Our Blog
Popular Articles
-

Hacking the Thermostat That Guards the Cloud: 5 CVEs in Trane HVAC Controllers
Five chained vulnerabilities in Trane Tracer SC+ HVAC controllers give remote attackers root access to data center cooling systems. A broken substitution cipher, hardcoded global credentials, and unauthenticated API endpoints combine into a full compromise chain. Firmware v6.30.2313 patches all five flaws.
-

BRIDGE:BREAK in the Wild: The Lantronix Serial-to-IP Flaw That Gives Attackers Root Access to Your OT Network
CVE-2025-67038 in Lantronix EDS5000 serial-to-IP converters is actively exploited in the wild. Forescout confirmed attackers reverse-engineered the firmware patch to build an exploit weeks before public disclosure. CISA added it to the KEV catalog June 23, 2026 with a 72-hour patch deadline.
-

Sandworm Doesn’t Need Zero-Days: Russia’s Most Dangerous Cyber Unit Exploits Already-Compromised Industrial Environments
Nozomi Networks’ analysis of 5.5 million alerts from 10 industrial customers reveals that Sandworm (APT44) systematically exploits already-compromised OT environments. Every infected system gave an average of 43 days of advance warning. After detection, Sandworm escalates — targeting PLCs, HMIs, and engineering workstations directly.