AI Models Used to Target Utility OT Systems

Dragos documents first AI-assisted ICS attack
AI-assisted cyber attacks are no longer a theoretical future problem, they’re happening right now. Last week an adversary used commercial AI models to guide an intrusion into a live utility's OT environment.
Separately, Verizon's Data Breach Investigations Report (DBIR) came out with a surprising finding: vulnerability exploitation has overtaken stolen credentials as the top breach vector for the first time in 19 years. The culprit, again, is AI-accelerated exploitation.
Two active vulnerabilities that energy operators need to be aware of: a CVSS 10.0 authentication bypass in Cisco SD-WAN with no workaround, and a Microsoft Exchange zero-day being exploited in the wild right now.
If you'd like to see howRaptor Comply helps you stay on top of your CIP obligations while the threat landscape challenges your protections, pick a time here:
Industry Update
Dragos Documents First AI-Assisted Cyberattack Targeting a Utility’s OT Systems
Dragos published a threat intelligence report this week on the first documented AI-assisted cyberattack targeting a utility’s industrial control systems. In January 2026, an unidentified threat actor breached Servicios de Agua y Drenaje de Monterrey, a municipal water and drainage utility in Monterrey, Mexico. The intrusion was part of a broader campaign against nine Mexican government entities between December 2025 and February 2026.
Dragos analyzed more than 350 artifacts, the majority AI-generated malicious scripts, and found the adversary used commercial AI models throughout the attack. After establishing a foothold in the utility’s enterprise IT network, the attacker attempted to pivot toward operational technology infrastructure.
AI lowers the skill threshold for OT-targeting operations by automating the reconnaissance and tooling phases that previously required specialized expertise. The precondition for this attack pattern is an IT network with access to OT systems, which describes the majority of generation facilities. Your CIP-005 Electronic Security Perimeter controls are the primary defense against this lateral movement path. Review your network segmentation between IT and OT environments and confirm your monitoring covers the boundary between them.
Vulnerability Exploitation Is Now the Leading Breach Vector
Verizon’s 2026 Data Breach Investigations Report documents a significant shift in how attackers gain initial access. Vulnerability exploitation now accounts for 31% of all breaches, surpassing stolen credentials as the top entry point for the first time in 19 years. The DBIR attributes the change directly to AI. Attackers are using AI tools to accelerate exploit development and deployment, compressing the time between vulnerability disclosure and active exploitation.
The DBIR data supports documenting your CIP-007 R2 patch management process around exploitability and active threat actor interest.
Compliance Resources
Cisco SD-WAN (CVE-2026-20182)
CISA added CVE-2026-20182 to its Known Exploited Vulnerabilities catalog on May 14, 2026. The vulnerability is a maximum-severity authentication bypass in Cisco Catalyst SD-WAN Controller and SD-WAN Manager. A remote attacker can bypass authentication entirely and gain administrative access to the SD-WAN fabric.
Active exploitation has been attributed to UAT-8616, a sophisticated threat actor tracked by Cisco Talos with a documented history of targeting Cisco SD-WAN infrastructure since at least 2023. On successful exploitation, the group adds SSH keys, modifies NETCONF configurations, and escalates to root privileges. Cisco confirms there are currently no workarounds available.
Microsoft Exchange OWA Zero-Day (CVE-2026-42897)
Microsoft confirmed active exploitation of CVE-2026-42897, a cross-site scripting flaw in the Outlook Web Access component of Exchange Server 2016, 2019, and Subscription Edition.
The attack requires a single crafted email, when opened in OWA, arbitrary JavaScript executes within the recipient’s authenticated browser session, enabling session token theft and mailbox impersonation without server-level access. The vulnerability surfaced two days after Microsoft’s May Patch Tuesday, which patched 138 unrelated vulnerabilities. The next standard patch cycle is June 10, 2026.
Important Dates
May 27:SEIA Virtual Solar & Storage Codes & Standards Symposium. Two-day deep dive on UL 9540, NFPA 855, NEC updates, and new energy storage standards.
June 1: NERC Large Loads Working Group SAR Roadmap comment period closes. This affects interconnection reliability standards for data centers and large energy consumers connecting to the Bulk Power System.
June 2: SEIA Webinar: FEOC Rules for Solar Interconnection ITC. Deep dive on Foreign Entity of Concern restrictions making solar Investment Tax Credits harder to claim under the One Big Beautiful Bill Act.
June 10: Microsoft Patch Tuesday. Expected release of permanent fix for Exchange CVE-2026-42897.
Join our mailing list.
Weekly industry insights, news, and product updates.
More News

Four IBR standards, four different compliance clocks
The ERO ran one-on-one IBR sessions with GOs and GOPs. PRC-028, 029, 030 and MOD-026.

Iranian actors in energy-sector PLCs + Nico knows your fleet
CISA and the FBI name Energy in their updated PLC advisory. Plus nine weeks to the ride-through wave.

FERC orders mandatory NERC standards for data centers
A July 16 FERC order gives NERC a year-end deadline to bring large loads under mandatory standards.