• About
  • Advertise
  • Privacy & Policy
  • Contact
Vidianews
  • Home
  • Entertainment
    • All
    • Gaming
    • Movie
    steam-players-have-24-hours-to-claim-and-keep-a-classic-free-game

    Steam players have 24 hours to claim and keep a classic free game

    J.

    vc-guy-‘shocked-and-sad’-to-know-how-much-players-hate-ai

    VC Guy ‘Shocked And Sad’ To Know How Much Players Hate AI

    how-britney-spears-contributed-to-the-success-of-‘how-i-met-your-mother’

    How Britney Spears contributed to the success of ‘How I Met Your Mother’

    gene-hackman’s-friends-fight-back-after-bombshell-liza-minnelli-memoir

    Gene Hackman’s Friends Fight Back After Bombshell Liza Minnelli Memoir

    eric-dane’s-ex-girlfriend-priya-jain-says-she’s-still-waiting-for-him-to-die

    Eric Dane’s ex-girlfriend Priya Jain says she’s still waiting for him to die

  • Sports
  • Tech
    • All
    • Gadget
    • Startup
    us-military-announces-anduril-contract-worth-up-to-$20-billion-|-techcrunch

    US military announces Anduril contract worth up to $20 billion | TechCrunch

    i-tested-the-small-russell-hobbs-coffee-maker-which-uses-grounds-or-nespresso-pods-–-but-discovered-an-infuriating-drawback

    I tested the small Russell Hobbs coffee maker which uses grounds or Nespresso pods – but discovered an infuriating drawback

    spotify-was-the-“highest-paid-retailer”-in-the-world-in-2025-–-but-i-think-it-should-start-investing-in-these-3-areas-if-it-wants-to-repair-the-cracks-in-its-reputation.

    Spotify was the “highest paid retailer” in the world in 2025 – but I think it should start investing in these 3 areas if it wants to repair the cracks in its reputation.

    iPhone Fold: launch date, price, huge battery and everything we know

    8 Tips, Answers & Help from Today’s NYT Strands for March 15 #742 – CNET

    nyt-strands-today-–-my-advice-and-answers-for-march-15-(#742)

    NYT Strands today – my advice and answers for March 15 (#742)

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Lifestyle
    • All
    • Faith
    • Health
    • Travel
    encouragement-for-the-mom-who-needs-a-sweet-friend

    Encouragement for the mom who needs a sweet friend

    from-saying-yes-to-everything-to-selective-living-with-kornelija-collins

    From Saying Yes to Everything to Selective Living with Kornelija Collins

    how-to-design-a-guest-bedroom-so-everyone-feels-at-home

    How to design a guest bedroom so everyone feels at home

    15-beautiful-abstract-summer-nail-design-ideas-to-copy

    15 Beautiful Abstract Summer Nail Design Ideas to Copy

    the-anti-route-safari

    The anti-route safari

    6-things-to-know-about-the-stryker-cyberattack-–-medcity-news

    6 things to know about the Stryker cyberattack – MedCity News

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • News
    • All
    • Business
    • Science
    spring-break-flyers-warn-of-massive-tsa-lines-as-closure-drains-airport-staff

    Spring Break Flyers Warn Of Massive TSA Lines As Closure Drains Airport Staff

    Iranian strikes and Hezbollah rockets make normal life in Israel ‘simply impossible’

    doj-to-appeal-block-on-fed-subpoenas-in-jerome-powell-criminal-investigation

    DOJ to appeal block on Fed subpoenas in Jerome Powell criminal investigation

    trump-says-iran-ready-to-negotiate-ceasefire,-but-not-ready-to-make-deal

    Trump says Iran ready to negotiate ceasefire, but not ready to make deal

    chess:-the-content-creators-who-are-bringing-the-ancient-game-into-the-digital-age.

    Chess: the content creators who are bringing the ancient game into the digital age.

