critical infrastructure6 articles
AI-Assisted Hacking Puts Siemens PLCs in US Critical Infrastructure Squarely in the Crosshairs
US government agencies, including the NSA, CISA, FBI, EPA, and DOE, have issued a joint advisory warning that unidentified hackers are using AI to develop exploitation scripts targeting Siemens PLCs across critical infrastructure sectors such as energy, water, and manufacturing. The attackers combine AI-generated tools with open-source industrial automation libraries to manipulate PLC memory, configuration data, and ladder logic, while also conducting persistent reconnaissance that suggests preparation for future disruptive attacks. Agencies are urging organizations to apply the latest patches, restrict internet exposure of PLCs, and implement strong access controls and ICS monitoring solutions.
AI-Assisted PLC Attacks on Critical Infrastructure Are No Longer Hypothetical
Five US federal agencies have issued a joint alert warning that attackers are actively using AI-generated scripts and open-source industrial libraries to hack internet-exposed Siemens S7 Series programmable logic controllers (PLCs) across critical infrastructure sectors including water, energy, and manufacturing. Iran-affiliated actors are suspected to be behind the campaign, which has already disrupted water systems in at least 12 US states. Authorities warn that AI is lowering the technical barrier for such attacks and urge critical infrastructure operators to immediately patch systems, remove PLCs from internet exposure, and monitor for anomalous network behaviour.
AI-Powered Attacks on Critical Infrastructure Are No Longer a Thought Experiment
Autonomous AI-powered cyberattacks on critical infrastructure are now a reality, with suspected Chinese operators using AI agents in July to breach Taiwanese government systems and energy companies across 12 attack waves. Security experts and officials, including the FBI, warn that AI tools — particularly freely available commodity models — are lowering the barrier for adversaries to exploit decades of accumulated technical debt in critical systems like power grids, water utilities, and financial networks. Offensive AI capabilities are outpacing defensive ones, with experts cautioning that weaponized autonomous AI poses a clear and escalating danger to national security worldwide.
AI Agents Ran a Near-Autonomous Cyberattack on Taiwan's Nuclear Safety Agency
Suspected Chinese cyber operatives used AI agents built on open-source tools to launch a "near-autonomous" attack on Taiwanese government systems in early July, compromising 85 user accounts and extracting over 2,500 personnel records across 12 attack waves in just four days. The AI framework autonomously mapped government infrastructure, bypassed authentication, solved CAPTCHAs, and then pivoted to target supply-chain vendors, a nuclear safety agency, and at least seven energy companies. The attack highlights the growing real-world threat of fully automated, AI-driven cyberattacks, with the agents capable of self-correcting errors and independently researching new vulnerabilities to exploit.
PLCs on the public internet are an open goal for attackers, says ex-NSA chief
Retired General and former NSA chief Paul Nakasone has warned that water system controllers should not be connected to the internet, following suspected Iranian cyberattacks on water facilities across at least 12 US states. Speaking at DEF CON, he highlighted the enormous attack surface posed by around 50,000 underfunded and understaffed water municipalities, calling for higher cybersecurity standards and a collaborative defence approach. While neither the FBI nor the Trump administration has officially attributed the attacks to Iran, security researchers and Nakasone himself consider Iranian involvement highly likely given the country's history and demonstrated capability in targeting such infrastructure.
Iranian Hackers Suspected Behind Wave of Cyberattacks Hitting Minnesota Water Systems
Cyberattacks targeted over 30 water systems across Minnesota on Sunday and Monday, with authorities including the FBI investigating the source amid warnings that Iranian hackers have been actively targeting water and critical infrastructure systems. While some communities experienced brief disruptions, such as the city of Braham temporarily asking residents to conserve water, there were no reported impacts on water quality or service for residents. Investigators have noted similarities across the incidents in timing and technology targeted, but have not yet confirmed whether a single culprit was responsible or publicly attributed the attacks to Iran.