
Five chained vulnerabilities in Trane Tracer SC+ HVAC controllers give remote attackers root access to data center cooling systems. A broken substitution cipher, hardcoded global credentials, and unauthenticated API endpoints combine into a full compromise chain. Firmware v6.30.2313 patches all five flaws.

Nozomi Networks’ analysis of 5.5 million alerts from 10 industrial customers reveals that Sandworm (APT44) systematically exploits already-compromised OT environments. Every infected system gave an average of 43 days of advance warning. After detection, Sandworm escalates — targeting PLCs, HMIs, and engineering workstations directly.

Dragos documents the first real-world case of an adversary using AI tools to target water utility OT infrastructure. Claude autonomously identified SCADA systems and launched credential attacks — without prior ICS knowledge.

On April 8, 2026, a joint advisory from the FBI, CISA, NSA, EPA, DOE, and US Cyber Command confirmed that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) across multiple US critical infrastructure sectors. The attacks — attributed to actors linked to the CyberAv3ngers group and Iran’s Islamic…