Intel's ME [out-of-band management of your PC and the data on it] which is embedded in one or more roms on the motherboard
One small ray of hope for non-techie mitigation of IME risk:
For IME access to your PC to be exploited remotely [as opposed to someone who has physical access to your device] probably requires IPv6 routing to be enabled on both your router and PC. It is easy to disable IPv6 on both.
However, that does not prevent "call-home" microcode embedded in your PC from hailing the mothership over IPv4...