PUB-820014151Eअमेरिकी एजेंसियों ने एआई-जनरेटेड एक्सप्लॉइटेशन स्क्रिप्ट्स का उपयोग करके सीमेंस पीएलसी को निशाना बनाने वाले थ्रेट एक्टर्स के बारे में चेतावनी दी
एनएसए, सीआईएसए, एफबीआई, डीओई और ईपीए ने एक संयुक्त साइबर सुरक्षा एडवाइजरी जारी कर महत्वपूर्ण बुनियादी ढांचा क्षेत्रों में सीमेंस एस7 सीरीज के प्रोग्रामेबल लॉजिक कंट्रोलर्स (पीएलसी) को निशाना बनाने वाले एक सक्रिय खतरे की चेतावनी दी है। थ्रेट एक्टर्स उजागर (एक्सपोज्ड) पीएलसी को निशाना बनाने के लिए वैध निगरानी उपकरणों के रूप में प्रच्छन्न स्नैप7 लाइब्रेरी के साथ एकीकृत एआई-जनरेटेड पायथन एक्सप्लॉइटेशन स्क्रिप्ट्स को तैनात करके टोह ले रहे हैं और क्षमताओं का विकास कर रहे हैं।
क्या हुआ
एनएसए, सीआईएसए, एफबीआई, डीओई और ईपीए ने एक संयुक्त साइबर सुरक्षा एडवाइजरी जारी कर महत्वपूर्ण बुनियादी ढांचा क्षेत्रों में सीमेंस एस7 सीरीज के प्रोग्रामेबल लॉजिक कंट्रोलर्स (पीएलसी) को निशाना बनाने वाले एक सक्रिय खतरे की चेतावनी दी है। थ्रेट एक्टर्स उजागर (एक्सपोज्ड) पीएलसी को निशाना बनाने के लिए वैध निगरानी उपकरणों के रूप में प्रच्छन्न स्नैप7 लाइब्रेरी के साथ एकीकृत एआई-जनरेटेड पायथन एक्सप्लॉइटेशन स्क्रिप्ट्स को तैनात करके टोह ले रहे हैं और क्षमताओं का विकास कर रहे हैं।
Active targeting of operational technology in multiple critical infrastructure sectors utilizing AI-assisted exploit scripting that could lead to industrial disruption and physical safety incidents.
प्रमाण अंश
- Threat actors are using AI assistance to generate exploitation scripts disguised as legitimate monitoring tools targeting Siemens S7 Series PLCs.
- Targeted sectors in the US include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities.
- Threat actors combine AI-assisted scripting with open-source automation libraries such as snap7.dll/python-snap7 to conduct read/write operations on PLCs via the S7comm protocol.
- The advisory was jointly released by CISA, NSA, FBI, DOE, and EPA.
गंभीरता आयाम
स्रोत संदर्भ
- Defending Against an Active Threat to Siemens S7 Series PLCsUS Cybersecurity and Infrastructure Security Agency · 2026-08-19 · primary