NSA, CISA, and FBI warn attackers are using AI to build exploits for industrial control systems

Share
NSA, CISA, and FBI warn attackers are using AI to build exploits for industrial control systems

U.S. intelligence and cybersecurity agencies issued a joint advisory today confirming what many in the security community have feared: attackers are using AI to generate exploit scripts targeting the industrial control systems that run power plants, water treatment facilities, and manufacturing lines.


Attackers are using AI to build exploit scripts for Siemens S7 controllers, U.S. agencies warn. The NSA, CISA, FBI, and allied agencies published a joint advisory identifying an active threat against Siemens S7 programmable logic controllers — the workhorses of industrial automation. According to the advisory, AI is "dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts," enabling threat actors who previously lacked the skill to attack these systems. Affected sectors include energy, water, chemical, and manufacturing — the backbone of critical U.S. infrastructure. The agencies note that attackers can now easily collect public information about vulnerabilities, locate exposed PLCs on the internet, and use AI-generated scripts to exploit them. The UK's AI Safety Institute offers a partial counterpoint: in its evaluations, frontier models failed to hack operational technology systems on their own, getting stuck on the IT systems in front of them rather than the devices themselves. But that finding doesn't neutralize the threat — real-world attackers combine AI with human expertise, and the advisory recommends immediate mitigations including network segmentation and limiting internet exposure of PLCs. This is the first major government advisory explicitly naming AI as a tool lowering the barrier to critical infrastructure attacks, and it signals that the weaponization of AI models for industrial sabotage is no longer theoretical.


OpenAI revokes researchers' access to its Trusted Access for Cyber program. Multiple cybersecurity researchers reported losing access to OpenAI's Trusted Access for Cyber program, which grants vetted defenders access to frontier models with fewer guardrails for security research. OpenAI confirmed the revocations were caused by a "technical issue affecting a limited number of users" and asked researchers to reverify their identity. The affected tier, Daybreak Blue, was launched on August 10 and gives researchers access to GPT-5.6 Sol with safeguards tailored to authorized defensive work — vulnerability discovery, malware analysis, incident response. All researchers TechCrunch spoke to live outside the U.S. and Europe, suggesting the revocations may be region-specific. The incident underscores the friction between AI companies' efforts to control model access and the needs of defensive researchers who depend on less-restricted models to find and report vulnerabilities before attackers do. Anthropic operates a similar program called the Cyber Verification Program.


Google launches AI-powered study tools across Search and Gemini. Google introduced a suite of learning features including AI-generated interactive visuals, 3D simulations, customized practice quizzes, and a dedicated study hub in the Gemini app. Students can now generate custom simulations in Search (plotting citrus fruits on a pH scale, for example), upload handwritten notes to get study documents, and launch multi-step research reports in Gemini Live that run in the background. The features mark Google's latest push to position Gemini as the go-to AI assistant for students, competing with OpenAI and education startups like Knowt and Gauth.

What to watch: Whether the NSA/CISA advisory accelerates new regulations on AI model access for cybersecurity, and how the OpenAI TAC disruptions affect the broader effort to arm defenders with frontier models.

Do you think AI companies should guarantee uninterrupted access for defensive researchers, even when technical issues arise? Tell us in the comments.

Sources: CISA Joint Advisory AA26-231A · The Decoder · TechCrunch — OpenAI TAC · TechCrunch — Google study tools