Circuit Wire — a daily news update from the Circuit.

Five US federal agencies warned on Wednesday, August 19, that attackers are using AI-generated scripts to break into internet-exposed Siemens S7 Series programmable logic controllers at water, energy and manufacturing sites across the country. The joint advisory came from the National Security Agency, CISA, the FBI, the Department of Energy and the Environmental Protection Agency. The agencies called the activity an active threat rather than a theoretical risk.

The attackers pair open source industrial automation libraries, specifically snap7.dll and python-snap7, with AI coding assistants. That combination lets them build custom tools that look like ordinary operational technology monitoring software. The tools give read and write access to a controller's memory, configuration data and ladder logic programs over the S7comm protocol, The Register reported.

Targets are found using internet scanning services such as Censys and ZoomEye. The agencies said attackers look for poorly protected controllers running outdated software or still using default passwords. Sectors named in the advisory include critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. The advisory also warned that Siemens S7 controllers are widely used across the Defense Industrial Base and could be targeted there.

The agencies described the use of AI as an evolution in attacker capability. It cuts the technical knowledge and the time needed to produce working industrial control system tools, and it helps attackers adapt when defenders change something. The advisory does not name a government or a criminal group. It describes the activity as persistent reconnaissance intended to build capability for later operational effects, The Record reported.

In July, federal agencies said Iran-affiliated hackers were targeting controllers made by Siemens, Schneider Electric, Rockwell Automation and Allen-Bradley. Dozens of water utilities in at least 12 states reported intrusions over recent weeks, including more than 30 community water systems in Minnesota in late July. Some of those facilities switched to manual operation while they recovered.

The agencies told owners and operators to inventory every Siemens S7 controller, apply available patches, and confirm that none are reachable from the internet. They also advised watching for unusual S7comm behavior, including connections from non-engineering workstations, odd data block access patterns and write operations outside change windows. Sequential scanning on port 102 and repeated connection attempts with varying parameters can both signal reconnaissance.

"The barrier that used to be expertise is now time, and time is getting shorter," said Brian Proctor, chief executive of operational technology testing firm Frenos.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.