A joint US government advisory says hackers are using AI to build exploit tools aimed at critical infrastructure.
The advisory, issued by the NSA, CISA, FBI, DOE, and EPA, warns of an active threat to Siemens S7 programmable logic controllers. Threat actors are reportedly using AI-generated exploitation scripts, disguised as legitimate monitoring tools and built on open-source automation libraries, to read and write data on these controllers - work the agencies say looks like reconnaissance or pre-positioning for future attacks. The sectors named include critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. Cynthia Kaiser, a former FBI Cyber Division official, told The Register the activity resembles a pattern linked to Iran-affiliated actors previously tied to water-system breaches.
The real story here isn't the PLCs, it's the tooling. AI doesn't hand attackers new access, but it erases the specialized ICS expertise that used to bottleneck attacks like this, letting more actors move faster against systems that run water treatment plants and power grids. That's a bigger structural risk than any single vulnerability.
Government advisories are usually hedged. This one says the threat is active, not theoretical, and tells operators to treat it with urgency - a tone alone worth noticing.