AI is getting closer to being able to exploit OT, and that’s very bad news for critical infrastructure
- Forescout researchers showed AI can port RCE exploits to PLCs, achieving DoS and shellcode execution
- Effort required heavy researcher input and $500+ in API usage, making attacks impractical for criminals
- Nation‑state actors remain a concern, as seen in Sandworm’s 2025 attack on Poland’s power grid
If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a little longer.
Recently, security researchers from Forescout set off on a simple mission – to understand if crooks can use AI to target the ever-increasing population of exposed industrial devices. The short answer is “yes, but it’s not yet worth the trouble”.
In their mission, they launched an experiment – to port a remote code execution (RCE) vulnerability from one PLC to another. These devices were built on closed-source software and thus were not that easy to manipulate, yet the experiment was a success.
Latest Videos FromTechRadar
Yes, but…
Not only did they manage to trigger a Denial of Service (DoS) state that crashed the device but ended up with a working RCE capable of executing attacker-supplied ARM shellcode.
It is indeed a worrying development, but one that comes with a huge “but”:
“It required significant researcher input. The final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial RCE ultimately bricked the PLC,” the researchers said in the report.
“These limitations taught us valuable lessons about AI-assisted exploitation in OT. It can be done, but it’s not as easy as it sounds. For now, the difficulty, cost, and specialist expertise required are likely to make this kind of attack less attractive than easier alternatives.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
In other words, cybercriminals still have easier avenues to explore, and as long as that is the case, OT is relatively safe. What the report, unfortunately, does not discuss, is nation-state attackers with significant resources. For such attackers, industrial devices are a prime target, and spending $500+ in API usage is a drop in a bucket. We’ve already seen it back in 2025 when Sandworm struck Poland’s electricity suppliers.
![]()
The best antivirus for all budgets

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Forescout researchers showed AI can port RCE exploits to PLCs, achieving DoS and shellcode execution Effort required heavy researcher input and $500+ in API usage, making attacks impractical for criminals Nation‑state actors remain a concern, as seen in Sandworm’s 2025 attack on Poland’s power grid If you are worried cybercriminals…
Recent Posts
- Google says its new Gemini 3.8 Flash model ‘works harder’ but might cost more
- AI is getting closer to being able to exploit OT, and that’s very bad news for critical infrastructure
- Lockheed carries out missile launches directly from a drone boat – will the US Navy be next?
- Here are some of REI’s best Labor Day sale deals
- NYC bans the use of generative AI tools in public schools for students through eighth grade
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023