AI-Written Tools Are Now Hitting Siemens PLCs (08/19/2026)

August 19, 2026
AI-Written Tools Are Now Hitting Siemens PLCs (08/19/2026)
Key Intel / TL;DR
  • The NSA, CISA, FBI, Energy, and EPA jointly warned that actors are using AI to write Python exploitation scripts against Siemens S7 programmable logic controllers, disguised as monitoring software.
  • The tools read and write PLC memory, configuration, and ladder logic over the S7comm protocol, across five controller families.
  • The Justice Department charged eight more Iranians tied to the Mabna Institute, bringing the total to 17, over 31.5 terabytes of academic data valued at $3.4 billion.
  • Latvia's road safety agency lost data on 1.2 million people and 200,000 businesses, and its supervisory board resigned.
  • Researchers pulled a JSON Web Token from a co-located Cloudflare Worker at 12 bits per second, and Cloudflare says the issue is already mitigated.

The Siemens advisory is today’s story with your name on it. Five federal agencies put out a joint warning that actors are using AI to write the exploitation tooling for S7 controllers, then packaging it to look like operational technology monitoring software. That is the same equipment class behind the water utility attacks we have been tracking since July, and the barrier to writing the tools has dropped.

Top 5 Critical Security Alerts

1. Five Agencies Warn of AI-Written Tooling Against Siemens Controllers

The NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency issued a joint advisory today. Actors are using artificial intelligence to build Python exploitation scripts around the snap7.dll and python-snap7 libraries, giving read and write access to PLC memory, configuration data, and ladder logic programs over the S7comm protocol. The tools are disguised as legitimate operational technology monitoring software. Targeted models span the S7-200, S7-300, S7-400, S7-1200, and S7-1500 families, across critical manufacturing, energy, water and wastewater, chemical, food and agriculture, commercial facilities, and the defense industrial base. BleepingComputer

Operator Note: Write access to ladder logic is the line that matters. Reading a controller tells an attacker what a plant does. Writing to it changes what the plant does, and the operator’s screen keeps showing whatever the logic now says it should. The advisory’s own mitigations are unglamorous and correct: inventory your S7 devices, patch them, and block internet access to them. We wrote about why that last one carries the load in exposed PLCs, where the attack was setting a password.

2. Eight More Iranians Charged Over $3.4 Billion in Stolen Research

The Justice Department charged eight additional Iranians connected to the Mabna Institute, a hacking-for-hire operation, bringing the total to 17 across an indictment first made public in March 2018. The campaign started around 2013 and hit 178 universities, 144 of them in the United States, along with 53 private companies, 42 of them American, two non-governmental organizations, at least ten US state agencies, and HBO. The $3.4 billion figure values 31.5 terabytes of journals, theses, dissertations, ebooks, and research. The State Department is offering up to $10 million for information on five of the defendants. BleepingComputer

Operator Note: Thirteen years of collection and the charges are the outcome. If you work at a university or a research-heavy company, the target was never your production environment. It was the library subscription, the shared credential, and the graduate student’s account that never had multi-factor enabled, because nobody classified access to journals as sensitive.

3. Latvia’s Road Safety Agency Loses 1.2 Million Records

The Road Traffic Safety Directorate lost data covering 1.2 million people and 200,000 businesses, in a country of roughly 1.8 million. The records include personal and company registration numbers, vehicle plate numbers, payment amounts and dates, addresses from vehicle registration certificates, and payment receipt history reaching back to 2008. The supervisory board has resigned and the agency’s chief has said he will step down once the investigation finishes. Officials describe the attack as targeted and technically competent, with no attribution yet. The Record

Operator Note: Two thirds of a country’s population in one agency’s database, with eighteen years of retained receipts attached to home addresses. Nobody chose to build that. It accumulated because no one ever set a deletion date on payment records, and this is what a retention schedule is for. Go find out how far back your own transaction history runs and whether anyone can name the business reason for the oldest year in it.

4. Four Critical Flaws Are Under Active Exploitation at Once

macOS, SharePoint, VMware vCenter, and Microsoft IKE all have critical flaws being exploited right now. Three of those we have carried separately over the past week, and they are now landing together. The Hacker News

Operator Note: Four simultaneous exploited criticals is a resourcing problem before it is a technical one. Sequence by exposure rather than by severity score: whatever is reachable from the internet goes first, regardless of which number is higher.

5. A Spectre Attack Pulled a Token From a Neighbouring Cloudflare Worker

Working with TU Graz, researchers extracted a JSON Web Token from a co-located Worker’s memory at up to 12 bits per second with 99.16% accuracy, against 2 bits per minute in the 2021 demonstration. Cloudflare Workers runs multiple tenants in separate V8 isolates inside one operating system process, which is the condition the attack needs. Cloudflare says it has already mitigated this in production through improved process isolation, the V8 sandbox, and memory protection keys, and reports no indicators of exploitation over the past three years. The researchers placed the token in victim memory themselves and accessed no customer data. The Hacker News

Operator Note: Read the conditions before you react to the headline. This is a controlled research scenario with the attacker deliberately co-located and the target planted, and the vendor fixed it. The number worth keeping is the improvement curve: 2 bits per minute to 12 bits per second in five years is a 360-fold speedup on a side channel everyone had filed as impractical.

Additional Security Alerts

Threat Intelligence

  • SilkParasite is hitting Central Asian governments with five new remote access trojans: A single campaign carrying that much fresh tooling suggests real development capacity behind it. Dark Reading
  • Microsoft linked more than 30 rotating domains to MacSync Stealer: Infrastructure built to survive takedowns. The Hacker News
  • Grandoreiro has resurfaced in Mexico with a new DLL sideloading campaign: The banking trojan keeps returning with a different loading technique each time. Infosecurity Magazine

Security Breaches & Incidents

  • T-Mobile cut a cable to get Chinese actors out of its network: Physical disconnection as the containment step, which tells you how much confidence there was in anything else. TechCrunch
  • More than 14,500 Dahua cameras were compromised over 35 days: Credential attacks, authentication bypasses, and peer-to-peer access, against devices most owners never log into. BleepingComputer
  • Sakura Internet exposed data on up to 1.36 million accounts: BleepingComputer

Security Tools & Best Practices

  • StopAndProtect is using nearly 2,000 hacked WordPress sites to push malware: Compromised legitimate sites remain the cheapest distribution available. The Hacker News
  • A rogue ransomware affiliate is posing as a data recovery firm to collect payments: The second reporting on the scheme we covered yesterday, now with the affiliate relationship confirmed. BleepingComputer

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)