This exploit was found within a year of Bloomberg's article being published: https://www.wired.com/story/supermicro-bug-virtual-usb/
Whether or not that was the exploit being referred to by Bloomberg is unknown, but suspicious.
Whether or not that was the exploit being referred to by Bloomberg is unknown, but suspicious.
Perhaps there was a Chinese whispers (no pun intended) style miscommunication and while the original source meant "software component", it became "hardware component" somewhere along. Or the attack was actually developed as proof-of-concept but never applied in the wild. The attack is feasible as other security researchers have shown: