AI is getting closer to being able to exploit OT, and that's very bad news for critical infrastructure

https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-2121-80.jpg
  • Forescout researchers showed AI can port RCE exploits to PLCs, achieving DoS and shellcode execution
  • Effort required heavy researcher input and $500+ in API usage, making attacks impractical for criminals
  • Nation‑state actors remain a concern, as seen in Sandworm’s 2025 attack on Poland’s power grid

If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a little longer.

Recently, security researchers from Forescout set off on a simple mission - to understand if crooks can use AI to target the ever-increasing population of exposed industrial devices. The short answer is “yes, but it’s not yet worth the trouble”.

In their mission, they launched an experiment - to port a remote code execution(RCE) vulnerability from one PLC to another. These devices were built on...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE