Find notable cyber news and cases, enriched with sources, timelines, and signals.

Siemens S7 PLC AI-assisted exploitation campaign targeting critical infrastructure

Campaign
First reported
Last updated
Happening score
H score 17
3 unique sources, 3 articles

Summary

Hide ▲

The U.S. government warned of an active threat using AI-generated exploit scripts against Siemens S7 Series PLCs in U.S. critical infrastructure. The campaign uses Censys and ZoomEye to find internet-exposed devices, then applies AI-generated Python scripts built with snap7.dll and python-snap7 over S7comm to read and write PLC memory, configuration data, and ladder logic. U.S. agencies said the activity targets Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, Commercial Facilities, and the Defense Industrial Base. The devices singled out include S7-200, S7-300, S7-400, S7-1200, and S7-1500 series, and the described outcomes include reconnaissance, credential access, denial of service, disruption, equipment damage, and downtime.

Related Happenings

QTFY US government and critical infrastructure targeting campaign

Campaign
H score40 First: 27.08.2026 15:00 Last: 27.08.2026 15:00 Sources 1

About this happening: The QTFY campaign is a Chinese targeting activity against U.S. government and critical infrastructure systems, with reported focus on defense industrial base,...

FBI urgent mitigation advisory for QTFY

Advisory/Mitigation
H score39 First: 27.08.2026 15:00 Last: 27.08.2026 15:00 Sources 1

About this happening: The FBI urged US government and critical infrastructure entities to take urgent action against QTFY. The advisory, issued with the NSA and Cyber National Mis...

FBI disrupts quartermaster infrastructure for Chinese espionage

Law Enforcement
H score33 First: 26.08.2026 17:17 Last: 26.08.2026 17:17 Sources 1

About this happening: FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...

CISA AA26-237A red team assessment results

Public Sector Action
H score28 First: 26.08.2026 16:07 Last: 26.08.2026 16:07 Sources 1

About this happening: CISA released AA26-237A, publishing the results of two simultaneous red team assessments against two critical infrastructure organizations and exposing major gaps in d...

Iranian threat actors' Water and Wastewater Systems PLC targeting campaign

Campaign
H score33 First: 26.08.2026 14:29 Last: 26.08.2026 14:29 Sources 1

About this happening: A campaign tied to Iranian threat actors targeted over 100 internet-exposed water systems in July 2026, signaling a broad operation against critical OT environment...

Timeline

  1. 19.08.2026 20:50 4 articles · 13d ago

    U.S. agencies warn of AI-generated scripts exploiting Siemens S7 PLCs

    Initial Disclosure

    NSA, CISA, FBI, the Department of Energy, and the Environmental Protection Agency issued a joint advisory on Wednesday about an active threat to Siemens S7 Series programmable logic controllers in U.S. critical infrastructure. Threat actors are using Censys and ZoomEye to find exposed devices, then using AI-generated Python exploitation scripts built with snap7.dll and python-snap7 to communicate over S7comm, read and write PLC memory, configuration data, and ladder logic, and target sectors including Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, Commercial Facilities, and the Defense Industrial Base.

    Show sources