:

24,000 EXPOSED SERVERS LEAK PASSWORD HASHES VIA 20-YEAR-OLD BMC FLAW

INDUSTRY DESK1 MIN READ
TUE, JUL 28, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Over 24,000 internet-exposed servers are leaking authentication password hashes through a two-decade-old vulnerability in their Baseboard Management Controller (BMC) interfaces. The flaw allows attackers to extract credentials remotely without authentication.

Baseboard Management Controllers are out-of-band management interfaces that let administrators access servers remotely, even when the main operating system is offline. The vulnerability affects multiple BMC implementations and has persisted unpatched for approximately 20 years. Exposed BMC interfaces are particularly dangerous because they operate independently of standard server security measures. Attackers scanning for vulnerable devices can extract password hashes and potentially crack them to gain administrative access to critical infrastructure. The widespread exposure suggests many organizations have failed to restrict BMC access to trusted networks or change default credentials. Security researchers recommend immediately inventorying BMC devices, restricting network access to administrative ranges only, and applying available patches. Organizations should treat BMC security as critical infrastructure protection rather than an afterthought, given attackers' ability to bypass standard server defenses through these interfaces.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

OpenAI inadvertently launched a denial-of-service attack against Hugging Face, the popular machine learning platform. The incident has prompted questions about AI infrastructure security and unintended consequences of large-scale operations.

9H AGOAI Desk

Framework's customer database was compromised in a data breach, though payment information was not exposed. The company has disclosed the incident to affected users.

10H AGODev Desk

Security researchers have identified potential hardware backdoors in certain x86 processors. The findings, detailed in a GitHub repository called Rosenbridge, reveal vulnerabilities at the processor level that could allow unauthorized access.

13H AGOIndustry Desk

Flock Safety, the traffic camera company, is expanding beyond law enforcement with plans to deploy dashcams in rideshare vehicles and offer coaching services to police departments.

13H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.