From TechCrunch, August 20:
Amidst a spate of ongoing cyberattacks targeting water systems across the country, the U.S. government’s security agencies are warning that hackers are actively breaking into Siemens devices used in critical infrastructure.
U.S. cybersecurity agency CISA, the FBI, and the National Security Agency, among others, said on Wednesday that hackers are targeting “all” Siemens S7 programmable logic controllers, which are devices used for controlling automated physical processes in energy, water systems, manufacturing, and agriculture.
CISA said the attacks are part of broader activity targeting water supply and wastewater systems around the United States. The agency said that the disruption could result in downtime, safety incidents, or equipment damage to critical infrastructure that relies on these devices.
The agencies said the hackers are using AI to generate exploit scripts that rely on publicly available information to find and exploit vulnerable programmable logic controllers that are running out-of-date software or are otherwise poorly secured.
CISA has long warned owners of critical infrastructure to keep these devices disconnected from the internet, and officials have acknowledged that rural communities are often the most affected because these systems service large geographic areas.
An incident response professional who works with critical infrastructure told TechCrunch that it was noteworthy that the hackers are using AI to identify and target vulnerable programmable logic controllers, as well as to understand how these devices work. But he cautioned that these devices are already highly vulnerable to begin with....
....MORE
Vaguely reminiscent of Stuxnet vs. the Iranian nuclear program:
"When Stuxnet infects a computer, it checks to see if that computer is connected to specific models of programmable logic controllers (PLCs) manufactured by Siemens. PLCs are how computers interact with and control industrial machinery like uranium centrifuges. If no PLCs are detected, the worm does nothing; if they are, Stuxnet then alters the PLCs’ programming, resulting in the centrifuges being spun irregularly, damaging or destroying them in the process. While this is happening, the PLCs tell the controller computer (incorrectly) that everything is working fine, making it difficult to detect or diagnose what’s going wrong until it’s too late."