메뉴
BL
The Decoder • 37일 전

미 기관 경고: 해커들이 AI로 산업 제어 시스템 익스플로잇 개발

IMP
8/10
핵심 요약

NSA, CISA, FBI 등 미국 기관들의 합동 권고에 따르면, 공격자들이 AI를 활용해 지멘스 S7 PLC(프로그래밍 가능 논리 컨트롤러)를 겨냥한 익스플로잇 스크립트를 제작하고 있습니다. AI는 산업 제어 시스템(ICS) 공격에 필요한 기술 수준과 시간을 획기적으로 낮추고 있어, 인터넷에 노출된 PLC는 매우 위험합니다. 에너지, 상수도, 화학, 제조 분야가 영향권에 있으며 능동적 위협으로 분류됩니다.

번역된 본문

해커들이 AI로 산업 제어 시스템 익스플로잇을 개발하고 있다고 미국 기관들이 경고했다. Matthias Bastian, 2026년 8월 19일.

이제 실제로 일어나고 있다! NSA, CISA, FBI 및 기타 미국 기관들의 합동 권고에 따르면, 공격자들이 AI를 활용해 지멘스 S7 프로그래밍 가능 논리 컨트롤러(PLC)를 표적으로 하는 익스플로잇 스크립트를 제작하고 있다.

이들 기관은 AI가 산업 제어 시스템(ICS) 공격에 필요한 기술 수준과 시간을 획기적으로 줄이고 있다고 밝혔다. AI로 익스플로잇 스크립트를 생성하는 것은 위협 행위자 역량의 진화를 보여주며, 작동하는 ICS 익스플로잇 스크립트와 악성 도구를 개발하는 데 필요한 기술 전문성과 시간을 크게 감소시킨다.

또한 AI는 공격자들이 추가적인 공격 벡터를 신속히 활용하고 방어 조치에 적응할 수 있게 한다. 위협 행위자는 취약점과 약점에 관한 공개 정보를 손쉽게 수집하고, 노출되어 침입 가능한 PLC를 찾은 뒤, AI가 생성한 스크립트를 사용해 해당 정보를 활용할 수 있다. PLC가 인터넷에 노출되어 있다면 침해 위험이 매우 높다. — 합동 사이버보안 권고

영향을 받는 분야에는 에너지, 상수도, 화학, 제조가 포함된다. 해당 기관들은 이를 능동적 위협으로 분류했다. 권장 완화 조치가 담긴 전체 권고문은 PDF로 제공된다.

영국 AI 세이프티 연구소(AI Safety Institute)의 시뮬레이션에서는 지금까지 모델들이 자율적으로 운영 기술(OT) 시스템을 해킹하는 데 실패했다. 다만 기기 자체에서 실패한 것이 아니라, 그 앞단의 IT 시스템에서 막혔던 것이다.

원문 보기
원문 보기 (영어)
Attackers are using AI to build exploits for industrial control systems, U.S. agencies warn Matthias Bastian View the LinkedIn Profile of Matthias Bastian Aug 19, 2026 It's happening! Attackers are using AI to build exploit scripts targeting Siemens S7 programmable logic controllers, according to a joint advisory from the NSA, CISA, FBI, and other U.S. agencies. AI is drastically cutting both the skill level and time needed to attack industrial control systems (ICS), the agencies say. Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information. If PLCs are exposed to the Internet, they are at high risk for exploitation. Joint Cybersecurity Advisory Affected sectors include energy, water, chemical, and manufacturing. The agencies classify this as an active threat. The full advisory with recommended mitigations is available as a PDF. In simulations by the UK's AI Safety Institute, models have so far failed to hack operational technology (OT) systems on their own . They didn't fail at the devices themselves, though, but got stuck on the IT systems in front of them. Ad Ad AI News Without the Hype – Curated by Humans Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section. Subscribe now Source: Website Ask about this article… Search