Was An IPMI Flaw Behind 300Gbps DDoS Attack? – ComputerworldUK.com
ID: d886e0a7-408e-5a73-a238-f425d585156c
STIX ID: report--d886e0a7-408e-5a73-a238-f425d585156c
Feed Name: Security Ledger
Threat Score
A massive 300 Gbps DDoS campaign in June targeted a media-sector CDN by exploiting a Supermicro IPMI/BMC vulnerability that exposed plaintext PSBlock passwords on port 49152, enabling attackers to automate credential harvesting and recruit an estimated 100,000 unpatched servers into a botnet; Verisign mitigated the impact by balancing traffic across its global network and Supermicro issued firmware patches, though many devices remained unpatched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
