Hey #infosec -
Intel AMT has some issues. It's a way of doing out of band management of hardware. Most of you probably don't care about it, but there's going to be some hardware type patches soonish.
In the meantime, set your firewalls to deny port 623, 664, and 16992 - 16995 at your gateways, and set your IDS to look for that traffic originating from any systems other than those specifically authorized.
Or disable AMT entirely.