• About
  • Advertise
  • Privacy & Policy
  • Contact
Vidianews
  • Home
  • Entertainment
    • All
    • Gaming
    • Movie
    gemini-can-now-leverage-your-google-data-to-personalize-the-images-it-generates

    Gemini can now leverage your Google data to personalize the images it generates

    joseph-duggar’s-in-laws-break-silence-on-‘traumatic’-allegations

    Joseph Duggar’s in-laws break silence on ‘traumatic’ allegations

    prince-harry-drops-royal-bomb-in-australia-in-reference-to-his-mother’s-death

    Prince Harry drops royal bomb in Australia in reference to his mother’s death

    brian-hooker’s-yacht-‘soulmate’-docked-in-bahamas-as-he-leaves-to-see-sick-mother

    Brian Hooker’s yacht ‘Soulmate’ docked in Bahamas as he leaves to see sick mother

    tiger-woods-cites-privacy-in-fight-against-prescription-records-subpoena

    Tiger Woods cites privacy in fight against prescription records subpoena

    beef-season-2-review:-anxiety-is-the-latest-obsession-in-netflix’s-angry-thriller

    Beef Season 2 Review: Anxiety Is the Latest Obsession in Netflix’s Angry Thriller

  • Sports
  • Tech
    • All
    • Gadget
    • Startup
    former-playstation-exec-suggests-xbox-can-do-it

    Former PlayStation exec suggests Xbox can do it

    i

    I

    Character.AI will use AI to let you play a character in your favorite book

    Should you buy an auto-empty robot vacuum? The answer is not so simple

    congress-increases-pressure-on-dhs-over-palantir’s-role-in-immigration-crackdown

    Congress increases pressure on DHS over Palantir’s role in immigration crackdown

    hightouch-achieves-$100m-arr-with-ai-powered-marketing-tools-|-techcrunch

    Hightouch Achieves $100M ARR With AI-Powered Marketing Tools | TechCrunch

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Lifestyle
    • All
    • Faith
    • Health
    • Travel
    new-bill-aims-to-reduce-direct-drug-costs-–-medcity-news

    New bill aims to reduce direct drug costs – MedCity News

    april-2026-scripture-writing-challenge

    April 2026 Scripture Writing Challenge

    7-“healthy”-habits-that-could-be-why-you’re-always-tired

    7 “Healthy” Habits That Could Be Why You’re Always Tired

    should-chocolate-syrup-be-refrigerated?-|-live-better

    Should Chocolate Syrup Be Refrigerated? | Live Better

    the-new-cultural-luxury:-art,-design-and-creators-take-precedence-over-attractions-in-new-zealand

    The new cultural luxury: art, design and creators take precedence over attractions in New Zealand

    heartflow-clearly-sues-cardiac-ai-rival-over-alleged-intellectual-property-theft-–-medcity-news

    Heartflow clearly sues cardiac AI rival over alleged intellectual property theft – MedCity News

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • News
    • All
    • Business
    • Science
    mortgage-rates-fall-as-iran-ceasefire-eases-market-tensions

    Mortgage Rates Fall As Iran Ceasefire Eases Market Tensions

    More than a dozen killed in Russian attacks on Kyiv and other Ukrainian cities

    the-british-economy-grew-by-05%-in-february,-far-exceeding-economists’-expectations.

    The British economy grew by 0.5% in February, far exceeding economists’ expectations.

    480 ducks rescued for adoption in California

    daniel-duggan:-australian-citizen-and-former-us-navy-pilot-loses-extradition-appeal

    Daniel Duggan: Australian citizen and former US Navy pilot loses extradition appeal

    Trump threatens to fire Fed Chairman Powell if he doesn’t leave in May

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Business
  • Politics
  • World
  • Review

    iPhone 13, iPhone 13 Pro: the best new reasons to buy an iPhone 12?

    iPhone Fold Reportedly Facing Production Delay, Limited Availability Expected at Launch

    How to choose good cryptos? Understanding Cryptocurrency Investing

    Amazon announces acquisition of Globalstar; Partnership with Apple for satellite features on iPhone and Apple Watch

    How not to lose money in crypto

    Apple reportedly testing four distinct frame styles and designs for its smart glasses

No Result
View All Result
  • Home
  • Entertainment
    • All
    • Gaming
    • Movie
    gemini-can-now-leverage-your-google-data-to-personalize-the-images-it-generates

    Gemini can now leverage your Google data to personalize the images it generates

    joseph-duggar’s-in-laws-break-silence-on-‘traumatic’-allegations

    Joseph Duggar’s in-laws break silence on ‘traumatic’ allegations

    prince-harry-drops-royal-bomb-in-australia-in-reference-to-his-mother’s-death

    Prince Harry drops royal bomb in Australia in reference to his mother’s death

    brian-hooker’s-yacht-‘soulmate’-docked-in-bahamas-as-he-leaves-to-see-sick-mother

