/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Flaws found in Supermicro motherboards could let hackers remotely mount virtual USB drives; patch issued, but 47,000+ potentially exposed devices found online

Lily Hay Newman / Wired :

Wired Lily Hay Newman

Context & Ripple Effects

This is the third strike in recent years against Supermicro's firmware hygiene. In February, researchers showed weaknesses in its hardware could plant a persistent hidden backdoor on IBM's bare-metal cloud servers, and Bloomberg had already reported a 2015 breach of Supermicro's firmware portal that served malware to customers including Facebook. Now the company is patching a motherboard flaw that lets attackers remotely mount virtual USB drives — with more than 47,000 potentially exposed devices found online.

First-order effects

  • Operators of the 47,000+ internet-facing Supermicro devices must apply the patch urgently, since remote virtual-USB mounting gives an attacker a physical-style injection path into machines they never touch.
  • Cloud providers running Supermicro-based bare-metal offerings — IBM among them, per the February research — now have to audit whether their fleets carry this BMC-level exposure.

Second-order effects

  • The drumbeat of vendor-specific firmware flaws pressures enterprise buyers to demand disclosure-and-patch commitments from server makers, and rivals are shown to share the weakness class: Eclypsium later reported a firmware flaw spanning 271 Gigabyte motherboard models with only partial fixes planned.
  • Each incident compounds reputational cost on top of technical risk — Supermicro was still absorbing the fallout from the portal breach report when this new exposure surfaced.

Third-order effects

  • Motherboard and BMC firmware is consolidating as its own attack surface and audit discipline, distinct from OS patching — following the template Intel set when its firmware flaws forced PC vendors into a mass scramble to patch millions of devices.
  • If firmware flaws keep surfacing at major board vendors, procurement standards and regulators will likely treat firmware provenance and update guarantees as baseline requirements for data-center hardware rather than differentiators.

The trend: Server security is shifting from operating-system defense toward firmware-level accountability, as repeated motherboard vulnerabilities at Supermicro, Gigabyte, and Intel force vendors to own the layer beneath the OS.

Discussion

  • @marypcbuk Mary Branscombe on x
    There's a Supermicro bug. Not *that* Supermicro bug, but there is an actual Supermicro bug. Also don't put your BMC on the Internet, Mrs Worthington https://www.wired.com/...
  • @martinsfp Martin Sfp Bryant on x
    Okay, but what ever happened to that Bloomberg story from last year? Still waiting on a correction, clarification, or additional reporting... https://twitter.com/...
  • @ekovarski Eddie on x
    The BMC should def not be exposed to the Internet. Folks should def do an upgrade. Supermicro should also make the updates easier - it's a hot mess to find proper updates with all of their motherboard permutations. https://twitter.com/...
  • @c7zero Yuriy Bulygin on x
    Malicious USB attacks against servers and remotely. New research by the Eclypsium research team - Presentation: https://github.com/... [PDF] - POC video: https://www.youtube.com/... - Details and tools: https://github.com/... #USBAnywhere #BadUSB https://twitter.com/...
  • @wired @wired on x
    You probably know better than to plug a strange USB stick into a network computer. But there are flaws in certain devices that an attacker could exploit to plug in all the “virtual” thumb drives they want. https://www.wired.com/...
  • @abazhaniuk Alex Bazhaniuk on x
    Critical vulnerabilities in Virtual Media SW stack in Supermicro BMC (X9-X11) opens servers to remote attack. 47k servers with their BMCs exposed to the Internet and using the relevant protocol.Details at @osfc_io https://osfc.io/... Great job @kc8apf https://eclypsium.com/... ht…
  • @campuscodi Catalin Cimpanu on x
    Props to Supermicro for patching this without making a ruckus. Vendor worked with Eclypsium to verify patches and all (both told me via email) Eclypsium's technical paper on the matter is here: https://eclypsium.com/... https://twitter.com/...