SummaryU.S. cybersecurity and national-security agencies have warned of an active threat targeting Siemens S7 Series PLCs in critical infrastructure. The activity affects sectors including critical manufacturing, energy, water and wastewater, chemicals, food and agriculture, and commercial facilities. Threat actors are using internet scanning to identify exposed or poorly protected controllers, exploiting weak credentials and outdated configurations, and rapidly developing attack tooling with AI assistance. Observed Python scripts incorporate the legitimate snap7.dll/python-snap7 library to communicate with Siemens controllers while masquerading as monitoring tools. The agencies assess that the activity is currently focused on reconnaissance and capability development that could prepare attackers for future operational effects. The warning is broader than Siemens alone: operators of PLC environments generally are being urged to strengthen exposure management, segmentation, authentication, patching and monitoring. Key Takeaways• NSA, CISA, FBI, DOE and EPA have jointly warned of an active threat against Siemens S7 PLC environments. • Attackers are using internet-scanning services to identify internet-exposed or insufficiently protected PLCs. • AI is being used to rapidly iterate exploitation code, reducing portions of the technical barrier associated with developing OT attack tooling. • Observed AI-generated Python scripts incorporate snap7.dll/python-snap7 and can perform read/write operations against PLCs. • Malicious tooling is being disguised as legitimate industrial monitoring software. • Current activity is assessed as persistent reconnaissance and capability development that could prepare attackers for future operational effects. • Operators should remove PLCs from direct internet exposure, strengthen credentials, patch critical vulnerabilities, segment OT networks and monitor unauthorized controller activity. KeywordsSiemens S7, Siemens PLC, programmable logic controller, PLC security, AI-generated malware, AI-assisted cyberattacks, critical infrastructure, operational technology, OT security, ICS security, industrial cybersecurity, python-snap7, snap7.dll, CISA, NSA, FBI, critical manufacturing, energy security, water infrastructure, network segmentation, industrial control systems, Digital Warfare Podcast, threat intelligence