News

Five US agencies warn of AI-built exploits probing Siemens S7 PLCs: advisory AA26-231A

NSA, CISA, FBI, DOE and EPA issued AA26-231A on active targeting of Siemens S7 PLCs over S7comm on TCP port 102, using snap7 tooling and AI-generated Python scripts. No victim count, no named group. The one control to check today is whether port 102 is internet-reachable.

Five US agencies warn of AI-built exploits probing Siemens S7 PLCs: advisory AA26-231A

Five US agencies (NSA, CISA, FBI, the Department of Energy and the Environmental Protection Agency) issued a joint advisory, AA26-231A, on 19 August 2026, titled "Defending Against an Active Threat to Siemens S7 Series PLCs." It describes active targeting of programmable logic controllers on the factory and utility floor, not a theoretical scenario. BleepingComputer and The Record both carried it the same day.

The instrument: S7comm on TCP port 102

Here is the fact to act on before any of the framing. The activity rides S7comm, the Siemens control protocol, over TCP port 102, using the snap7.dll and python-snap7 libraries to reach the controllers. That is the single perimeter fact in this advisory, and it is not in the "US warns of AI attacks" headline. If port 102 is reachable from an untrusted network, you are already inside the exposed set the advisory is describing.

The targeted hardware spans the full S7 line: S7-200, S7-300, S7-400, S7-1200 and S7-1500, across CPU variants (the 1200 range covers the 1211C through 1217C, and the 1500 range includes the F-series safety controllers). If you run any of these, assume you are in scope.

What the actors are actually doing, and what they are not

This is reconnaissance and capability development, not a confirmed nationwide outage. The advisory describes read and write access to PLC memory, configuration and ladder logic, scripts disguised as legitimate OT monitoring software, and target discovery through internet scanning services such as Censys and ZoomEye. BleepingComputer frames it as "persistent reconnaissance, potentially preparing attackers for disruption."

The advisory names six most-targeted sectors: Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. It separately notes that the Defense Industrial Base also runs S7 controllers, which is context, not a seventh most-targeted sector. Read the list as the blast radius, not as a ranking to argue with.

The AI angle is the reason this got five agency logos rather than a routine ICS bulletin. The exploitation scripts are Python built with AI assistance, which the agencies call an evolution that, in The Record's quote, is "dramatically reducing the technical expertise and time required" to produce working ICS exploitation code. The tooling is not novel. The speed and the lowered skill floor are.

Two things the advisory does not do, and you should not do either. It names no victim count and no threat group. Some secondary coverage sits this next to July's reported activity against Minnesota water utilities and April's Iran-linked warnings on Rockwell controllers; treat those as prior, separate incidents that BleepingComputer references, not as attribution for this campaign. The primary does neither.

Broader than Siemens, and the operator checklist

The agencies are explicit that S7 is one subset of a wider problem. The Record notes prior warnings on Schneider Electric, Rockwell and Allen-Bradley controllers, so every PLC owner should apply the mitigations, not only Siemens shops. The advisory's own operator actions are concrete: inventory your S7 devices, patch firmware, block TCP 102 at the perimeter, keep PLCs off the public internet, enable PLC passwords and protection levels, hunt for snap7.dll and python-snap7 outside approved engineering workstations, and alert on S7comm PUT/GET operations outside change windows.

This is a distinct event from this week's KEV batch. That was known-exploited IT vulnerabilities with patch deadlines. This is pre-positioning against the controllers that run physical processes, where the fix is network exposure and hygiene, not a single CVE.

The takeaway

If you run S7, the one thing to do today is audit whether TCP port 102 is reachable from any untrusted network, including the flat corporate LAN, not just the internet edge. Treat any internet-exposed S7 as already in the scan set, not as a future risk, and pull the snap7 hunt into your engineering workstations now. The advisory's value is not the AI headline. It is the exact port, protocol and libraries, which give you something to grep for and something to block before the reconnaissance turns into a write.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free