Skip to content

Cybersecurity

AI changed vulnerability discovery: but there is an OT gap you cannot ignore

New AI models discover vulnerabilities autonomously and at industrial scale. But the tools stay tuned for IT: the OT world risks falling behind just as attackers accelerate.

2 min read
Abstract illustration: artificial intelligence and vulnerability discovery in OT systems

Automated vulnerability discovery has just taken a generational leap. The latest AI models no longer merely suggest where to look: they find unknown flaws on their own, reproduce exploits, and do it at a scale that until yesterday required entire teams of researchers. That is good news for defenders. But there is a gap the industrial sector cannot afford to ignore.

What actually changed

Recent announcements are clear. The new systems reach success rates around 83% on vulnerability-reproduction benchmarks, discover zero-days autonomously on widely used operating systems and browsers, and in one case identified a bug that had stayed hidden in OpenBSD for 27 years.

The point is not the individual number, but the paradigm shift: vulnerability discovery is becoming industrialized. When a capability like this scales, it scales for everyone.

The gap: these tools speak IT, not OT

The initiatives deploying these models today focus on operating systems, browsers, cloud platforms, and open source software. All areas where patching is an established practice and remediation can be fast.

The OT/ICS world runs by different rules:

Dimension IT OT/ICS
Patching standard updates requires planned downtime, often impractical
Consequences digital only physical-world impact
Hardware x86 with standard OS PLCs with proprietary and legacy protocols
Protocols modern standards Modbus, DNP3, EtherNet/IP, IEC 61850
Access software only often requires physical interaction with the hardware

Assessing an OT vulnerability does not just mean understanding the software: it means understanding how the hardware interacts with the physical world. That is domain expertise the tools designed for IT do not have.

The dual-use risk

Any technology that industrializes vulnerability discovery benefits both defenders and attackers. Whoever is already equipped to act on the results gains an asymmetric advantage.

For critical infrastructure the imbalance is concrete: if attackers acquire AI-enhanced discovery capabilities while OT defenders lack tools tuned to their own environment, the risk grows exactly where the consequences are most severe.

Why remediation in OT is a different craft

A vulnerability found in a SCADA system or a safety instrumented system is not closed with an update. You have to reason about:

  • the blast radius of a potential exploit
  • which compensating controls already exist in the field
  • how to intervene without stopping production or compromising functional safety

These considerations are absent from standard IT workflows, but decisive in an industrial environment.

What is needed now

OT and critical infrastructure security cannot be an afterthought to where this technology is heading.

The direction is clear: bring OT expertise into the design of these tools, not bolt it on afterwards. Industrial defenders need capabilities calibrated to the specific, unforgiving environments they operate in, where unexpected behavior is not acceptable and where the physical world is always downstream of the digital one.

The MON5 point of view

This is exactly the ground we work on. Visibility into OT assets, the correlation of vulnerabilities with the real plant context, and anomaly monitoring without stopping production are the prerequisites for turning the power of AI into concrete defense, including for those who run industrial networks.

AI has changed vulnerability discovery forever. What remains to be decided is whether the industry will leave OT a step behind or put it at the center.


Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.

Related articles

Representation of a compromised industrial PLC affected by a chain of CODESYS vulnerabilities

Cybersecurity

CODESYS Under Attack: Three Chained Flaws to Plant a Backdoor in a PLC

Three chained CVEs in the CODESYS Control runtime let a Service user replace the PLC application with a backdoored version and run code as root.

3 min read
Industrial protocols Modbus, DNP3, and OPC UA with vulnerability analysis

Cybersecurity

Vulnerabilities in Industrial Protocols: Modbus, DNP3, OPC UA, and the Hidden Risks

Modbus, DNP3, OPC UA, and PROFINET underpin industrial communications. Designed for reliability in closed networks, they carry intrinsic vulnerabilities that become critical in increasingly connected environments.

4 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna