U.S. agencies report cybercriminals used AI-generated code to crack Siemens PLCs | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


If cyberattacks (or potential ones) on plant controllers sound familiar, contributor Trae Mazza, a senior security engineer at RMC Global, last fall detailed exclusively for Smart Industry two hidden gaps in Siemens’ RuggedCom ROXOS II multiservice platforms that were identified and patched, heading off possible penetration by threat actors.

And our Sarah Mattalian has been doing on-point reporting since 2025 turned to 2026 on numerous cybersecurity subjects, including an MxD workshop in Chicago where industrial stakeholders simulated ransomware attack scenarios (the kind manufacturers face most often) and observed strategies to implement before, during, and after data is stolen or systems are manipulated.

And, speaking of the current subject of AI-powered attacks, she followed a Darktrace report in June that also exposed more facets of the growing cybersecurity risks manufacturers face from AI.

More particulars of PLC cyberattacks and some defenses

According to BleepingComputer via IndustryWeek‘s Dennis Scimeca, the custom AI-generated attack tools work by continuously monitoring PLCs, looking for vulnerabilities and possibly preparing threat actors to launch the attacks that could steal data, shut down equipment on the floor, or otherwise interrupt normal operations.

See also: How one form of AI is hypercharging cyberattacks on manufacturing

According to CISA, top mitigation strategies include inventorying all Siemens PLCs, applying security patches, making sure PLCs cannot access the internet, and monitoring for unauthorized activity or anomalies that may indicate compromised security.

Kiteworks’ Frank Balonis added: “What’s notable here isn’t that Siemens PLCs are being targeted; that’s been happening for years. It’s how fast attackers can now build custom reconnaissance tools using AI-generated code. That compresses the timeline between ‘someone scanned our network’ and ‘someone has a working exploit,’ which means organizations can no longer treat OT monitoring as a quarterly checklist item.”

See also: Smart Industry cybersecurity e-book

This news about the Siemens PLC intrusion and the resulting multi-agency advisory follows closely behind cyberattacks on GE, Philips, Shell, and 40 other companies that reportedly targeted a specific vulnerability in software commonly used by manufacturers, product lifecycle management tools, or PLMs, these specifically from vendor PTC.

It also comes soon after coordinated incursions in late July, on other programmable logic controllers, that disrupted water utilities in 30-plus Minnesota communities. Iranian cyberattackers are suspected of being responsible for those break-ins.

——————————————————-


Click Here For The Original Source.