• Home
    • What is
    • Computer security
      • Windows security
      • Mac security
      • Linux security
    • Mobile security
      • Android security
      • iOS Security
    • Data security
    • SCCM
    • Reviews
      • Case studies
    • Advertise
    • Contact
      • Privacy Policy
  • Subscribe now

    Loading
  • Home
  • What is
  • Computer security
    • Windows security
    • Mac security
    • Linux security
  • Mobile security
    • Android security
    • iOS Security
  • Data security
  • SCCM
  • Reviews
    • Case studies
  • Advertise
  • Contact
    • Privacy Policy
Home » Breaking Computer security Cyber Security data security Device security Intruders Latest Cybersecurity News Linux security Mac security Windows security

More than 20,000 data centers and ILO are exposed to threat actors

John Greenwood Posted On January 29, 2022
0



data centers

Security researchers at Cyble have identified more than 20,000 instances of data centers that are exposed publicly and could cause catastrophic results if breached by hackers. These data centers are monitoring power distribution centers, HVAC control units, devices and more, which why the breach will be devastating.

These data centers should have strong safety regulations to manage fire breakout, storms, physical security and electric failure. Since most of these data centers aren’t managed staff hence their configurations aren’t up-to-date which is why optimal physical protection and performance aren’t enough to keep them secured.

Unprotected data centers is concerning

Cyble researchers have managed to find 20,000 instances of publicly exposed data centers including the ones that has thermal and cooling dashboards, rack monitors, UPS controllers, humidity controllers and transfer switches. Also, the Cyble team were able to crack and extract passwords of the dashboards which they later used to breach the actual database instances.

It also provides full remote access to the data center with status reports, and also the ability to configure various system parameters. Default passwords which are even easier to breach and can be overridden by hackers without any challenges is also a major concern.

data centers
Source: Cyble

Effects of unsecured data centers

After proper investigation the Cyble team figured out that anybody will be able to modify the temperature and humidity settings, alter the voltage parameters to unbearable levels, change or disable cooling units configurations, shutdown UPS devices, alter backup schedules and create fake alarms.

data centers
Source: Cyble

These modifications or privileges can cause data loss, system breakage, economic impact, financial loss and reputation damage for organizations associated with those data centers.

It is also to be noted that hackers can compromise these data centers, extract data and use it for their own benefits in complete stealth thus keeping the breach absolute silent. A similar incident was seen in March 2021 at Strasbourg when a power failure interrupted the data centers operation and caused security concerns.

Not just data centers the ILO also needs proper protection

Furthermore, security researcher and a ISC Handler Jan Kopriva have found around 20,000 servers with ILO management interfaces that are exposed to public. The integrated Lights-Out (ILO) management interfaces are used by administration for remote access, manage power settings, shutdown or reboot the systems as if they are present before them in real time.

When these ILO’s aren’t secured properly, it will allow threat actors to take complete access of the servers and modify the configurations as per their need. Thus it is important for these data centers to secured both DCIM and their ILO before threat actors take advantage of the same.

The Cyble team has reported the same to CERT and shared the list of publicly exposed DCIM.

Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, Instagram, Twitter and Reddit.

You can reach out to us via Twitter or Facebook, for any advertising requests.

Share the article with your friends


20000 data centersdata center breachdata centersdata centers securitysecuring data centers


Author

John Greenwood

He has been working with Cybersec and Infosec market for 12+ years now. Passionate about AI, Cybersecurity, Info security, Blockchain and Machine Learning. When he is not occupied with cybersecurity, he likes to go on bike rides!

Leave A Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • Subscribe to our newsletter

    Loading
  • Windows security

    • Top 9 Best Log Management Tools for 2025
      September 20, 2025
    • Top 4 Remote Support Tools for 2025- Best Remote Support...
      September 18, 2025
    • Top 5 Best Unified Endpoint Management (UEM) Software...
      September 12, 2025
    • Top 5 Threat Intelligence Tools For 2025
      July 25, 2025
    • Top 5 Best Microsoft Intune Alternatives to Consider...
      July 23, 2025


  • About us

    Our vision is to deliver the trending and happening cyber events to the enthusiasts.

    We believe in delivering educational and quality content for hassle-free understanding of the subject.

  • Subscribe to our newsletter

    Loading
  • Follow us

  • Advertise with us

    You can reach us via Facebook, Linkedin, or Twitter for advertising purposes.


© The Cybersecurity Times 2022. All rights reserved.
Press enter/return to begin your search