CISA/NSA/FBI warn of AI-generated exploit scripts targeting Siemens S7 PLCs (AA26-231A)
Framework / advisory19 Aug 2026Reported as the first government-confirmed in-the-wild use of AI code-generation to build offensive tooling against operational-technology/ICS (python-snap7 over S7comm), extending offensive-AI risk from software and espionage into physical-safety and critical-infrastructure territory. Scope and attribution are per the CISA advisory.
Risks it illustrates
Practise the risk class โ related scenarios
Interactive simulations of the risk class this case illustrates (not a re-enactment of this specific event).
An ops agent gets one god-mode credential โ and one misread wipes production
A coding agent asks to write ./notes.txt โ the file it actually overwrites is your SSH keys
A text-to-SQL agent runs the model's output straight at the database
An auto-approving coding agent reads a poisoned page โ and executes code it never should have
A fake Sentry error report hijacks a developer's coding agent into running a shell command
Every command is harmless on its own โ the sequence is the exploit
A 'safe' dataset preview turns an upload into code execution on the pipeline's workers
A GUI agent clicks 'Continue' โ but the screen moved, and it lands on 'Send'