The NSA, CISA, FBI, Department of Energy, and EPA issued a joint advisory warning that threat actors are actively using AI-generated Python exploit scripts to attack internet-exposed Siemens S7 Series PLCs (S7-200 through S7-1500). Attackers combine internet-scanning services with AI coding assistants to build custom tools that read and write PLC memory, configuration data, and ladder logic over the S7comm protocol while posing as legitimate OT monitoring software. The agencies said the campaign, spanning critical manufacturing, energy, water/wastewater, chemical, food/agriculture, and defense-industrial targets, is an active threat aimed at reconnaissance and potential future disruption or equipment damage; no specific victim organization or financial loss has been publicly disclosed.