AI-powered attacks target Siemens PLCs used in Malaysia
U.S. agencies warned that threat actors are automating attacks on Siemens S7 Series programmable logic controllers using AI-generated scripts, according to a joint alert.
Source: The Hacker News · August 24, 2026 at 10:33 PM · AI-assisted report
Single-sourceKUALA LUMPUR, 25 AUGUST 2026 —
U.S. agencies warned that threat actors are automating attacks on Siemens S7 Series programmable logic controllers using AI-generated scripts, according to a joint alert.
Market Impact
Threat actors are scanning internet-exposed S7 PLCs via services such as Censys and ZoomEye before deploying AI scripts masquerading as monitoring tools. The alert said the activity is not theoretical but active, with actors mapping environments to prepare future write operations that could disrupt industrial processes.
Malaysian utilities and factories using older S7-300 and S7-400 models with default credentials remain at elevated risk, said a senior OT consultant at a Bursa Malaysia-listed automation vendor. “The AI angle lowers the skill barrier, so any exposed device is now in the crosshairs,” the consultant said.
Separately, 52 high-severity vulnerabilities were disclosed this week, including flaws in Forminator Forms (CVE-2026-15748), Elementor Pro (CVE-2026-32475) and GitLab (CVE-2026-19478). Maybank’s cyber-risk team told corporate clients that patches for Forminator and Elementor are available, but legacy WordPress and self-hosted GitLab instances remain exposed.
JFrog reported that Malaysian software houses with publicly accessible Artifactory repositories are being compromised within hours of new CVEs, including critical-rated CVE-2026-65922. One local firm had 14 repositories compromised last month after failing to rotate default credentials.
Splunk disclosed 13 CVEs, including CVE-2026-76310 through CVE-2026-76312, which could allow privilege escalation. Malaysian Splunk users said Bank Negara Malaysia’s Financial Technology Enforcement Department had ordered upgrades by 30 June or face additional scrutiny.
Analysts said the wave of advisories shows Malaysia’s digital infrastructure is tightening but gaps persist in operational technology and third-party code supply chains. “The threat is no longer limited to nation-state actors,” said a Kuala Lumpur-based risk officer at a government-linked company. “Script kiddies with AI assistance can now probe OT networks that were once considered too hard to reach.”
Related: Tenaga