    ‘horrible’-war-bets-fuel-calls-for-crackdown-on-kalshi-polymarket

    ‘Horrible’ war bets fuel calls for crackdown on Kalshi polymarket

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Business
  • Politics
  • World
  • Review

    MacBook Neo teardown suggests it could be Apple’s most repairable laptop in several years

    Why I’m bullish on Ether for 2022

    Apple’s foldable model expected to launch as ‘iPhone Ultra’; Leaked price and memory configurations

    Why I’m optimistic about Terra for 2022

    iPhone Fold would feature an iPad-style UI and support split-screen apps

    Why I’m bullish on Polkadot for 2022

No Result
View All Result
  • Home
  • Entertainment
    • All
    • Gaming
    • Movie
    steam-players-have-24-hours-to-claim-and-keep-a-classic-free-game

    Steam players have 24 hours to claim and keep a classic free game

    J.

    vc-guy-‘shocked-and-sad’-to-know-how-much-players-hate-ai

    VC Guy ‘Shocked And Sad’ To Know How Much Players Hate AI

    how-britney-spears-contributed-to-the-success-of-‘how-i-met-your-mother’

    How Britney Spears contributed to the success of ‘How I Met Your Mother’

    gene-hackman’s-friends-fight-back-after-bombshell-liza-minnelli-memoir

    Gene Hackman’s Friends Fight Back After Bombshell Liza Minnelli Memoir

    eric-dane’s-ex-girlfriend-priya-jain-says-she’s-still-waiting-for-him-to-die

    Eric Dane’s ex-girlfriend Priya Jain says she’s still waiting for him to die

  • Sports
  • Tech
    • All
    • Gadget
    • Startup
    us-military-announces-anduril-contract-worth-up-to-$20-billion-|-techcrunch

    US military announces Anduril contract worth up to $20 billion | TechCrunch

    i-tested-the-small-russell-hobbs-coffee-maker-which-uses-grounds-or-nespresso-pods-–-but-discovered-an-infuriating-drawback

    I tested the small Russell Hobbs coffee maker which uses grounds or Nespresso pods – but discovered an infuriating drawback

    spotify-was-the-“highest-paid-retailer”-in-the-world-in-2025-–-but-i-think-it-should-start-investing-in-these-3-areas-if-it-wants-to-repair-the-cracks-in-its-reputation.

    Spotify was the “highest paid retailer” in the world in 2025 – but I think it should start investing in these 3 areas if it wants to repair the cracks in its reputation.

    iPhone Fold: launch date, price, huge battery and everything we know

    8 Tips, Answers & Help from Today’s NYT Strands for March 15 #742 – CNET

    nyt-strands-today-–-my-advice-and-answers-for-march-15-(#742)

    NYT Strands today – my advice and answers for March 15 (#742)

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Lifestyle
    • All
    • Faith
    • Health
    • Travel
    encouragement-for-the-mom-who-needs-a-sweet-friend

    Encouragement for the mom who needs a sweet friend

    from-saying-yes-to-everything-to-selective-living-with-kornelija-collins

    From Saying Yes to Everything to Selective Living with Kornelija Collins

    how-to-design-a-guest-bedroom-so-everyone-feels-at-home

    How to design a guest bedroom so everyone feels at home

    15-beautiful-abstract-summer-nail-design-ideas-to-copy

    15 Beautiful Abstract Summer Nail Design Ideas to Copy

    the-anti-route-safari

    The anti-route safari

    6-things-to-know-about-the-stryker-cyberattack-–-medcity-news

    6 things to know about the Stryker cyberattack – MedCity News

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • News
    • All
    • Business
    • Science
    spring-break-flyers-warn-of-massive-tsa-lines-as-closure-drains-airport-staff

    Spring Break Flyers Warn Of Massive TSA Lines As Closure Drains Airport Staff

    Iranian strikes and Hezbollah rockets make normal life in Israel ‘simply impossible’

    doj-to-appeal-block-on-fed-subpoenas-in-jerome-powell-criminal-investigation

    DOJ to appeal block on Fed subpoenas in Jerome Powell criminal investigation

    trump-says-iran-ready-to-negotiate-ceasefire,-but-not-ready-to-make-deal

    Trump says Iran ready to negotiate ceasefire, but not ready to make deal

    chess:-the-content-creators-who-are-bringing-the-ancient-game-into-the-digital-age.

