Ahmet Ö.
Corporate
- Thread Author
- #1
🚨 AI-Powered Cyberattacks Are Real!
AI-powered cyberattacks targeting manufacturing and critical infrastructure are now a reality, and warnings about this have been issued for a long time. Recent developments have once again proven how serious this threat is.
💥 Siemens PLCs Targeted
The U.S. National Security Agency (NSA), FBI, Department of Energy, Environmental Protection Agency, and Cybersecurity and Infrastructure Security Agency (CISA) issued a joint statement announcing that cyber attackers have used or are using AI-generated code to target Siemens S7 Series programmable logic controllers (PLCs).
- Why are PLCs Important? PLCs are critical facility equipment that automate machine and factory processes by monitoring inputs from sensors, executing custom user logic, and controlling physical outputs such as motors, valves, and lights. Siemens PLCs are among the most widely used in manufacturing and other sectors.
- Targeted Models: S7-200, S7-300, S7-400, S7-1200, and S7-1500 models are among those targeted by the attacks.
🔍 Security Experts Warn
Frank Balonis, field chief information security officer at Kiteworks, emphasized the seriousness of the situation, stating:
- "The fundamental failure is rarely the PLC itself. It's internet-exposed devices, poor authentication, and a lack of clear inventory of what's actually exposed."
- "Until organizations can confidently answer 'who and what can reach this system,' simply patching won't close this vulnerability."
🛠️ Attack Techniques and Defense Strategies
According to the multi-agency alert, unidentified attackers are using AI to develop Python exploit scripts that utilize the "snap7.dll" and "python-snap7" libraries to communicate with Siemens S7 PLC devices.
According to CISA, key mitigation strategies include:
- Inventorying all Siemens PLCs.
- Applying security patches.
- Ensuring PLCs cannot access the internet.
- Monitoring for anomalies that may indicate unauthorized activity or a security breach.
Frank Balonis highlighted the speed of AI-powered attacks, saying, "It's remarkable how quickly attackers can now create custom reconnaissance tools using AI-generated code. This compresses the timeline between 'someone scanned our network' and 'someone has a working exploit,' meaning organizations can no longer treat OT monitoring as a quarterly checklist item."
📢 Siemens Statement
Siemens maintains open communication about targeted industrial control systems and publishes its own bulletins alongside relevant government advisories. The company recently updated its year-old warning about cyber threats to its S7 Series PLCs, adding more information and mitigation strategies.
Siemens stated that CISA's warning did not identify new vulnerabilities in S7 Series PLCs but rather that threat actors are using new techniques to exploit potential misconfigurations or insecure operations. A company spokesperson confirmed that "new techniques" referred, at least in part, to recent attacks using AI-generated code.
CISA emphasized that AI represents an evolution in threat actors' capabilities, significantly reducing the technical expertise and time required to develop working ICS exploit scripts and malicious tools. It also noted that AI allows adversaries to quickly leverage additional attack vectors and adapt to defensive measures.


