    Brian Hooker’s yacht ‘Soulmate’ docked in Bahamas as he leaves to see sick mother

    tiger-woods-cites-privacy-in-fight-against-prescription-records-subpoena

    Tiger Woods cites privacy in fight against prescription records subpoena

    beef-season-2-review:-anxiety-is-the-latest-obsession-in-netflix’s-angry-thriller

    Beef Season 2 Review: Anxiety Is the Latest Obsession in Netflix’s Angry Thriller

  • Sports
  • Tech
    • All
    • Gadget
    • Startup
    former-playstation-exec-suggests-xbox-can-do-it

    Former PlayStation exec suggests Xbox can do it

    i

    I

    Character.AI will use AI to let you play a character in your favorite book

    Should you buy an auto-empty robot vacuum? The answer is not so simple

    congress-increases-pressure-on-dhs-over-palantir’s-role-in-immigration-crackdown

    Congress increases pressure on DHS over Palantir’s role in immigration crackdown

    hightouch-achieves-$100m-arr-with-ai-powered-marketing-tools-|-techcrunch

    Hightouch Achieves $100M ARR With AI-Powered Marketing Tools | TechCrunch

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Lifestyle
    • All
    • Faith
    • Health
    • Travel
    new-bill-aims-to-reduce-direct-drug-costs-–-medcity-news

    New bill aims to reduce direct drug costs – MedCity News

    april-2026-scripture-writing-challenge

    April 2026 Scripture Writing Challenge

    7-“healthy”-habits-that-could-be-why-you’re-always-tired

    7 “Healthy” Habits That Could Be Why You’re Always Tired

    should-chocolate-syrup-be-refrigerated?-|-live-better

    Should Chocolate Syrup Be Refrigerated? | Live Better

    the-new-cultural-luxury:-art,-design-and-creators-take-precedence-over-attractions-in-new-zealand

    The new cultural luxury: art, design and creators take precedence over attractions in New Zealand

    heartflow-clearly-sues-cardiac-ai-rival-over-alleged-intellectual-property-theft-–-medcity-news

    Heartflow clearly sues cardiac AI rival over alleged intellectual property theft – MedCity News

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • News
    • All
    • Business
    • Science
    mortgage-rates-fall-as-iran-ceasefire-eases-market-tensions

    Mortgage Rates Fall As Iran Ceasefire Eases Market Tensions

    More than a dozen killed in Russian attacks on Kyiv and other Ukrainian cities

    the-british-economy-grew-by-05%-in-february,-far-exceeding-economists’-expectations.

    The British economy grew by 0.5% in February, far exceeding economists’ expectations.

    480 ducks rescued for adoption in California

    daniel-duggan:-australian-citizen-and-former-us-navy-pilot-loses-extradition-appeal

    Daniel Duggan: Australian citizen and former US Navy pilot loses extradition appeal

    Trump threatens to fire Fed Chairman Powell if he doesn’t leave in May

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Business
  • Politics
  • World
  • Review

    iPhone 13, iPhone 13 Pro: the best new reasons to buy an iPhone 12?

    iPhone Fold Reportedly Facing Production Delay, Limited Availability Expected at Launch

    How to choose good cryptos? Understanding Cryptocurrency Investing

    Amazon announces acquisition of Globalstar; Partnership with Apple for satellite features on iPhone and Apple Watch

    How not to lose money in crypto

    Apple reportedly testing four distinct frame styles and designs for its smart glasses

No Result
View All Result
Vidianews
No Result
View All Result
Home Tech

Worrying Zero Day Flaw at Dell Reportedly Unpatched for Years

Ivan Mehta by Ivan Mehta
February 18, 2026
in Tech
0
worrying-zero-day-flaw-at-dell-reportedly-unpatched-for-years

Worrying Zero Day Flaw at Dell Reportedly Unpatched for Years

0
SHARES
0
VIEWS
Share on FacebookShare on Twitter
A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all dressed in black with hoods pulled up over their heads. You can't see their faces. The hacker in the foreground is sitting with an open laptop in front of him. The background, behind the hackers, is a Chinese flag
(Image credit: Getty Images)

  • Dell fixed a critical flaw in RecoverPoint for Virtual Machines caused by hardcoded credentials
  • Operated as a zero-day since mid-2024 by the Chinese state-sponsored UNC6201 group
  • The attackers deployed a new Grimbolt backdoor and used a new “ghost network cards” technique for stealth and lateral movement.

Chinese state-sponsored threat actors have been exploiting a rather embarrassing vulnerability in a Dell product for nearly two years, experts have claimed.

In a security advisory, Dell said its RecoverPoint for Virtual Machines contained a hardcoded credential flaw.

RecoverPoint for Virtual Machines (RP4VM) is a data protection and disaster recovery solution designed for virtualized environments, primarily VMware vSphere and Microsoft Hyper-V. When building it, a developer left login information in the code, presumably so they could quickly log in and test the product.

