Bottom line: Exposed Siemens S7 Series PLCs are vulnerable to AI-generated exploits that can be used to gain unauthorized access to critical infrastructure.
What's happening: The U.S. Department of Homeland Security (DHS) and the Department of Energy (DOE), along with the National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure Security Agency (CISA), have released a joint advisory warning of this threat. The advisory notes that threat actors have been using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs in sectors such as energy, water, and transportation. The affected systems are those with outdated firmware or unpatched vulnerabilities, including those using the Siemens SIMATIC WinCC SCADA system, which has an identified CVE-2021-6855 vulnerability.
What to do: Security leaders should immediately check for updates on Siemens S7 Series PLC firmware and patch any identified vulnerabilities. They should also conduct a risk assessment to determine the scope of the affected systems and implement additional security controls to prevent unauthorized access. CISA recommends using the NIST Cybersecurity Framework to guide the response effort.