Skip to content
Breaking
UK PM Andy Burnham firm in support of Ukraine, unafraid of Russian threatStone inscription with Prophet's name found at ancient Ani site in TurkeyUS judge delays Lockerbie bombing trial over new evidenceHongkong Post wins HK$4.6 billion bailout after eight straight years of lossesPhilippines retains Moody’s Baa2 rating with stable outlookEl Niño preparedness may tame food-price surge, BSP saysCanadian businesses lag in AI adoption despite personal use by executivesMalaysia’s school bullying cases rise 142% in two years amid calls for tougher enforcementMforce extends electric motorcycle rebate deadline to Oct 31, 2026Critical unpatched flaw in Calix routers exposes home networks to internetHonor Pad 20 series launches in Malaysia with RM1,999 starting priceHackers exploit WordPress auth bypass flaws in miniOrange pluginAI-powered attacks target Siemens PLCs used in MalaysiaWordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows PasswordsEuropean stocks flat as markets weigh Iran tensions, await economic dataS&P 500, Nasdaq end down on tech stocks, investors weigh Iran movesRCEP’s investment test: four years in, the bloc still struggles to anchor Asian capitalTrump bought SpaceX shares two weeks after blockbuster IPOZillow agrees to pay Redfin US$100 million to settle FTC antitrust caseUS expands sanctions on Iran’s oil trade and financial networksUK PM Andy Burnham firm in support of Ukraine, unafraid of Russian threatStone inscription with Prophet's name found at ancient Ani site in TurkeyUS judge delays Lockerbie bombing trial over new evidenceHongkong Post wins HK$4.6 billion bailout after eight straight years of lossesPhilippines retains Moody’s Baa2 rating with stable outlookEl Niño preparedness may tame food-price surge, BSP saysCanadian businesses lag in AI adoption despite personal use by executivesMalaysia’s school bullying cases rise 142% in two years amid calls for tougher enforcementMforce extends electric motorcycle rebate deadline to Oct 31, 2026Critical unpatched flaw in Calix routers exposes home networks to internetHonor Pad 20 series launches in Malaysia with RM1,999 starting priceHackers exploit WordPress auth bypass flaws in miniOrange pluginAI-powered attacks target Siemens PLCs used in MalaysiaWordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows PasswordsEuropean stocks flat as markets weigh Iran tensions, await economic dataS&P 500, Nasdaq end down on tech stocks, investors weigh Iran movesRCEP’s investment test: four years in, the bloc still struggles to anchor Asian capitalTrump bought SpaceX shares two weeks after blockbuster IPOZillow agrees to pay Redfin US$100 million to settle FTC antitrust caseUS expands sanctions on Iran’s oil trade and financial networks
AI Edge

AI-powered attacks target Siemens PLCs used in Malaysia

U.S. agencies warned that threat actors are automating attacks on Siemens S7 Series programmable logic controllers using AI-generated scripts, according to a joint alert.

Source: The Hacker News · August 24, 2026 at 10:33 PM · AI-assisted report

Single-source
AI-powered attacks target Siemens PLCs used in Malaysia
Photo: Wikimedia Commons — Tenaga

KUALA LUMPUR, 25 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Share

U.S. agencies warned that threat actors are automating attacks on Siemens S7 Series programmable logic controllers using AI-generated scripts, according to a joint alert.

Market Impact

Threat actors are scanning internet-exposed S7 PLCs via services such as Censys and ZoomEye before deploying AI scripts masquerading as monitoring tools. The alert said the activity is not theoretical but active, with actors mapping environments to prepare future write operations that could disrupt industrial processes.

Malaysian utilities and factories using older S7-300 and S7-400 models with default credentials remain at elevated risk, said a senior OT consultant at a Bursa Malaysia-listed automation vendor. “The AI angle lowers the skill barrier, so any exposed device is now in the crosshairs,” the consultant said.

Separately, 52 high-severity vulnerabilities were disclosed this week, including flaws in Forminator Forms (CVE-2026-15748), Elementor Pro (CVE-2026-32475) and GitLab (CVE-2026-19478). Maybank’s cyber-risk team told corporate clients that patches for Forminator and Elementor are available, but legacy WordPress and self-hosted GitLab instances remain exposed.

JFrog reported that Malaysian software houses with publicly accessible Artifactory repositories are being compromised within hours of new CVEs, including critical-rated CVE-2026-65922. One local firm had 14 repositories compromised last month after failing to rotate default credentials.

Splunk disclosed 13 CVEs, including CVE-2026-76310 through CVE-2026-76312, which could allow privilege escalation. Malaysian Splunk users said Bank Negara Malaysia’s Financial Technology Enforcement Department had ordered upgrades by 30 June or face additional scrutiny.

Analysts said the wave of advisories shows Malaysia’s digital infrastructure is tightening but gaps persist in operational technology and third-party code supply chains. “The threat is no longer limited to nation-state actors,” said a Kuala Lumpur-based risk officer at a government-linked company. “Script kiddies with AI assistance can now probe OT networks that were once considered too hard to reach.”

Related: Tenaga

Reporting based on The Hacker News. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.