Multiple security agencies in the United States are warning about an "active cyber threat" from foreign hackers using AI tools to infiltrate American infrastructure, threatening the water supply. In a report published Wednesday by Cybersecurity and Infrastructure Security Agency (CISA), the agency warned that owners and operators of control systems that use Siemens S7 Series programmable logic controllers (PLCs) are vulnerable to attack. "All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems.," the advisory warned, adding, "The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape." Newsweek reached out to Siemens by email Wednesday for comment.
"The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools," the advisory said, noting, that "the actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected. The infrastructure being targeted includes energy, water, wastewater, chemical, and commercial facilities, according to the advisory. "This is not a theoretical risk—it is an active threat.
Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems," the advisory read. This is a breaking news story.
Extract — continue reading at the source.