Five US agencies warn of AI-built exploits probing Siemens S7 PLCs: advisory AA26-231A
NSA, CISA, FBI, DOE and EPA issued AA26-231A on active targeting of Siemens S7 PLCs over S7comm on TCP port 102, using snap7 tooling and AI-generated Python scripts. No victim count, no named group. The one control to check today is whether port 102 is internet-reachable.

Five US agencies (NSA, CISA, FBI, the Department of Energy and the Environmental Protection Agency) issued a joint advisory, AA26-231A, on 19 August 2026, warning that attackers are actively probing Siemens S7 programmable logic controllers on factory and utility floors. The document is titled "Defending Against an Active Threat to Siemens S7 Series PLCs." BleepingComputer and The Record both carried it the same day.
The activity rides S7comm, the Siemens control protocol, over TCP port 102, using the snap7.dll and python-snap7 libraries to reach the controllers. That port-and-library detail is the operational core of the advisory, and it sits well below the "AI attacks" headline.
The targeted hardware spans the full S7 line: S7-200, S7-300, S7-400, S7-1200 and S7-1500, across CPU variants. The 1200 range covers the 1211C through 1217C, and the 1500 range includes the F-series safety controllers.
The agencies describe reconnaissance and capability development, not a confirmed nationwide outage. Attackers are getting read and write access to PLC memory, configuration and ladder logic, disguising scripts as legitimate OT monitoring software, and finding targets through internet scanning services such as Censys and ZoomEye. BleepingComputer frames the work as "persistent reconnaissance, potentially preparing attackers for disruption."
The advisory names six most-targeted sectors: Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. It separately notes that the Defense Industrial Base also runs S7 controllers, which is context rather than a seventh most-targeted sector.
The AI angle is why five agency logos showed up on what could have been a routine ICS bulletin. The exploitation scripts are Python built with AI assistance, an evolution that, in The Record's quote, is "dramatically reducing the technical expertise and time required" to produce working ICS exploitation code. The tooling itself is not novel. The speed and the lowered skill floor are.
The advisory names no victim count and no threat group. Some secondary coverage sits this next to July's reported activity against Minnesota water utilities and April's Iran-linked warnings on Rockwell controllers. BleepingComputer references those as prior, separate incidents, and the primary advisory attributes neither to this campaign.
The agencies are explicit that S7 is one subset of a wider problem. The Record notes prior warnings on Schneider Electric, Rockwell and Allen-Bradley controllers, so the listed mitigations apply beyond Siemens shops. Those actions are concrete: inventory S7 devices, patch firmware, block TCP 102 at the perimeter, keep PLCs off the public internet, enable PLC passwords and protection levels, hunt for snap7.dll and python-snap7 outside approved engineering workstations, and alert on S7comm PUT/GET operations outside change windows.
The notice is a distinct event from this week's KEV batch on SharePoint, vCenter, macOS and IKE, which listed known-exploited IT vulnerabilities with patch deadlines. AA26-231A is about pre-positioning against the controllers that run physical processes, where the useful facts are the port, the protocol and the libraries.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free