What happened
Five federal agencies — the NSA, CISA, the FBI, the Department of Energy, and the EPA — released a joint advisory on August 20 warning that attackers are actively targeting Siemens S7 series programmable logic controllers, the small industrial computers that run equipment in water plants, factories, and building systems. According to the advisory, threat actors are using AI to generate Python scripts built on the open-source snap7 libraries and disguising them as legitimate monitoring tools. The scripts can read and write controller memory, configuration data, and the ladder logic programs that control physical equipment. Attackers locate targets using internet scanning services that flag exposed controllers running outdated software. The agencies stress this is an active threat, not a theoretical risk, and list water and wastewater, energy, critical manufacturing, chemical, food and agriculture, and commercial facilities among the targeted sectors. The warning lands after cyberattacks on water utilities were reported across at least a dozen states this month.
Why it matters for your business
Plenty of small and midsize operations run industrial controllers without thinking of themselves as critical infrastructure — commercial buildings, food producers, machine shops, property managers with automated HVAC and pump systems. Many DC, Maryland, and Virginia businesses also depend on the water and utility systems being probed. The advisory's core finding is blunt: equipment reachable from the internet is being found by automated scanning, and AI has lowered the skill required to attack it once found.
What to do about it
- Inventory any PLCs or building-automation controllers your business operates, and confirm none are directly reachable from the internet.
- Apply vendor firmware updates and replace default credentials.
- Put controllers behind a firewall or VPN, and ask whoever manages your facilities systems to monitor for unfamiliar connections.