    Chess: the content creators who are bringing the ancient game into the digital age.

    ‘horrible’-war-bets-fuel-calls-for-crackdown-on-kalshi-polymarket

    ‘Horrible’ war bets fuel calls for crackdown on Kalshi polymarket

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Business
  • Politics
  • World
  • Review

    MacBook Neo teardown suggests it could be Apple’s most repairable laptop in several years

    Why I’m bullish on Ether for 2022

    Apple’s foldable model expected to launch as ‘iPhone Ultra’; Leaked price and memory configurations

    Why I’m optimistic about Terra for 2022

    iPhone Fold would feature an iPad-style UI and support split-screen apps

    Why I’m bullish on Polkadot for 2022

No Result
View All Result
Vidianews
No Result
View All Result
Home Tech

Worrying Zero Day Flaw at Dell Reportedly Unpatched for Years

Ivan Mehta by Ivan Mehta
February 18, 2026
in Tech
0
worrying-zero-day-flaw-at-dell-reportedly-unpatched-for-years

Worrying Zero Day Flaw at Dell Reportedly Unpatched for Years

0
SHARES
0
VIEWS
Share on FacebookShare on Twitter
A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all dressed in black with hoods pulled up over their heads. You can't see their faces. The hacker in the foreground is sitting with an open laptop in front of him. The background, behind the hackers, is a Chinese flag
(Image credit: Getty Images)

  • Dell fixed a critical flaw in RecoverPoint for Virtual Machines caused by hardcoded credentials
  • Operated as a zero-day since mid-2024 by the Chinese state-sponsored UNC6201 group
  • The attackers deployed a new Grimbolt backdoor and used a new “ghost network cards” technique for stealth and lateral movement.

Chinese state-sponsored threat actors have been exploiting a rather embarrassing vulnerability in a Dell product for nearly two years, experts have claimed.

In a security advisory, Dell said its RecoverPoint for Virtual Machines contained a hardcoded credential flaw.

RecoverPoint for Virtual Machines (RP4VM) is a data protection and disaster recovery solution designed for virtualized environments, primarily VMware vSphere and Microsoft Hyper-V. When building it, a developer left login information in the code, presumably so they could quickly log in and test the product.

Limited active exploitation

Usually, developers would go through the code before shipping the product and remove all traces of the hardcoded credentials. However, they are sometimes forgotten or left unattended, leaving a gaping hole for cybercriminals to exploit.

Now, Dell claims that all versions prior to 6.0.3.1 HF1 contained hardcoded credentials – a critical vulnerability because “an unauthenticated, remote attacker with knowledge of hardcoded credentials could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence.”

To make matters worse, security researchers from Google and Mandiant warned Dell against “limited active exploitation” of the flaw. Both companies say the bug had been exploited, as a zero-day, since mid-2024, meaning they had been using it for more than a year and a half.

The group apparently exploiting this bug is identified as UNC6201. They are not a widely recognized group, like APT41 or Silk Typhoon, but they are just as dangerous. In fact, researchers said the group deployed several malware payloads, including a brand new backdoor called Grimbolt, built in C# using a new compilation technique that made reverse engineering faster and more difficult than its previous tools.

Sign up for the TechRadar Pro newsletter to get all the top news, opinions, features and tips your business needs to succeed!

The researchers also said that UNC6201 used new lateral movement and stealth techniques:

“UNC6201 uses temporary virtual network ports (aka “ghost NICs”) to transition compromised virtual machines to internal or SaaS environments, a new technique that Mandiant has not previously observed in its investigations,” Mandiant said. BeepComputer. “In line with the previous BRICKSTORM campaign, UNC6201 continues to target devices that typically lack traditional Endpoint Detection and Response (EDR) agents to remain undetected for extended periods of time. »

Via BeepComputer


Best Antivirus Software

Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds. Make sure to click the Follow button!

And of course you can too follow TechRadar on TikTok for news, reviews, unboxings in video form and receive regular updates from us on WhatsApp Also.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). During his career, which spans more than a decade, he has written for numerous media outlets, including Al Jazeera Balkans. He has also hosted several modules on content writing for Represent Communications.

