# 美国多机构警告：攻击者正用AI构建针对西门子PLC的利用脚本

- 来源：The Decoder：AI News（RSS）
- 作者：Matthias Bastian
- 发布时间：2026-08-20 02:55
- AIHOT 分数：53
- AIHOT 链接：https://aihot.virxact.com/items/cmt0he6dt04q4ro2oya4f6ja8
- 原文链接：https://the-decoder.com/attackers-are-using-ai-to-build-exploits-for-industrial-control-systems-u-s-agencies-warn

## AI 摘要

美国NSA、CISA、FBI等机构联合警告，攻击者正使用AI生成针对西门子S7可编程逻辑控制器的利用脚本，大幅降低了攻击工业控制系统（ICS）所需的技能水平和时间。AI还使对手能快速利用更多攻击向量并适应防御措施，能源、水务、化工和制造业均受影响。英国AI安全研究所的模拟中，模型尚无法独立入侵运营技术（OT）系统，但卡在了其前的IT系统上。

## 正文

It's happening! Attackers are using AI to build exploit scripts targeting Siemens S7 programmable logic controllers, according to a joint advisory from the NSA, CISA, FBI, and other U.S. agencies. AI is drastically cutting both the skill level and time needed to attack industrial control systems (ICS), the agencies say.

Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information. If PLCs are exposed to the Internet, they are at high risk for exploitation.

Joint Cybersecurity Advisory

Affected sectors include energy, water, chemical, and manufacturing. The agencies classify this as an active threat. The full advisory with recommended mitigations is available as a PDF. In simulations by the UK's AI Safety Institute, models have so far failed to hack operational technology (OT) systems on their own. They didn't fail at the devices themselves, though, but got stuck on the IT systems in front of them.

Website
