
Five chained vulnerabilities in Trane Tracer SC+ HVAC controllers give remote attackers root access to data center cooling systems. A broken substitution cipher, hardcoded global credentials, and unauthenticated API endpoints combine into a full compromise chain. Firmware v6.30.2313 patches all five flaws.

Three CODESYS vulnerabilities (CVE-2025-41658/59/60) let attackers backdoor Soft PLCs from hundreds of manufacturers. Full attack chain analysis and defensive playbook for OT security teams.