Infrastructure Security Vulnerabilities and Memory Supply Crisis in the AI Era
인프라/플랫폼 | Sat Aug 08 2026 00:00:00 GMT+0000 (Coordinated Universal Time) | 3 sources
Server BMC vulnerabilities, water utility PLC hacks, and 2027 memory supply sellouts reveal risks across AI infrastructure.
Analysis
[runZero] disclosed large-scale server motherboard BMC vulnerabilities [1]
- Over 12 new vulnerabilities discovered in BMC
- the small computer used for remote server management
- Impacts products from major manufacturers including HPE
- Supermicro
- Avocent
- Huawei
- Lenovo
- and Dell
- Over 54% of 86
- 000 internet-exposed BMCs contain critical vulnerabilities
- CVE-2013-4786
- discovered in 2013
- still exists on 75
- 000 devices
[Paul Nakasone (former NSA Director)] warned about internet exposure risks of US water utility PLCs [2]
- At least 12 state water systems have been hacked
- allegedly by Iran
- Emphasized that PLCs should not be connected to the internet
- 50
- 000 water municipalities across the US form a broad attack surface
- Open source-based defense platforms such as Project Chimera are under development
[Samsung, SK Hynix, Micron] sold out entire 2027 memory production capacity [3]
- AI companies have absorbed all 2027 DRAM and HBM capacity from the top three memory manufacturers
- Most locked in via 5-year long-term purchase contracts
- pre-ordering yet-to-be-manufactured supply
- NAND storage demand also surging
- driving up SSD prices
- Western Digital SN7100 1TB up 52% from January