<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bmc on CuraSec</title><link>https://curasec.metacog.co.kr/tags/bmc/</link><description>Recent content in Bmc on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 28 Jul 2026 13:01:43 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/bmc/index.xml" rel="self" type="application/rss+xml"/><item><title>24,000+ internet-exposed BMCs leaking password hashes via 20-year-old flaw</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-over-24-000-exposed-server-bmcs-leak-password-hash-via-decad/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-over-24-000-exposed-server-bmcs-leak-password-hash-via-decad/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Internet-exposed BMC/IPMI interfaces leaking password hashes represent an immediately exploitable misconfiguration — anyone can harvest and crack those hashes for out-of-band server access. Audit all BMC/IPMI interfaces for internet reachability now and move them behind an OOB management network or VPN; rotate any credentials on exposed units.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs or active campaign are cited, so there is no immediate hunt to launch, but external scanning of IPMI port 623 is trivially cheap for attackers. Build or tune detections for inbound connections to BMC management ports from non-management-network sources.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Twenty-four thousand exposed instances signals a systemic industry hygiene failure; direct engineering to confirm no BMC interfaces in your estate are internet-reachable this quarter, and add management-plane network segmentation to your next control review.&lt;/li>
&lt;/ul></description></item></channel></rss>