AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure

AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure

First seen 19 Aug 2026, 22:48 UTC CnbcTherecord.MediaCybersecuritydiveTheregisterFeeds2.Feedburner+24 75.9

Article Content

Browse articles
ThreatCluster

On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including water, energy, and manufacturing. The advisory, co-signed by the NSA, CISA, FBI, DOE, and EPA, highlights that these attacks exploit vulnerabilities in PLCs that are exposed to the internet or poorly segmented. Attackers utilize open-source libraries like snap7 and python-snap7 to create custom tools that mimic legitimate operational technology software, allowing them to gain unauthorized access to PLC memory and configuration data. This represents a significant evolution in threat capabilities, as AI reduces the technical expertise required to develop effective exploits. The advisory also notes that these attacks could lead to severe disruptions in critical services and safety incidents. Recent incidents have been linked to Iranian cyber operatives, raising concerns about the geopolitical implications of these attacks.

Key Points: • AI-generated scripts are actively targeting Siemens S7 Series PLCs across critical sectors. • Threat actors exploit vulnerabilities in internet-exposed PLCs using open-source libraries. • Recent attacks are suspected to be linked to Iranian cyber operatives.

Timeline

2023-03-07
CVE-2022-41328 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-06-13
CVE-2023-20867 published
A vulnerability affecting Siemens PLCs was published, later added to CISA KEV for active exploitation.
N/A
2023-06-23
CVE-2023-20867 added to CISA KEV
CISA confirmed active exploitation of CVE-2023-20867, a critical vulnerability in Siemens PLCs.
N/A
2023-10-25
CVE-2023-34048 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-11
CVE-2026-35273 published
A new vulnerability affecting Siemens PLCs was published, indicating potential for exploitation.
N/A
2026-06-12
CVE-2026-35273 added to CISA KEV
CISA added CVE-2026-35273 to the KEV list, indicating it is actively being exploited.
N/A
2026-08-19
Joint advisory issued by U.S. agencies
Five U.S. agencies warned of AI-generated attacks on Siemens S7 PLCs, marking an active threat to critical infrastructure.
Techtimes
Recent
Increased attacks linked to Iranian operatives
Recent cyber incidents targeting water systems have been linked to Iranian-affiliated hackers, raising security concerns.
The Register