Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.
Deep dive into BMC vulnerabilities affecting server infrastructure, highly relevant for cloud and platform engineers.
Researchers at Black Hat revealed over a dozen new BMC vulnerabilities across HPE, Supermicro, Lenovo, and Dell servers, with external scans finding 86,000 internet-exposed BMCs—54% critically vulnerable. Many devices remain susceptible to CVE-2013-4786, an IPMI 2.0 authentication flaw enabling offline password cracking. The attack surface is pervasive, under-patched, and allows deep persistent access to server fleets.
Dan Goodin — Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. A journalist with more than 25 years experience, he has been chronicling the...