Fetching from the wire…
Security2026-08-06 · source-backed
Research published August 5 found baseboard management controllers leaking auth hashes prior to login through CVE-2013-4786, rooted in the IPMI 2.0 spec itself. For at least a third of exposed servers, researchers recovered valid passwords using dictionaries and the default-credential patterns printed on factory chassis stickers, Supermicro units with 10-character uppercase passwords and username ADMIN being most common. BMC firmware lives independently of the host OS, so a backdoor written to BMC flash survives a full reinstall. Nothing to do with AI. Still probably the worst thing in today's set.
Each link below shares sources, entities, or timing with this story.
Shared entities / Earlier coverage / Tension
Both cover CVE, Research; earlier CVE coverage from 2026-03-23; pushes against this story (against).
Shared entities / Tension
Both cover August, Still; pushes against this story (against).
Shared entity: CVE / Shared topic / Earlier coverage
Both cover CVE; overlapping topics (admin, backdoor); earlier CVE coverage from 2026-07-20.
Shared entity: CVE / Same source domain / Earlier coverage
Both cover CVE; reported by the same outlet (arstechnica.com); earlier CVE coverage from 2026-07-08.
Shared entity: August / Earlier coverage / Tension
Both cover August; earlier August coverage from 2026-08-05; pushes against this story (against).
Both cover August; earlier August coverage from 2026-08-05; pushes against this story (but).
Both cover August; earlier August coverage from 2026-08-05; pushes against this story (against).
Both cover August; earlier August coverage from 2026-08-05; pushes against this story (but).