#Team82
🏢 Team82’s research found that attackers can potentially reach data center assets through indirect pathways, including interconnected IT systems, third-party remote access, and trusted network relationships.

🔎 Read more: claroty.com/blog/data-ce...
Data Center Exposures and the Pathways Putting Data Center Assets at Risk
Secure data centers require remediation and mitigation of data center asset and infrastructure exposures. Claroty Team82’s latest research report dives into the riskiest data center exposures, and how...
claroty.com
September 24, 2026 at 8:38 PM
Vulnerability Disclosure - SCHNEIDER ELECTRIC Modicon Controllers M241 / M251 / M262
CPS Vulnerability Disclosure Dashboard
Track all CPS vulnerabilities disclosed by Team82, the industry’s best cybersecurity vulnerability and threat research team. Team82 finds software and firmware vulnerabilities before threat actors can exploit them.
claroty.com
September 14, 2026 at 12:43 AM
🚨 Team82 uncovered vulnerabilities in the Danfoss AK-SM 800A refrigeration controller platform, including a hidden “code-of-the-day” authentication mechanism that could bypass normal authentication. Danfoss has addressed them in a recent firmware version. claroty.com/team82/resea...
Freeze the Controller, Defrost the Food: Uncovering Vulnerabilities in Danfoss Refrigeration Controllers
Team82 researched the attack surface of the Danfoss AK-SM 800A refrigeration controller platform and identified multiple vulnerabilities affecting the embedded web management interface. Team82 disclos...
claroty.com
September 2, 2026 at 6:12 PM
🚨 Team82 uncovered serious security flaws in the Copeland XWEB Pro platform that could allow an unauthenticated attacker to compromise refrigeration systems and cause real-world operational impact.

🔎 Read the research blog: claroty.com/team82/resea...
Chilling Discoveries: Unpacking Vulnerabilities in Copeland XWEB Pro Controllers
Team82 researched the attack surface of the Copeland XWEB Pro platform to assess its resilience against network-based attacks. Our analysis uncovered a total of 23 vulnerabilities, 21 of which are hig...
claroty.com
August 18, 2026 at 6:25 PM
Hackers Can Turn Off Refrigeration While the Temperature Display Still Looks Normal
Hackers Can Turn Off Refrigeration While the Temperature Display Still Looks Normal
Claroty Team82 has uncovered 23 vulnerabilities in Copeland’s XWEB Pro supervisory controllers, widely used to manage commercial refrigeration in supermarkets, warehouses, and hospitals. Of these, 21 are rated high severity, and together they allow an unauthenticated attacker to gain full root-level control of the device over the network. Commercial cooling systems rely on a layered setup. A supervisory controller sits at the top, connected to the internet. In contrast, field controllers below it manage individual units, such as compressors and fans, via a serial connection. The Copeland XWEB300D and XWEB500D PRO controllers are central to this setup, tracking temperature logs required for food safety and health regulations. Commercial refrigeration control system managing multiple units (Source: Team 82) One flaw, tracked as CVE 2026 25085, stems from a coding logic error. When a user submits an unrecognized login type, the system should reject it. Instead, it returns an empty data structure that the software mistakenly treats as valid. This allowed attackers to bypass login checks entirely and access restricted administrative functions without credentials. A second flaw, CVE 2026 21718, is arguably more dangerous. The device generates its administrator SSH and web passwords using only the current date, the device’s MAC address, and secret keys hidden in the firmware. An XWEB500D PRO controller unit (Source: Team 82) Since the date is public and the MAC address is easy to retrieve, an attacker can calculate the exact daily password offline and log in as an administrator. After bypassing authentication, researchers found 19 separate command injection flaws across various device functions, including firmware updates and network settings. These allow attackers to insert hidden system commands into normal-looking data, granting them complete root access to the controller. To demonstrate real-world impact, researchers built a working mini-refrigerator connected to an XWEB controller and an XR60CX field unit. Using a custom Python tool, they demonstrated how to set the display to any arbitrary temperature between -50 and 110 degrees Celsius. An HTTP request that exploits the authentication bypass to access a device-protected endpoint (Source: Team 82) More alarmingly, they showed an attack in which the display kept showing the correct temperature while the cooling fans were silently switched off in the background. The refrigerator slowly warmed, spoiling its contents, with no visible warning on the screen. Claroty reported these issues to Copeland , which released firmware version 1.13 to patch all 23 vulnerabilities. Facilities using XWEB Pro controllers should update immediately, since exploitation requires no valid credentials and can be carried out remotely over the internet. This research highlights a growing risk in operational technology: software bugs in industrial controllers can directly cause physical damage, from spoiled groceries to ruined medical supplies. Experts recommend removing these controllers from direct internet exposure, segmenting refrigeration networks from other systems, and applying vendor patches promptly to prevent similar silent sabotage attacks.  Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. ->  Integrate ANY.RUN With Your SOC  Now . The post Hackers Can Turn Off Refrigeration While the Temperature Display Still Looks Normal appeared first on Cyber Security News .
cybersecuritynews.com
August 11, 2026 at 2:45 PM
コープランドXWEB Proの重大な欠陥、遠隔攻撃者による冷蔵システム乗っ取りが可能に

