生成摘要
PUB-820014151E美国多家机构警告威胁行为者正利用人工智能生成的漏洞利用脚本针对西门子 PLC
美国国家安全局(NSA)、网络安全和基础设施安全局(CISA)、联邦调查局(FBI)、能源部(DOE)以及环境保护局(EPA)联合发布了一份网络安全咨询公告,警告针对关键基础设施领域西门子 S7 系列可编程逻辑控制器(PLC)的活跃威胁。威胁行为者正在通过部署与 snap7 库集成、伪装成合法监控工具的人工智能生成 Python 漏洞利用脚本,对暴露的 PLC 进行侦察和能力开发。
严重度高75/100
证据置信度82%1 独立来源
证据状态信号已发布
发生了什么
美国国家安全局(NSA)、网络安全和基础设施安全局(CISA)、联邦调查局(FBI)、能源部(DOE)以及环境保护局(EPA)联合发布了一份网络安全咨询公告,警告针对关键基础设施领域西门子 S7 系列可编程逻辑控制器(PLC)的活跃威胁。威胁行为者正在通过部署与 snap7 库集成、伪装成合法监控工具的人工智能生成 Python 漏洞利用脚本,对暴露的 PLC 进行侦察和能力开发。
Active targeting of operational technology in multiple critical infrastructure sectors utilizing AI-assisted exploit scripting that could lead to industrial disruption and physical safety incidents.
证据摘录
- Threat actors are using AI assistance to generate exploitation scripts disguised as legitimate monitoring tools targeting Siemens S7 Series PLCs.
- Targeted sectors in the US include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities.
- Threat actors combine AI-assisted scripting with open-source automation libraries such as snap7.dll/python-snap7 to conduct read/write operations on PLCs via the S7comm protocol.
- The advisory was jointly released by CISA, NSA, FBI, DOE, and EPA.
严重度维度
影响78
规模70
控制损失65
可利用性85
紧迫性88
不可逆性60
来源引用
- Defending Against an Active Threat to Siemens S7 Series PLCsUS Cybersecurity and Infrastructure Security Agency · 2026-08-19 · primary