Related
Ivan Mehta

Ivan Mehta

Stay Connected

  • 99 Subscribers
  • Trending
  • Comments
  • Latest
european-markets-in-mixed-territory-after-a-positive-start

European markets in mixed territory after a positive start

January 26, 2026
nascar-driver-denny-hamlin-breaks-silence-after-father-dies-in-house-fire

NASCAR driver Denny Hamlin breaks silence after father dies in house fire

December 31, 2025
fivio-foreign-checks-himself-into-a-$10,000-rehab-center-to-get-his-mind-straight

Fivio Foreign checks himself into a $10,000 rehab center to get his mind straight

December 31, 2025
tcl-lost-a-lawsuit-claiming-its-qled-tvs-are-not

TCL lost a lawsuit claiming its QLED TVs are not

March 13, 2026
hansmaker-presents-the-d1-ultra:-a-dual-laser-engraver-designed-for-each-material-–-techenger

Hansmaker presents the D1 Ultra: a dual laser engraver designed for each material – Techenger

0
nascar-driver-denny-hamlin-breaks-silence-after-father-dies-in-house-fire

NASCAR driver Denny Hamlin breaks silence after father dies in house fire

0
fivio-foreign-checks-himself-into-a-$10,000-rehab-center-to-get-his-mind-straight

Fivio Foreign checks himself into a $10,000 rehab center to get his mind straight

0
david-beckham-leaves-brooklyn-for-his-2025-instagram-tribute-amid-family-feud

David Beckham leaves Brooklyn for his 2025 Instagram tribute amid family feud

0
table,-schedule-and-standings-for-the-2026-world-baseball-classic

Table, schedule and standings for the 2026 World Baseball Classic

March 15, 2026
spring-break-flyers-warn-of-massive-tsa-lines-as-closure-drains-airport-staff

Spring Break Flyers Warn Of Massive TSA Lines As Closure Drains Airport Staff

March 15, 2026
this-dhs-official-oversees-federal-election-security-he-wants-to-ban-voting-machines.

This DHS official oversees federal election security. He wants to ban voting machines.

March 15, 2026
steam-players-have-24-hours-to-claim-and-keep-a-classic-free-game

Steam players have 24 hours to claim and keep a classic free game

March 15, 2026

Recent News

table,-schedule-and-standings-for-the-2026-world-baseball-classic

Table, schedule and standings for the 2026 World Baseball Classic

March 15, 2026
spring-break-flyers-warn-of-massive-tsa-lines-as-closure-drains-airport-staff

Spring Break Flyers Warn Of Massive TSA Lines As Closure Drains Airport Staff

March 15, 2026
this-dhs-official-oversees-federal-election-security-he-wants-to-ban-voting-machines.

This DHS official oversees federal election security. He wants to ban voting machines.

March 15, 2026
steam-players-have-24-hours-to-claim-and-keep-a-classic-free-game

Steam players have 24 hours to claim and keep a classic free game

March 15, 2026
Vidianews

Trusted news coverage delivering accurate reporting, breaking headlines, and insightful analysis on global events, business, politics, and tech.

Follow Us

Browse by Category

  • Business
  • Entertainment
  • Faith
  • Gadget
  • Gaming
  • General
  • Health
  • Lifestyle
  • Movie
  • News
  • Politics
  • Review
  • Science
  • Sports
  • Startup
  • Tech
  • Travel
  • World

Recent News

table,-schedule-and-standings-for-the-2026-world-baseball-classic

Table, schedule and standings for the 2026 World Baseball Classic

March 15, 2026
spring-break-flyers-warn-of-massive-tsa-lines-as-closure-drains-airport-staff

Spring Break Flyers Warn Of Massive TSA Lines As Closure Drains Airport Staff

March 15, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© © Copyrights 2026 Vidianews. All Rights Reserved. Designed by Vidianews

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result

© © Copyrights 2026 Vidianews. All Rights Reserved. Designed by Vidianews

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
Go to mobile version