ransomware affiliate poses as recovery firm to steal payments

    August 19, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»US warns of AI-powered attacks on Siemens PLCs in critical infrastructure
    News

    US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

    adminBy adminAugust 19, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Siemens S7-1500

    U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure.

    PLCs are industrial computers used to automate and control machinery and physical processes in factories and other critical infrastructure.

    The NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency issued the joint advisory Wednesday, saying the attacks are ongoing.

    image

    “This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs),” reads the advisory.

    “However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems.”

    The critical infrastructure sectors most targeted include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. The agencies also note that Siemens S7 PLCs are used in the Defense Industrial Base, which could also be targeted.

    Threat actors are using internet scanning services, including Censys and ZoomEye, to find exposed Siemens PLCs and exploit critical and high-severity vulnerabilities, outdated software, and weak authentication.

    The advisory says the attackers are using artificial intelligence to develop Python exploitation scripts that use the ‘snap7.dll’ and ‘python-snap7’ libraries to communicate with Siemens S7 PLC devices.

    These custom tools are disguised as legitimate OT monitoring software and can provide read and write access to PLC memory, configuration data, and ladder logic programs over the S7comm protocol.

    The agencies say the activity appears focused on persistent reconnaissance, potentially preparing attackers for disruption to critical infrastructure, including stealing sensitive data, damaging equipment, causing extended downtime, or leading to safety incidents.

    The actively targeted devices include Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 PLCs.

    Organizations are urged to inventory Siemens S7 PLCs, install the latest security updates, block internet access, strengthen access controls, and monitor for unusual activity targeting these devices.

    Today’s advisory follows a recent increase in attacks targeting exposed PLCs at U.S. critical infrastructure organizations.

    In July, hackers targeted more than 30 Minnesota water utilities, causing equipment malfunctions and forcing some facilities to switch to manual operations temporarily.

    CISA later warned of an increase in attacks against internet-exposed PLCs used by water and wastewater utilities.

    Earlier in April, U.S. agencies also warned that Iranian-linked hackers were targeting internet-exposed Rockwell Automation/Allen-Bradley PLCs, causing disruptions and financial loss across multiple critical infrastructure sectors.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSakura Internet hack exposes data of up to 1.36 million accounts
    admin
    • Website

    Related Posts

    News

    Sakura Internet hack exposes data of up to 1.36 million accounts

    August 19, 2026
    News

    Rogue ransomware affiliate poses as recovery firm to steal payments

    August 19, 2026
    News

    OpenAI confirms ChatGPT is down as logins and signups fail

    August 19, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

    August 19, 2026

    Sakura Internet hack exposes data of up to 1.36 million accounts

    August 19, 2026

    Rogue ransomware affiliate poses as recovery firm to steal payments

    August 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.