Skip to content
Live newsroom 125 readers online
Saturday, September 5, 2026 Live Sync: Just now
BreakingGrowth in home-brand products could impact affordability, experts say
Important AVOID AMZN Stage 4 (Conv: 1/5 | Size: 10%)

AI is getting closer to being able to exploit OT, and that's very bad news for critical infrastructure

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works. If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a […]

By deepak · September 2, 2026 · 3 min read

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a little longer.

Recently, security researchers from Forescout set off on a simple mission – to understand if crooks can use AI to target the ever-increasing population of exposed industrial devices. The short answer is “yes, but it’s not yet worth the trouble”.

In their mission, they launched an experiment – to port a remote code execution (RCE) vulnerability from one PLC to another. These devices were built on closed-source software and thus were not that easy to manipulate, yet the experiment was a success.

Not only did they manage to trigger a Denial of Service (DoS) state that crashed the device but ended up with a working RCE capable of executing attacker-supplied ARM shellcode.

It is indeed a worrying development, but one that comes with a huge “but”:

“It required significant researcher input. The final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial RCE ultimately bricked the PLC,” the researchers said in the report.

“These limitations taught us valuable lessons about AI-assisted exploitation in OT. It can be done, but it’s not as easy as it sounds. For now, the difficulty, cost, and specialist expertise required are likely to make this kind of attack less attractive than easier alternatives.”

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

In other words, cybercriminals still have easier avenues to explore, and as long as that is the case, OT is relatively safe. What the report, unfortunately, does not discuss, is nation-state attackers with significant resources. For such attackers, industrial devices are a prime target, and spending $500+ in API usage is a drop in a bucket. We’ve already seen it back in 2025 when Sandworm struck Poland’s electricity suppliers.

➡️ Read our full guide to the best antivirus1. Best overall:Bitdefender Total Security2. Best for families:Norton 360 with LifeLock3. Best for mobile:McAfee Mobile Security

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Source: Read the original article on www.techradar.com

Important Legal & Financial Disclaimer

FutureKnowledge is an automated financial intelligence aggregator. The information provided on this website does not constitute investment advice, financial advice, trading advice, or any other sort of advice and you should not treat any of the website's content as such. We are not registered with the SEC, SEBI, or any regulatory agency. Automated AI-generated content may contain errors. Always conduct your own due diligence and consult your financial advisor before making any investment decisions.

© 2026 FutureKnowledge Intelligence. All rights reserved.