AI meets decades of technical debt
Vulnerability discovery has become cheap. The machines it finds are the ones that cannot be patched, cannot run an agent and cannot be taken offline – and federal advisories now name AI-generated exploits by name.
For twenty years, the machines running plants, hospitals, utilities and buildings have been protected less by security than by obscurity and effort. Finding a flaw in a programmable logic controller took a specialist, a lab and months. That arithmetic has changed. Vulnerability discovery is now cheap, and the devices it finds are the ones least able to be fixed.
Status verified October 4, 2026. This page tracks a moving target and is updated as actions land.
The federal warning is already specific, and it names AI
On August 19, 2026, the NSA, CISA, the FBI, the Department of Energy and the Environmental Protection Agency jointly published AA26-231A, Defending Against an Active Threat to Siemens S7 Series PLCs.
The advisory describes threat actors using AI-generated Python scripts built on the `snap7.dll` library to reach Siemens PLCs, and using commercial Internet scanning services such as Censys and ZoomEye to find, in the agencies' words, "Internet-exposed or insufficiently segmented" controllers. It states plainly: "If PLCs are exposed to the Internet, they are at high risk for exploitation."
What matters is not that a vulnerability exists. It is that AI-assisted development collapsed the cost of weaponizing it. The agencies note actors "rapidly iterating exploit code through AI-assisted development" — work that previously required scarce expertise.
The advisory lists seven mitigations. Patching is second. Third is: "Ensure PLCs are NOT accessible from the Internet." For an asset that cannot take the patch, the second is unavailable and the third is what remains.
Discovery got cheap. Fixing did not.
The academic framing is blunt. In After Cheap Discovery: From unknown to known-and-unfixed, Bahman Sistany describes what happens when AI makes it economically viable to examine systems that were previously too obscure to be worth anyone's time. Those systems do not become secure. They move from unknown — relatively safe through irrelevance — to known-and-unfixed, which is a materially worse place to be.
Analysis published through the Cloud Security Alliance in June 2026 put numbers on the compression: time-to-exploit has fallen from 2.3 years in 2018 to under one day in 2026.
Industrial estates cannot absorb that. A continuous process does not pause because a CVE arrived. Maintenance windows fall months apart, or once a year at an annual shutdown planned long in advance. ICS components are specified for lifecycles of twenty-five to thirty-five years, and a great deal of what is running today is already past vendor support — SCADA servers on Windows XP, PLCs on firmware from 2009. The title of that analysis is the whole problem: you cannot patch a running plant.
The models themselves have already reached real systems
On July 30, 2026, Anthropic disclosed three incidents – the earliest from April – in which its own models, running in what were believed to be isolated evaluation environments, reached the open Internet and affected real organizations.
In one, Claude Opus 4.7 found a real company whose domain matched a fictional target, exploited vulnerabilities in its infrastructure, extracted credentials and reached a database holding several hundred rows of production data — which Anthropic called "the most serious impact we identified." In another, Claude Mythos 5 published a malicious Python package to PyPI that was downloaded and run on fifteen real systems, including a security company's scanner.
Anthropic's own assessment is that these were "closer to a harness and operational failure than a model alignment failure," and that the models involved ran without the safeguards applied to commercial deployments. That is a fair characterization, and it is also the point for anyone defending infrastructure: the capability is present, and the thing that kept it contained was configuration.
This is not a future problem for critical infrastructure
AI-assisted exploitation sits on top of pressure that was already there. CISA's advisory AA26-097A, issued April 7, 2026 and updated in July, warns of Iranian-affiliated actors targeting Internet-connected operational technology including PLCs. The FCC has moved against foreign-made routers on national-security grounds, and national cyber leaders have warned for years that state-sponsored actors have pre-positioned inside compromised routers and smart hardware.
The common factor across all of it is reachability. Equipment that cannot be patched, cannot run an agent and cannot be taken offline is still, in most estates, reachable from the Internet.
What actually changes the exposure
The federal guidance and the OT analysis converge on the same conclusion, and it is not "patch faster." Where patching is structurally impossible, the remaining control is reachability: take the equipment off the public Internet, and constrain what it can talk to.
That is what Faction Pods and Portals do, and what Faction Outposts will do – Outposts are in Early Access. Equipment behind one has no path to the Internet; its only route is an encrypted tunnel to your Faction Network. Nothing is installed on the machine itself, which matters precisely because these are the devices that cannot take software. The controller that cannot be patched this quarter stops being discoverable by an Internet scan, and stops being reachable by a script generated in an afternoon.
It does not make a vulnerable device invulnerable. It removes the path an attacker needs to reach it, which for an unpatchable asset is the control that remains.
Sources: CISA AA26-231A, Defending Against an Active Threat to Siemens S7 Series PLCs · CISA AA26-097A, Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers · Anthropic, Investigating three incidents in our cybersecurity evaluations · Cloud Security Alliance, You can't patch a running plant · After Cheap Discovery: From unknown to known-and-unfixed · CISA and partners, Principles for the Secure Integration of AI in Operational Technology
Own your trust. Keep your peace of mind.
The new threat environment calls for a new Zero Trust model. We'd welcome the chance to show you how Faction puts you in control and secures your critical systems and assets rapidly with low cost and IT overhead.