What is a BMC vulnerability, and why it puts thousands of servers at risk

Nearly every enterprise server's motherboard hosts a small auxiliary computer that operates independently of the main processor and operating system: the baseboard management controller, or BMC. This chip lets technicians remotely restart, monitor and service hardware even when the server is completely powered off.
Security researchers have found serious vulnerabilities in the firmware of several widely used BMC manufacturers' products. The flaws allow attackers to bypass authentication and gain full control of the BMC, then use that foothold to reach the rest of the server.
The core reason BMCs are dangerous is their position in the privilege hierarchy — above even the operating system. When an attacker compromises a BMC, malware can persist on the server even after the operating system is reinstalled, because the BMC operates in memory and storage entirely separate from the OS.
Researchers stress that this kind of attack is extremely difficult to detect. Standard antivirus software and security monitoring tools cannot reach the BMC layer, meaning malware can go unnoticed for months or even years.
In an attack scenario, once an attacker gains network access to the BMC, they can alter the server's hardware-level behavior, steal data or render the machine entirely unusable. Cloud providers and large data centers are especially vulnerable to this kind of flaw, since it can affect thousands of servers simultaneously.
Security experts say the root of the problem is that BMC firmware is often left running unpatched for years. Many organizations configure BMC software once during server setup and never update it again.
Affected manufacturers have released patches closing the flaw, but researchers note that the patching process is often slow, since BMC updates can require briefly powering down the server — creating operational friction for systems that need to run continuously.
Experts recommend that organizations completely isolate BMC interfaces from the public internet, allowing access only through trusted management networks. They also advise changing default passwords and regularly auditing BMC logs.
This kind of hardware-level vulnerability is drawing increasing attacker interest compared with software flaws, researchers note, because detection risk is lower and the impact can be far more persistent. Researchers expect this trend to grow in attacks targeting large-scale data centers in coming years.
The security community says the findings serve as another reminder that hardware supply-chain security must be taken as seriously as software security — since even the strongest software defenses can fall short when the hardware layer beneath them is not secure.
Read next

You can now turn off Google Gemini's visible AI watermarks. Here is what that actually changes
Google now lets users toggle off the visible watermark that normally appears on images, videos and music generated with Gemini and its Nano Banana and Omni models. The invisible SynthID watermark and embedded metadata remain in place regardless, meaning the content stays technically traceable as AI-generated even when it no longer looks that way.

A screen-sharing flaw is letting attackers take full control of Macs. Here is what to know
Security researchers have confirmed active exploitation of a vulnerability that lets remote attackers log into Macs without a password through a flaw in the screen-sharing feature. Here is how the exploit works, which systems are exposed, and the steps Mac users should take while a patch is developed.

OpenAI and Anthropic cut prices as Chinese AI rivals gain ground
OpenAI and Anthropic have both released cheaper models in recent weeks, a shift analysts attribute to intensifying competition from Chinese AI labs offering comparable performance at a fraction of the cost. The pricing pressure marks a notable change for two companies that have spent years competing primarily on capability rather than cost.

What we know about the alleged Iranian hacks on US water utilities
Over the past several weeks, hackers have broken into the industrial control systems of multiple US water utilities in an operation researchers attribute to actors linked to the Iranian government. Here is what has been confirmed about the intrusions, the vulnerable equipment involved, and why water infrastructure keeps turning up as a target.

Self-driving trucks are now testing on California highways: what the new permits actually allow
Aurora Innovation and Kodiak AI have received permits from the California Department of Motor Vehicles to test self-driving trucks on the state's highways, a milestone for an industry that has struggled to gain regulatory footing in one of the country's largest freight markets. Here is what the permits do and do not allow.