A worrying Dell zero-day flaw has reportedly gone unpatched for nearly two years – and Chinese hackers are taking advantage



  • Dell patched critical flaw in RecoverPoint for Virtual Machines caused by hardcoded credentials
  • Exploited as a zero-day since mid-2024 by Chinese state-sponsored group UNC6201
  • Attackers deployed new Grimbolt backdoor and used novel “Ghost NICs” technique for stealth and lateral movement

Chinese state-sponsored threat actors have been abusing a rather embarrassing vulnerability in a Dell product for nearly two years, experts have claimed.

In a security advisory, Dell said its RecoverPoint for Virtual Machines contained a hardcoded credential flaw.


https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1920-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img