What Happened
Claroty has analyzed 750,000 cyber-physical systems across some of the world’s largest data center facilities. The post 1 in 5 Data Center Assets Are Within Easy Reach of Attackers appeared first on SecurityWeek .
Why It Matters
Claroty’s research finds that about 18% of 174,000 cyber-physical data center infrastructure assets are only one network hop away from internet-exposed systems, creating accessible attack paths to power distribution, HVAC, and other critical CPS components.[1] These findings highlight converged IT/OT exposure and reliance on third-party hardware and controllers, which aligns with broader data center supply-chain and infrastructure risks.[2][3] From a RealGround perspective, this indicates elevated AI supply chain risk for AI workloads hosted in such facilities: compromise of cooling, power, or building management systems can quickly cascade into outages or integrity issues for AI clusters and training environments. Organizations should prioritize SBOM-driven supplier oversight, OT/IT network segmentation, and readiness assessments focused on attack paths from internet-facing components into operational CPS that underpin AI infrastructure.
RealGround Analysis
This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://www.securityweek.com/1-in-5-data-center-assets-are-within-easy-reach-of-attackers/
