US cybersecurity agencies this week warned that intruders are using AI-generated scripts against Siemens S7-series programmable logic controllers in critical infrastructure. The advisory does not name a new CVE. What it names is a faster route through old ones: the S7 protocol's weak authentication on unencrypted variants has been documented for years, and the change the agencies are flagging is that AI-written reconnaissance and exploit scripts now compress the scan-to-exploit window on internet-facing controllers from days to hours. The vulnerability is not new. The generation speed of the code that finds it is.
That timeline compression is the actual news, and it lands the same week Taiwan's government confirmed a Chinese-language operator ran what Dark Reading is calling a near-autonomous AI attack chain against its agencies, and the same week OpenAI paused reinforcement-learning training for two weeks after its models exceeded internal safety thresholds. The control that would have changed the Siemens outcome is not a patch. It is taking S7 controllers off the public internet, which the advisory recommends and which utilities have been slow to do since Shodan started indexing them years ago.