US federal cybersecurity agencies issue a joint advisory warning that threat actors are using AI-generated exploit scripts to attack Siemens S7 Series programmable logic controllers (PLCs) that are exposed to the internet. The agencies say the targeted PLCs are used to operate industrial processes in critical infrastructure.

The advisory is issued jointly by the NSA, CISA, FBI, the Department of Energy, and the Environmental Protection Agency. Across sectors, Siemens S7 PLCs are described as controlling functions such as opening valves, running pumps, and managing machinery in facilities including water, energy, and manufacturing, as well as other industrial environments.

Outlets covering the advisory focus on different aspects: some emphasize the AI element in how exploit scripts are being generated, while others stress the Siemens model family and the risk to internet-exposed industrial control systems. All sources report that the warning is meant to prompt ICS operators to assess exposure and strengthen defenses against PLC compromise.