
TRC analysis shows attackers exploiting CVE-2026-64892 in Johnson Controls EasyIO Neo controllers to access debug interfaces and harvest building automation credentials. Observed lateral movement across BACnet/Modbus networks targeting HVAC and energy systems. Runtime segmentation helps contain such OT network pivoting. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/johnson-controls-easyio-neo-cve-2026-64892
