'This is not a theoretical risk—it is an active threat': The NSA, FBI, CISA and more warn of AI-assisted hacks against critical US infrastructure and facilities
About
Overview
A cybersecurity advisory jointly authored by multiple US agencies, including the NSA, CISA, FBI, DOE, and EPA, warns the owners and operators of industrial facilities of an "active cyber threat" to Siemens S7 programmable logic controllers. "The threat actors are conducting reconnaissance and capability development against US-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools," says the advisory. "The US critical infrastructure sectors most targeted by this threat activity include critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. This is not a theoretical risk—it is an active threat." Essentially, it reads like a list of some of the most important infrastructure facilities behind the lives of the average US citizen (via The Register). The threat actors are said to be leveraging open source automation libraries to create custom tools that mimic existing monitoring solutions, which are capable of evading detection by security teams. These tools and scripts are said to be conducting read/write operations on data blocks, "potentially for reconnaissance, capability testing, or pre-positioning for effects operations." The advisory notes that the use of AI to generate exploits represents "an evolution in threat actor capabilities," and that it "dramatically [reduces] the technical expertise and time required to develop working ICS exploitation scripts and malicious tools." The advisory also says that, as the Siemens S7 Series PLCs are used in other sectors, including the Defense Industrial Base (DIB), they could also be targeted. As for the potential damage that could be caused, the list is rather long. The potential effects include the disruption of critical industry processes, increased safety incidents affecting personnel through the "manipulation of safety interlocks, emergency shutdown systems, or process parameters," equipment damage and extended operational downtime, the compromise of sensitive operational data, and "cascading impacts across interconnected systems affecting supply chains, dependent facilities, and integrated business operations." All very bad things, I think you'll agree. As for what organisations can do about it, the advice includes multiple steps for detecting anomalies that may indicate a compromise, and a series of "hardening actions" involving firmware updates, patches, network segmentation, and more. While the advisory doesn't attribute blame to any particular government or cybercriminal group, Cynthia Kaiser, the former deputy assistant director of the FBI's Cyber Division (now the senior vice president of the Halcyon Ransom Research Center) has some thoughts related to recent water system cybersecurity breaches. "This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs," said Kaiser, speaking to The Register. "Iran-affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society." Regardless of the cause, it's rare to read an official US government cybersecurity advisory with a tone of such immediacy. In its conclusion, the report asserts that "organizations should treat this cybersecurity advisory with urgency." Gulp.
Details

Source
Originally published at www.pcgamer.com.