コープランド社の商用冷蔵コントローラー「XWEB Pro」に新たに23件の脆弱性が明らかになりました。認証バイパスや、予測可能な認証情報生成の欠陥が含まれており、認証されていない遠隔攻撃者がルート権限でのコード実行を獲得できる恐れがあります。 この問題は、Claroty社の研究部門Team82によって公表されたもので...
コープランドXWEB Proの重大な欠陥、遠隔攻撃者による冷蔵システム乗っ取りが可能に
コープランド社の商用冷蔵コントローラー「XWEB Pro」に新たに23件の脆弱性が明らかになりました。認証バイパスや、予測可能な認証情報生成の欠陥が含まれており、認証されていない遠隔攻撃者がルート権限でのコード実行を獲得できる恐れがあります。 この問題は、Claroty社の研究部門Team82によって公表されたもので
blackhatnews.tokyo
August 11, 2026 at 12:51 PM
🔎 Read why traditional assumptions about data center security may leave your environment exposed and what you can do to strengthen cyber resilience. claroty.com/blog/data-ce...
Data Center Exposures and the Pathways Putting Data Center Assets at Risk
Secure data centers require remediation and mitigation of data center asset and infrastructure exposures. Claroty Team82’s latest research report dives into the riskiest data center exposures, and how...
claroty.com
August 3, 2026 at 8:05 PM
July 31, 2026 at 8:40 PM
🚨 New Team82 research reveals 𝟭 𝗶𝗻 𝟱 𝗱𝗮𝘁𝗮 𝗰𝗲𝗻𝘁𝗲𝗿 𝗮𝘀𝘀𝗲𝘁𝘀 𝗮𝗿𝗲 “𝗼𝗻𝗲 𝗵𝗼𝗽” 𝗮𝘄𝗮𝘆 𝗳𝗿𝗼𝗺 𝗯𝗲𝗶𝗻𝗴 𝗮𝗰𝗰𝗲𝘀𝘀𝗶𝗯𝗹𝗲 𝘁𝗼 𝗮𝘁𝘁𝗮𝗰𝗸𝗲𝗿𝘀.

📰 Read more: claroty.com/press-releas...

#DataCenterSecurity #OTSecurity #CyberResilience
July 29, 2026 at 6:13 PM
Angriffsziel Rechenzentrum: Schwachstellen in Equipment bergen hohes Risiko #IT #Software
Angriffsziel Rechenzentrum: Schwachstellen in Equipment bergen hohes Risiko
Team82 entdeckt Schwachstellen in USP-Systemen und HLK-Anlagen
dlvr.it
July 3, 2026 at 9:35 AM
🚨 New research from Team82 explores how Iran-affiliated actors linked to the IRGC and The Ministry of Intelligence of the Islamic Republic of Iran (MOIS) claimed to have hijacked emergency alerts and announcement systems. Read here → claroty.com/team82/resea...
A Cyber-Psychological Operation: Iran-Linked Attackers Target Warning Systems
Iran-affiliated actors linked to the Islamic Revolutionary Guard Corps (IRGC) and The Ministry of Intelligence of the Islamic Republic of Iran (MOIS) claimed to have hijacked emergency alerts and anno...
claroty.com
June 25, 2026 at 6:06 PM
⚡ What happens when attackers target the systems designed to keep data centers online?

New research from Team82 examines vulnerabilities in UPS network management cards and the potential operational impact if they are exploited.

🔖 Read here: claroty.com/team82/resea...
Attacking UPS Network Cards to Take Down Data Centers
Team82 uncovered two critical vulnerabilities in Vertiv’s Liebert IS-UNITY-DP network cards, both assessed a CVSSv3 score of 9.8. These cards are a network interface for Vertiv’s line of uninterruptib...
claroty.com
June 18, 2026 at 12:12 PM
June 15, 2026 at 2:27 PM
Claroty finds authentication bypass, RCE flaws in Vertiv UPS management cards that could disrupt data center operations - Industrial Cyber industrialcyber.co/control-devi...
Claroty finds authentication bypass, RCE flaws in Vertiv UPS management cards that could disrupt data center operations - Industrial Cyber
Claroty's Team82 finds authentication bypass, RCE flaws in Vertiv UPS management cards that could disrupt data center operations.
industrialcyber.co
June 13, 2026 at 2:12 AM
🆕 Team82 research by Amir Zaltzman & Vera Mens looks at critical vulnerabilities in cooling controllers and power systems in data centers.

Amir presented the research today at the SANS ICS Security Summit & Training 2026.

🔖 claroty.com/team82/resea...
🔖 claroty.com/team82/resea...
June 9, 2026 at 8:54 PM
🔎 New research from Team82 reveals vulnerabilities in critical data center infrastructure, including power supply network devices and HVAC system controllers.

📰 Read more: claroty.com/press-releas...

#DataCenterSecurity #DataCenters
New Research Reveals Vulnerabilities in Data Center Equipment with High Potential for Operational Disruption
claroty.com
June 9, 2026 at 5:45 PM
Very uncool to see security #vulnerabilities like these pop up. They're a powerful reminder of why mission-critical infrastructure needs its own, dedicated sub-net / VLAN with a strong firewall / gateway in place at a minimum. No cooling => cooked servers.

www.facilitiesdive.com/news/vulnera...
Vulnerabilities discovered in Trane, Vertiv data center products
The companies are addressing the risks with updates, according to Team82 of cybersecurity company Claroty, which found and shared the vulnerabilities with the companies.
www.facilitiesdive.com
June 9, 2026 at 5:26 PM
June 3, 2026 at 1:00 PM
Our Team82 researchers put Anthropic’s Claude Opus 4.6 model to the test against a popular Zenitel video intercom platform to evaluate how effectively an LLM could identify #cybersecurity vulnerabilities. 🔎 Read the results in this research blog: claroty.com/team82/resea...
Hands Free: What LLM Driven Vulnerability Research Looks Like
Claroty Team82 researchers used Anthropic’s Claude Opus 4.6 AI model to uncover vulnerabilities in a popular video intercom platform manufactured by Zenitel. Team82 had already manually researched and...
claroty.com
June 2, 2026 at 4:28 PM