Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Likho Stealer’s New Toolkit Steals Telegram Sessions and Records Conversations
August 13, 2026
Jewelbug APT Hijacks Browsers to Steal Cookies, Spy on Government Networks
August 13, 2026
GitLab 16.2.2 Patches High-Severity XSS and CI/CD Authorization Flaws
August 13, 2026
Home/Threats/Critical Vulnerability in Schneider Electric APC NetBotz Exposes Data Centers
Threats

Critical Vulnerability in Schneider Electric APC NetBotz Exposes Data Centers

Key Takeaways Thousands of industrial control systems (ICS) and building automation systems (BAS) near U.S. data centers are exposed to the public internet. These exposed devices manage critical...

Marcus Rodriguez
Marcus Rodriguez
August 13, 2026 4 Min Read
2 0

Key Takeaways

  • Thousands of industrial control systems (ICS) and building automation systems (BAS) near U.S. data centers are exposed to the public internet.
  • These exposed devices manage critical functions like cooling and power distribution, creating a significant attack surface for potential disruptions.
  • Researchers identified over 6,300 such devices within one kilometer of 1,063 U.S. data centers, primarily using BACnet and Fox/Niagara protocols.
  • Successful exploitation could lead to data center outages, equipment damage, or costly emergency responses.
  • Mitigation involves removing direct public access, implementing strong authentication, network segmentation, and regular security audits of facility control systems.

A recent analysis reveals that thousands of industrial and building management controllers, crucial for the operational integrity of U.S. data centers, are directly accessible from the public internet. This widespread exposure presents a substantial risk to the physical infrastructure underpinning these vital facilities.

Table Of Content

  • Key Takeaways
  • Research Uncovers Extensive Exposure
  • Internet-Exposed Controllers: A Closer Look
  • What You Should Do

These exposed devices are responsible for maintaining critical environmental conditions, managing power distribution, and regulating cooling systems within data centers. Should an unauthorized entity gain control, the consequences could range from widespread service disruptions and severe equipment damage to expensive emergency interventions.

The core of the problem lies in the direct internet connectivity of industrial control systems (ICS) and building automation systems (BAS). Cybercriminals can readily locate these systems online and exploit publicly available software details, misconfigurations, or known vulnerabilities to establish a foothold.

Research Uncovers Extensive Exposure

Researchers at TrendAI identified a staggering 6,300 industrial control and building automation devices situated within a one-kilometer radius of 1,063 data centers across the United States. This data, derived from passive Shodan scans rather than active probing, was detailed in a report shared by TrendAI. While the research cannot definitively link each device to a specific data center, it clearly delineates a significant and proximate attack surface.

The uninterrupted operation of cooling and power systems is as fundamental to a data center as its servers. A sudden compromise of cooling capacity can trigger thermal alarms and automatic shutdowns, while power disturbances can corrupt data or interrupt critical applications. Prior reports on power device security flaws underscore how vulnerabilities in management systems can escalate into large-scale availability incidents.

Internet-Exposed Controllers: A Closer Look

The TrendAI study found that the BACnet protocol on port 47808 and the Fox/Niagara protocol on port 1911 accounted for 81 percent of the identified exposed devices. These protocols are commonly employed for controlling air conditioning, environmental sensors, and access control systems. Additionally, the analysis revealed 159 Modbus devices, frequently associated with power meters and various industrial equipment, and 16 Vertiv/Liebert devices, which are typically used in precision cooling, uninterruptible power supplies (UPS), and power distribution hardware.

Exposed system banners often reveal sensitive information such as vendor names, firmware versions, zone labels, and equipment inventories. This information significantly reduces the effort required for attackers to select and target vulnerable systems. In one anonymized instance, researchers observed a device responding to both Modbus and BACnet, indicating a potential link between power monitoring and cooling controls through a single point of entry.

The risk is not confined to a single protocol or vendor. The researchers documented 143 multi-protocol devices, with 125 communicating via both Fox/Niagara and BACnet. Such gateways are particularly critical, as compromising one interface could provide access to multiple interconnected building systems.

Further insights into the risks posed by direct access to web-managed building controls can be gleaned from a related report on online Honeywell controller exposure.

Interestingly, newer data center facilities exhibited a higher rate of nearby exposed devices. Sites permitted from 2021 onwards showed a 13.1 percent exposure rate, compared to 4.9 percent for facilities constructed before 2010. This trend is attributed to rapid deployment cycles, increased reliance on remote management, and potentially deferred security assessments. It is important to note that IP geolocation identifies a network area, not a precise building, so these figures represent potential vulnerabilities rather than confirmed breaches within specific data centers.

What You Should Do

  • Conduct Comprehensive Asset Discovery: Actively scan and inventory all public-facing IP address ranges to identify any internet-exposed building automation and industrial control systems. This must include devices managed by facilities teams, not just IT-controlled assets.
  • Review Network Access Controls: Scrutinize router and firewall rules for any port forwarding configurations that expose BACnet (port 47808), Fox/Niagara (port 1911), Modbus, EtherNet/IP, or other ICS/BAS services directly to the public internet.
  • Eliminate Direct Public Access: Wherever possible, remove direct public internet access to these critical control systems. Implement secure remote access solutions such as controlled VPNs, SSH tunnels, or zero-trust network access (ZTNA) services, ensuring strong multi-factor authentication and least-privilege permissions.
  • Strengthen Authentication and Patch Management: Replace all default credentials with strong, unique passwords immediately. Ensure that all supported products are regularly patched and updated to address known vulnerabilities. For devices that have reached end-of-life, apply compensating network controls to mitigate risks.
  • Implement Network Segmentation: Isolate building automation systems onto a separate operational technology (OT) network. Restrict traffic flow between the OT network, enterprise systems, and the internet to only what is absolutely necessary. This re-establishes a crucial security boundary often bypassed by direct internet connections for facilities equipment.
  • Develop and Practice Incident Response Plans: Conduct regular tabletop exercises and drills with facilities staff and contractors to rehearse responses to cooling or power control incidents.
  • Enhance Monitoring: Implement robust monitoring for unusual remote connections and unexpected changes in Modbus or BACnet traffic patterns. Early detection of anomalous behavior can significantly reduce the impact of a potential compromise, as demonstrated by incidents like the FrostyGoop malware, which focused on Modbus-based attacks to cause physical disruption.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarePatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Threat Actors Exploit Google Workspace for Phishing and Scam Campaigns

Next Post

GitLab 16.2.2 Patches High-Severity XSS and CI/CD Authorization Flaws

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Microsoft SharePoint CVE-2023-29357 Actively Exploited
August 13, 2026
Cloudflare Reports Record DDoS Attacks Exceeding 1 Tbps in H1 2023
August 13, 2026
Gunra Attackers Hijack RDP Sessions to Compromise Active Directory
August 13, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us