Thousand of Internet-Exposed Contollers Could Put Data center Cooling and Power at Risk
Cybersecurity NewsArchived Aug 13, 2026✓ Full text saved
Thousands of internet-exposed building controllers may be putting the physical backbone of U.S. data centers at risk. They manage cooling, electrical distribution, and environmental conditions. If an intruder reaches them, the result could be service outages, equipment damage, or a costly emergency response. It is a broad exposure problem created when industrial and building-management devices […] The post Thousand of Internet-Exposed Contollers Could Put Data center Cooling and Power at Risk ap
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Security News
Thousand of Internet-Exposed Contollers Could Put Data center Cooling and Power at Risk
By Tushar Subhra Dutta
August 13, 2026
Thousands of internet-exposed building controllers may be putting the physical backbone of U.S. data centers at risk.
They manage cooling, electrical distribution, and environmental conditions. If an intruder reaches them, the result could be service outages, equipment damage, or a costly emergency response.
It is a broad exposure problem created when industrial and building-management devices are reachable from the public internet.
Attackers can find these systems online and use disclosed software details, weak settings, or known flaws to gain a foothold.
TrendAI researchers identified 6,300 industrial-control and building-automation devices within one kilometer of 1,063 U.S. data centers.
TrendAI said in a report shared with Cyber Security News (CSN) that the findings came from passive Shodan data rather than direct probing.
The research cannot confirm each device belongs to a data center, but shows a nearby attack surface.
Data-center infrastructure and BAS architecture (Source – TrendAI)
Cooling and power are as essential as servers. A sudden loss of cooling margin can trigger thermal alarms and protective shutdowns, while a power disturbance can interrupt applications or corrupt data.
Reporting on power device security flaws shows how management-system weaknesses can create a wider availability incident.
Internet-Exposed Contollers
The study found BACnet on port 47808 and Fox/Niagara on port 1911 made up 81 percent of the exposed devices. These technologies commonly connect air conditioning, sensors, and access controls.
The data also contained 159 Modbus devices, often used with power meters and industrial equipment, plus 16 Vertiv/Liebert devices associated with precision cooling, uninterruptible power supplies, and distribution hardware.
A cluster of 171 devices near Silicon Valley hyperscale campuses (Source – TrendAI)
Exposed banners can disclose vendor names, firmware versions, zone labels, and equipment inventories. That can lower the effort needed to choose a target.
In one anonymized case, researchers saw a device responding to both Modbus and BACnet, potentially linking power monitoring and cooling controls.
The risk is not limited to a single protocol or supplier. Researchers counted 143 multi-protocol devices, including 125 that spoke both Fox/Niagara and BACnet.
Such gateways can be especially consequential because one interface may lead into several building systems.
Data-center OT architecture (Source – TrendAI)
A related report on online Honeywell controller exposure shows why direct access to web-managed building controls deserves close attention.
Newer facilities showed a higher nearby exposure rate than older ones: 13.1 percent for sites permitted from 2021 onward, compared with 4.9 percent for facilities built before 2010.
The report links this to fast deployment, remote management, and delayed security checks. Still, IP geolocation identifies a network area rather than a precise building, so the figures are not a list of confirmed exposed data centers.
Closing the Physical Security Gap
Operators should find what is exposed before attackers do. They should review public-facing address ranges and router or firewall rules for port forwarding to BACnet, Fox, Modbus, and EtherNet/IP services.
Asset inventories must include the controllers used by facilities teams, not only the servers and network gear managed by IT.
Direct public access should be removed wherever possible. Remote maintenance can instead use a controlled VPN, SSH tunnel, or zero-trust access service, with strong authentication and limited permissions.
Organizations should also replace default credentials, patch supported products, and apply compensating network controls when a device has reached end of life.
Segmentation is equally important. Building automation should sit on a separate operational network, with restricted traffic to enterprise systems and the internet.
That restores a security boundary often missing when facilities equipment has its own internet connection.
Attack chain (Source – TrendAI)
The broader exposed industrial systems worldwide problem shows that this is not just a data-center issue.
Teams should also rehearse a cooling or power-control incident with facilities staff and contractors. Monitoring unusual remote connections and unexpected changes to Modbus or BACnet traffic can help surface misuse early.
The FrostyGoop case, covered in FrostyGoop heating outage malware, demonstrated that Modbus-focused attacks can create real disruption, making this exposure a practical resilience concern rather than a theoretical one.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security News
Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks
Cyber Security
Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers
Cyber Security News
North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees
Cyber Security News
CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks
Cyber Security News
GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?