Next upHack for Humanity: San Francisco (powered by Google Gemini)
News

CISA warns hackers are using AI coding assistants to exploit Siemens S7 controllers

Five U.S. agencies warned on August 19 that threat actors are using AI coding assistants to build custom scripts exploiting internet-exposed Siemens S7 industrial controllers.

D
Aug 19, 2026 · 1 min read

Five U.S. agencies warned on August 19, 2026, that threat actors are using AI coding assistants to generate custom scripts exploiting internet-exposed Siemens S7 programmable logic controllers. The alert was led by the Cybersecurity and Infrastructure Security Agency, or CISA, and the joint advisory AA26-231A describes an active exploitation campaign.

The NSA, FBI, Department of Energy and Environmental Protection Agency co-signed the alert. It is one of the clearest official accounts yet of attackers using AI code generation against operational technology, the controllers that run physical processes in factories, power plants and water utilities.

According to the advisory, attackers build their scripts on open-source industrial-automation libraries such as python-snap7 to talk to the controllers over the S7comm protocol, then disguise the tools as legitimate monitoring software. They first locate exposed, poorly protected controllers using internet-scanning services such as Censys and ZoomEye, then rely on AI-assisted scripts for exploitation, lateral movement and evasion.

Affected sectors include critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and Defense Industrial Base facilities. The agencies’ top recommendation is blunt: keep Siemens S7 controllers off the public internet.

The warning follows attacks in late July 2026 that disrupted more than 30 community water systems in Minnesota, with targeting reported across at least 12 states. Those intrusions have been linked to suspected Iranian operatives, though the advisory itself does not formally attribute them.

AI did not create a new vulnerability here; it lowered the skill and time needed to weaponize known weaknesses in exposed controllers. The recommended fix, disconnecting the devices from the public internet, predates the campaign.

More news