NEWS

Five US Agencies Warn AI Is Writing Infrastructure Exploits

An industrial control panel with a warning overlay, representing AI-generated exploits targeting power and water infrastructure
Five US agencies warned that attackers are using AI to write exploits for the controllers that run power, water, and manufacturing plants. Source: Quartz
TLDR

Five agencies say AI is now writing working exploits for plant controllers

The United States issued one of its bluntest AI security warnings to date on Wednesday. In a joint advisory numbered AA26-231A, the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency said attackers are using AI to write exploit scripts aimed at Siemens S7 programmable logic controllers, the small computers that open valves, run pumps, and control machinery across the country's physical infrastructure.

The technique is not exotic, which is the point. Attackers pair widely available open-source automation libraries, such as python-snap7, with AI scripting to build tools that impersonate legitimate monitoring software and gain read and write access to a controller's memory and ladder logic. What once required specialist industrial-control expertise can now be assembled by less skilled actors with a capable model.

This is not a theoretical risk. It is an active threat.
Joint advisory AA26-231A, issued by the NSA, CISA, FBI, Department of Energy, and EPA

The agencies assessed that intruders are already inside the reconnaissance stage, using read access to understand target environments and prepare for write operations that could change how a plant physically operates.

What the advisory flags
Affected devicesevery S7 family, including the S7-200, S7-300, S7-400, S7-1200, and S7-1500, plus F-series safety controllers
Sectors namedcritical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities
Campaign stagepersistent reconnaissance and capability development, positioning for future write access
Source: Joint advisory AA26-231A, NSA, CISA, FBI, DOE, and EPA, August 20, 2026.

Why AI-written exploits change the infrastructure threat

The danger here is not a new vulnerability. It is a collapse in the skill and time an attack requires. Industrial control systems have long been protected as much by their obscurity as by their defenses, because writing code that speaks the S7comm protocol and manipulates ladder logic demanded rare knowledge. AI removes that barrier, turning a narrow specialty into a prompt and pushing the reconnaissance that precedes an attack from weeks of manual effort down to hours.

That shift favors the attacker in a domain where the defender was already behind. Many of the exposed controllers were installed years ago, sit directly on the internet, and cannot be patched without shutting down the plant they run. The agencies' recommended fixes, inventory every device, take controllers off the public internet, harden credentials, and run compromise assessments, are basic hygiene precisely because the systems were never built to face automated, intelligent attackers. The advisory does not describe a single breach so much as the moment the cost of attacking physical infrastructure fell far enough that the government felt compelled to say so out loud.

Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.