Lots of Internet-exposed server management controllers are subject to offline password-cracking attacks — and adversaries have taken note.

More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.

Lots of Internet-exposed server management controllers are subject to offline password-cracking attacks — and adversaries have taken note.