/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers find that weaknesses in Supermicro hardware would let an attacker leave a persistent and hidden backdoor on IBM's cloud “bare-metal” servers

IBM rated the severity “low”, while Eclypsium assigned a 9.3 “critical” CVE 3. Solid work by @ABazhaniuk and team. http://eclypsium.com/... Kenn White / @kennwhite : Researchers at @eclypsium demonstrate persistent implants on IBM SoftLayer via user-accessible unsecured motherboard management controller, survived server reprovisioning to new customers. http://twitter.com/...

Ars Technica Dan Goodin

Context & Ripple Effects

This disclosure lands mid-arc for Supermicro. A year earlier, Bloomberg reported that Supermicro's own firmware portal was breached in 2015, with Facebook among customers who downloaded malware from it. Now Eclypsium shifts the focus from distribution channels to the hardware itself: an unsecured baseboard management controller on Supermicro boards inside IBM's SoftLayer bare-metal cloud can host implants that persist through reprovisioning.

The finding matters because bare-metal clouds sell customers a freshly wiped machine between tenants — and this attack defeats exactly that guarantee. The severity dispute frames it: IBM rates the issue low while Eclypsium scores the CVE 9.3 critical, a gap that itself signals how differently providers and firmware-security researchers weigh BMC exposure.

First-order effects

  • IBM SoftLayer bare-metal customers inherit a tenancy-isolation gap: an attacker who reaches the unsecured management controller can leave an implant that survives the wipe meant to protect the next tenant.
  • IBM and Eclypsium are publicly split on severity — low versus a 9.3 critical score — leaving customers to decide for themselves whether to demand remediation or hardware changes.

Second-order effects

  • Supermicro's BMC surface comes under sustained scrutiny: months later researchers find related motherboard flaws allowing remote virtual USB drives, with 47,000+ potentially exposed devices online (the follow-up disclosure), forcing patching at fleet scale across every vendor building on its boards.
  • Bare-metal cloud rivals must now answer whether their own fleets have the same user-accessible management-controller exposure, since 'freshly provisioned' is only as trustworthy as the BMC wiping it.

Third-order effects

  • If BMC-level persistence proves routine, trust in commodity server hardware shifts toward verifiable firmware provenance — a direction US investigators' claims of tampered Supermicro chips with backdoor code (reported two years later) push further still.
  • Hyperscalers and cloud buyers gain leverage to demand attested, locked-down management controllers from board vendors, making firmware security a procurement requirement rather than a best effort.

The trend: Cloud infrastructure security is expanding from software images down to the motherboard management layer, where one vendor's BMC design decision propagates into every tenant-isolation promise built on top of it.