U.S. Federal Agencies Warn of AI-Generated Code Used in Critical Infrastructure Attacks
Five U.S. federal agencies, including the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA), have issued a joint alert regarding an active threat to critical infrastructure. Attackers are reportedly using AI-generated exploitation scripts to breach internet-exposed Siemens S7 Series programmable logic controllers (PLCs) in various sectors such as water, manufacturing, and energy. These attackers leverage open-source industrial automation libraries, specifically snap7.dll/python-snap7, in conjunction with AI coding assistants to create custom tools. These tools mimic operational technology (OT) monitoring software, granting read/write access to PLC memory, configuration data, and ladder logic programs via the S7comm protocol. While the alert does not attribute the threats to a specific group, Iranian cyber operatives are suspected of being behind recent attacks ...