Advertisement
  • The Daily Scoop Podcast

Federal agencies warn of AI-fueled attacks that pose an ‘active threat’ to water and other sectors

Hackers are targeting water, food, energy, chemical, manufacturing and commercial facilities by taking aim at Siemens S7 Series programmable logic controllers (PLCs) and making use of artificial intelligence in the attacks, U.S. government agencies warned Wednesday. It’s the latest government warning about attacks on critical infrastructure as the United States wages war against Iran, which the government blamed for a recent campaign against water and wastewater systems— but doesn’t mention in Wednesday’s alert. The National Security Agency didn’t immediately respond to a request for comment about who was behind the attacks on the PLCs, which are used to control manufacturing processes. The agencies said the attacks were an “active threat,” rather than a theoretical one. The attacks could disrupt critical industrial processes, cause safety incidents or lead to the compromise of sensitive data. Wednesday’s alert from the NSA, Cybersecurity and Infrastructure Security Agency, FBI, Energy Department and Environmental Protection Agency makes special note of the hackers using AI-generated exploitation scripts in the attacks. “Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools,” the alert states. “In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information.”

The Defense Innovation Unit has a new, specialized team that’s hustling to clear major constraints associated with transitioning proven commercial technologies directly into the military services. “Within one year, we will open co-use classified facilities nationwide, slash cyber authorization timelines by half, and enable agile, end-to-end testing capabilities for young companies desperate to demonstrate,” DIU’s Director Owen West wrote in a memorandum unveiling the Bridge Program this week. According to that instruction and a Pentagon press release, DIU’s new business unit is charged with “eliminating critical bottlenecks” — explicitly related to security clearances, classified workspace access, and technology testing and accreditations — that have notoriously kept industry-made prototypes from reaching military end users on the frontlines in a timely manner and at scale. DIU’s current chief of strategic initiatives, Sarah Pearson, will lead the Bridge Program. Pearson, who formerly served as a Navy officer and technology executive, conceptualized this effort for the unit over the last year. Some of the activities will include establishing a quicker and more reliable tech accreditation portfolio that’s enabled by cybersecurity and AI capabilities, and modernizing the military’s test and evaluation pipelines.

The Daily Scoop Podcast is available every Monday-Friday afternoon.

If you want to hear more of the latest from Washington, subscribe to The Daily Scoop Podcast  on Apple PodcastsSoundcloudSpotify and YouTube.

Monday through Friday

The Daily Scoop Podcast

We discuss the latest news and trends facing government leaders on such topics as technology, management and workforce. The program will explore headlines of the day as well as in depth discussions with top executives in both government and industry.

Advertisement