Critical vulnerabilities in baseboard management controllers (BMCs) — embedded microcontrollers found in virtually every enterprise server motherboard — expose thousands of internet-connected servers to remote backdooring. Security researcher HD Moore, presenting at Black Hat 2026, uncovered over a dozen new flaws affecting BMCs from major manufacturers including HPE, Supermicro, Huawei, Lenovo, and Dell. Some vulnerabilities date back more than a decade and remain unpatched despite prior warnings. BMCs are particularly dangerous targets because they operate independently of the host server, have their own OS and network stack, and provide deep administrative access even when servers are powered off.

2m read timeFrom arstechnica.com
Post cover image
Table of contents
Ars VideoHow The Callisto Protocol's Gameplay Was Perfected Months Before Release
40 Impressions