HD Moore, founder and CEO of runZero, took the Black Hat USA 2026 briefing on Wednesday 5 August from 3:35 to 4:15 p.m. Pacific at Mandalay Bay. The talk was Lights Out: BMCs Are Still Broken and Now We Have the Receipts. He released OOBscan the same afternoon.
OOBscan is an open-source auditor for IPMI-exposed and other out-of-band management devices. The GitHub repository is named runZeroInc/oobscan. The news for defenders is a talk and a tool. It is not a kit.
Saturday 8 August, 2 to 3 p.m. Pacific, Las Vegas Convention Center, DEF CON 34: Lights Out: Out-of-Band, Out of Mind, Out of Control. Moore expanded on the research. runZero dated its Hacker Summer Camp recap 14 August 2026. The recap names the Black Hat briefing as the defining moment of that week and names OOBscan as the object that went out with it.


A baseboard management controller is a management chip on an enterprise server. It runs dedicated firmware. It keeps a distinct network interface. It stays reachable when the host is off. That is the industrial point of the object, and it is why the category is still called lights-out. The host can be dark. The chip is not. Reboots, firmware work, fleet inventory when the operating system is not answering: those are the jobs the chip was put on the board to do. That sentence is enough. It will not explain how to reach the chip. It will not explain how to talk to it. It will not explain how to break it.
Many of those chips speak IPMI, the Intelligent Platform Management Interface. Architectural issues in that protocol go back to Dan Farmer's 2013 research. That is the history this file is willing to name. It is not willing to teach the bypass. Farmer's paper is thirteen years old on this calendar. The August 2026 talks were an argument that the architectural problem had not left the floor. Named year. Named researcher. Named talks. No walkthrough. Subsequent years produced vendor-specific BMC notes in the ordinary way. runZero's own research note says previous efforts have rarely re-examined core IPMI protocol implementations. File that as the company's claim about the literature. Do not treat a syllabus.
runZero's research note, updated 5 August 2026, is the document used here for the company's language. It says runZero has identified multiple vulnerabilities across major BMC implementations that expose BMC management subsystems to unauthorized control or disruption. Technical details for individual CVEs will be published as coordinated disclosure processes conclude. That sentence is the coordinated-disclosure sentence. It is on the record. It is not filling it in. There will be no list of unpublished identifiers in this file. There will be no attempt to reconstruct a briefing slide. High-level details were the advertised contents of the Black Hat talk and of the DEF CON talk. The altitude stays high-level until the processes conclude.
The implementations named on that note are OpenBMC, Supermicro IPMI, HPE iLO, Dell iDRAC, AMI MegaRAC, Raritan, H3C HDM, and Fujitsu. Those names are a patch list for owners, not a menu. A defender who runs those products already knows the brand on the board. The news is that runZero put those eight names on a public research note dated the same Wednesday as the Black Hat briefing, and that the company is waiting on coordinated disclosure before it publishes technical details for individual CVEs. The wait stands. This report does not pre-write the CVE table. It dates the talks. It names the tool. It names the vendors the company named.
runZero's impact line is dry on purpose. Successful exploitation of these vulnerabilities would allow an attacker to bypass security controls to access, control, or disrupt affected Baseboard Management Controllers, which may enable lateral movement or persistence across managed enterprise infrastructure. The consequence is reprinted. How it was reached is not. The company advises monitoring vendor advisories closely and establishing a formal patching process across all deployed BMC vendors. That is the defender sentence. That is the defender sentence. runZero also said it will detect and flag individual vulnerabilities as disclosure deadlines expire and corresponding CVEs are published. That is a later file. 30 August 2026 is not that later file.
OOBscan, as named at Black Hat and as described by runZero, is an auditor and inventory object for out-of-band management devices. BMCs. IPMI-exposed surfaces. The wider class of lights-out kit that sits beside a host rather than inside its operating system. The purpose, as printed here, is audit and inventory: to see the management chips and the other out-of-band devices that stay on when the host is off. The purpose is named. It will not print usage. It will not print flags. It will not print a command line. It will not tell anyone how to point the auditor at a network. It will not reproduce Moore's demonstration. The repository name is runZeroInc/oobscan. The name is enough. A tool that exists as a named object on a public repository is news. A recipe is not news.
The Black Hat slot is a timetable, not a mood. Wednesday 5 August 2026. 3:35 p.m. Pacific to 4:15 p.m. Pacific. Mandalay Bay. Briefing title Lights Out: BMCs Are Still Broken and Now We Have the Receipts. Featured, according to runZero's 14 August recap, in the official Black Hat press release. Moore detailed his latest research on baseboard management controllers and released OOBscan as an open-source auditor for IPMI-exposed devices. Those are the recap's words, compressed to objects. Talk. Date. Room. Tool. The Bayside Foyer is not the story. The booth, the swag, the quest: those are the company's carnival. The briefing is the news.
