Attackers are now targeting physical systems within data center environments. Vulnerabilities in power infrastructure could shut down entire computer networks instantly, while breaches in cooling systems can cause server facilities to overheat, even from a single cyberattack.
See also: Outlook spying: Hackers were monitoring a stock exchange executive

Modern data centers face an increasing threat from cybercriminals who now target physical infrastructure components rather than just software systems. Attackers know that compromising a single power device or climate control unit could cause massive operational failures across entire computing facilities.
The financial stakes are extremely high, as downtime at these facilities often costs hundreds of thousands of dollars per hour.
Recent research by Team82 has uncovered serious vulnerabilities in two key categories of data center equipment widely used in large facilities, raising concerns for users everywhere.
The first set of issues affects the network cards in Vertiv's Uninterruptible Power Supplies (UPS), which maintain stable electrical power during grid fluctuations or power outages. Any successful exploitation of these vulnerabilities could effectively shut down every server and router that depends on this power protection system.
See also: WordPress: Hackers exploit Burst Statistics vulnerability

The second discovery concerns deeply hidden vulnerabilities in Trane Tracer SC+ HVAC controllers that regulate temperatures in server rooms. An attacker who exploits these issues could execute unauthorized remote code and gain complete control of a building's environmental management systems without any prior access.
Standard protections such as antivirus software may not fully cover these systems because they directly monitor the physical infrastructure rather than just the data. This creates a risk where malware or targeted attacks could impact both digital services and the physical environment that supports them.
“Data centers must make a fundamental shift in how they redefine their cybersecurity and operational resilience goals, given that a single cyberattack incident can lead to physical outage, create security risks, or cause catastrophic downtime,” said Amir Preminger, CTO of Claroty and head of Team82.
Preminger also noted that the growing demand from cloud computing and artificial intelligence makes these systems more critical than ever. The vulnerabilities were disclosed to manufacturers Trane and Vertiv, who worked with researchers to fix the issues before the public announcement.
See also: Hackers abuse Google Ads and Claude.ai chats for Mac attacks

The world is now heavily dependent on AI workloads running exclusively within data centers, which governments and industry increasingly treat as critical infrastructure. Malicious actors are simultaneously deploying AI-enabled attacks while targeting physical systems that lie outside traditional security perimeters. A compromised UPS device cannot be fixed by rebooting a server, because the power path itself becomes the means of attack.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
