Five US federal agencies have warned that attackers are using AI-generated exploitation scripts to target internet-exposed Siemens S7 Series programmable logic controllers, according to The Register. The warning, issued Wednesday by the National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Department of Energy, and Environmental Protection Agency, described the activity as an “active threat.” The targets are industrial control devices used across critical infrastructure. The Register reports that the latest activity focuses on Siemens S7 Series PLCs in critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. The federal alert also noted that the controllers are used in the Defense Industrial Base and could be targeted there as well. The technical path described in the alert is notable because it combines widely available industrial automation libraries with AI coding tools. According to The Register, attackers are using snap7.dll/python-snap7 together with AI coding assistants to build custom tools that resemble operational technology monitoring software. Those tools are designed to interact with PLCs through the S7comm protocol. The Register says the agencies warned that the tools can provide read/write access to PLC memory, configuration data, and ladder logic programs — the software logic that runs industrial processes. The federal alert did not attribute the activity to a specific state or criminal group, according to The Register. But the report says Iranian cyber operatives are suspected of being behind recent attacks targeting PLCs at water and wastewater facilities across at least 12 states, including a late-July cyberattack that disrupted more than 30 community water systems in Minnesota. That attribution remains separate from the AI-assisted activity described in the new alert. The Register notes that experts previously told the outlet there was no indication the water-system hackers had used AI in those intrusions, though they expected attackers to add AI to their tooling for critical infrastructure operations. Cynthia Kaiser, senior vice president at Halcyon’s Ransomware Research Center and a former FBI cyber division deputy assistant director, told The Register that the advisory fits a broader pattern: state-sponsored adversaries using AI for discrete tasks such as code checks and scripting to move faster. Her assessment was that AI is increasing attacker efficiency rather than changing the target set by itself. For operators, the immediate issue is exposure. The agencies’ warning, as reported, is specifically about Siemens S7 Series PLCs that are reachable from the internet, not every deployment of the controller line. The risk described is also concrete: custom tools that can access configuration and logic on devices that sit inside operational technology environments. Who benefits: Defenders and asset owners benefit from a more specific threat model around internet-exposed Siemens S7 Series PLCs. Security teams can prioritize visibility into the exact controller family, protocol, and tooling described in the alert. Who's exposed: Organizations running internet-exposed Siemens S7 Series PLCs in the sectors named by the agencies are the clearest exposed group. The alert also flags potential exposure in the Defense Industrial Base because the same PLC series is used there.