The DEF CON slot is the second timetable. Saturday 8 August 2026. 2 p.m. Pacific to 3 p.m. Pacific. Las Vegas Convention Center. Talk title Lights Out: Out-of-Band, Out of Mind, Out of Control. The recap says Moore wrapped the company's Hacker Summer Camp speaking sessions with that talk and expanded on the BMC research. Expanded is the verb. It is not expanded further. A second talk in a second hall is still the same research, given more time, three days after the first. Owners who missed Mandalay Bay on Wednesday had a named hour at the convention centre on Saturday. Owners who missed both still have the research note, the recap, and the named repository. They do not need a lab manual.
Hacker Summer Camp, in the recap's dating, ran from 3 August to 9 August. BSides Las Vegas, Black Hat USA, DEF CON 34. Moore's Lights Out pair sat inside that week. The recap itself is dated 14 August 2026, 8:00 a.m. Eastern, written after the company had gone home. This file is 30 August 2026, a Sunday, sixteen days after the recap and twenty-five days after the Black Hat briefing. The news has not been withdrawn. The coordinated-disclosure sentence has not been replaced by a CVE table. Until that table exists, the honest object on the desk is still the one Moore released on 5 August: OOBscan, an auditor, repository runZeroInc/oobscan.
What this page will not print is as important as what it will. It will not print exploit steps. It will not print a proof of concept. It will not file a payload. It will not file a command line. It will not file a method for scanning a network. It will not file a method for attacking a BMC. It will not file an attack chain. It will not reproduce HD Moore's demonstration from either hall. Newspaper coverage of a talk and a tool release is the assignment. The readers already run fleets. They need the dates, the titles, the vendor names, and the existence of an auditor. They do not need a lesson in becoming the problem the auditor is meant to find.
Lights-out, as a category, is older than this August. Data centres bought the chips so that a dark host could still be reached by the people who own it. Independent of the host operating system. Dedicated firmware. Distinct interface. Reachable when the rack is otherwise quiet. That independence is the feature when the owner is the person on the other end. It is the exposure when the owner has lost the inventory. An auditor for out-of-band management devices is a reply to lost inventory. It is not a glamour object. It is a named tool for a named class of hardware that security programmes have a habit of treating as furniture. Furniture that stays powered when the server is off is not furniture. It is a second computer on the same board. 5 August put a name on a tool that counts those second computers. 8 August said the same thing at DEF CON for an hour. 14 August put both hours in a recap. 30 August is the timetable written down.
Dan Farmer, 2013, remains the historical citation. IPMI had architectural issues then. The August talks argued the category is still broken, and that the receipts now exist as research runZero is feeding through coordinated disclosure rather than through a dump. Receipts, in the Black Hat title, is a word. It is not a packet capture in this file. Owners who want the technical details for individual CVEs will get them when the processes conclude. That is runZero's sentence. Repeating it is enough. Filling it in would be a different job, and the wrong one.
The useful object matters more than the theatrical one. A briefing at Mandalay Bay is theatre until a tool ships. OOBscan shipped. A second briefing at the Las Vegas Convention Center is still theatre until the research note stays up and the disclosure process is named. The research note stayed up. The process is named. Monitor vendor advisories. Patch. Wait for the CVE table. Do not treat a newspaper as a substitute for a vendor bulletin. Do not treat a newspaper as a substitute for an auditor's own documentation. That documentation is not pasted here. It will point at the named repository and stop.
Eight vendor families on the 5 August note. Two talk titles. Two halls. Two clocks. One tool. One recap dated 14 August. One coordinated-disclosure sentence is left incomplete on purpose. That is the inventory of the file. OpenBMC, Supermicro IPMI, HPE iLO, Dell iDRAC, AMI MegaRAC, Raritan, H3C HDM, Fujitsu: if those names are on your boards, the work is the advisory watch and the patch window, not a weekend with a copied demonstration. If those names are not on your boards, the work is still the inventory. Out-of-band devices have a habit of existing in rooms that thought they had counted every computer. BMCs were designed to be the computer that remains when the count says the host is off. That is why the auditor exists. That is why the talks were given. That is why the release is printed and not the method.
By 30 August the week in Las Vegas is over. The title cards have been taken down. The object that remains is OOBscan, an open-source auditor for IPMI-exposed and out-of-band management devices, repository runZeroInc/oobscan, released with Lights Out: BMCs Are Still Broken and Now We Have the Receipts on Wednesday 5 August from 3:35 to 4:15 p.m. Pacific at Mandalay Bay, expanded on Saturday 8 August from 2 to 3 p.m. Pacific at DEF CON 34 in the Las Vegas Convention Center under Lights Out: Out-of-Band, Out of Mind, Out of Control, recapped by runZero on 14 August 2026. Technical details for individual CVEs will be published as coordinated disclosure processes conclude. The next number is those details when they are published. It will not invent them in the meantime. Successful exploitation would let an attacker bypass controls on BMCs. Monitor vendor advisories. Patch. The method stays off the page.

The paper
Comments
No notes on this story yet.
Sign in to comment