Limited active exploitation

Usually, developers would go through the code before shipping the product and remove all traces of the hardcoded credentials. However, they are sometimes forgotten or left unattended, leaving a gaping hole for cybercriminals to exploit.

Now, Dell claims that all versions prior to 6.0.3.1 HF1 contained hardcoded credentials – a critical vulnerability because “an unauthenticated, remote attacker with knowledge of hardcoded credentials could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence.”

To make matters worse, security researchers from Google and Mandiant warned Dell against “limited active exploitation” of the flaw. Both companies say the bug had been exploited, as a zero-day, since mid-2024, meaning they had been using it for more than a year and a half.

The group apparently exploiting this bug is identified as UNC6201. They are not a widely recognized group, like APT41 or Silk Typhoon, but they are just as dangerous. In fact, researchers said the group deployed several malware payloads, including a brand new backdoor called Grimbolt, built in C# using a new compilation technique that made reverse engineering faster and more difficult than its previous tools.

Sign up for the TechRadar Pro newsletter to get all the top news, opinions, features and tips your business needs to succeed!

The researchers also said that UNC6201 used new lateral movement and stealth techniques:

“UNC6201 uses temporary virtual network ports (aka “ghost NICs”) to transition compromised virtual machines to internal or SaaS environments, a new technique that Mandiant has not previously observed in its investigations,” Mandiant said. BeepComputer. “In line with the previous BRICKSTORM campaign, UNC6201 continues to target devices that typically lack traditional Endpoint Detection and Response (EDR) agents to remain undetected for extended periods of time. »

Via BeepComputer


Best Antivirus Software

Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds. Make sure to click the Follow button!

And of course you can too follow TechRadar on TikTok for news, reviews, unboxings in video form and receive regular updates from us on WhatsApp Also.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). During his career, which spans more than a decade, he has written for numerous media outlets, including Al Jazeera Balkans. He has also hosted several modules on content writing for Represent Communications.

Related
Ivan Mehta

Ivan Mehta

Stay Connected

  • 99 Subscribers
  • Trending
  • Comments
  • Latest
european-markets-in-mixed-territory-after-a-positive-start

European markets in mixed territory after a positive start

January 26, 2026
“we-are-on-the-edge-of-a-battlefield”:-reports-bbc-near-the-strait-of-hormuz

“We are on the edge of a battlefield”: reports BBC near the Strait of Hormuz

April 6, 2026
tcl-lost-a-lawsuit-claiming-its-qled-tvs-are-not

TCL lost a lawsuit claiming its QLED TVs are not

March 13, 2026
nascar-driver-denny-hamlin-breaks-silence-after-father-dies-in-house-fire

NASCAR driver Denny Hamlin breaks silence after father dies in house fire

December 31, 2025
hansmaker-presents-the-d1-ultra:-a-dual-laser-engraver-designed-for-each-material-–-techenger

Hansmaker presents the D1 Ultra: a dual laser engraver designed for each material – Techenger

0
nascar-driver-denny-hamlin-breaks-silence-after-father-dies-in-house-fire

NASCAR driver Denny Hamlin breaks silence after father dies in house fire

0
fivio-foreign-checks-himself-into-a-$10,000-rehab-center-to-get-his-mind-straight

Fivio Foreign checks himself into a $10,000 rehab center to get his mind straight

0
david-beckham-leaves-brooklyn-for-his-2025-instagram-tribute-amid-family-feud

David Beckham leaves Brooklyn for his 2025 Instagram tribute amid family feud

0
did-the-mbappe-experiment-fail?-real-madrid’s-trophy-drought-stretches-to-2-years

Did the Mbappé experiment fail? Real Madrid’s trophy drought stretches to 2 years

April 16, 2026
a-strange-‘neutrino-force’-helped-close-a-crack-in-particle-physics

A strange ‘neutrino force’ helped close a crack in particle physics

April 16, 2026
new-measurement-reveals-gravity-is-still-difficult-to-pin-down

New measurement reveals gravity is still difficult to pin down

April 16, 2026
secrets-of-cosmic-evolution-could-be-hidden-in-this-black-hole’s-‘dancing’-jets

Secrets of cosmic evolution could be hidden in this black hole’s ‘dancing’ jets

April 16, 2026

Recent News

did-the-mbappe-experiment-fail?-real-madrid’s-trophy-drought-stretches-to-2-years

Did the Mbappé experiment fail? Real Madrid’s trophy drought stretches to 2 years

April 16, 2026
a-strange-‘neutrino-force’-helped-close-a-crack-in-particle-physics

A strange ‘neutrino force’ helped close a crack in particle physics

April 16, 2026
new-measurement-reveals-gravity-is-still-difficult-to-pin-down

New measurement reveals gravity is still difficult to pin down

April 16, 2026
secrets-of-cosmic-evolution-could-be-hidden-in-this-black-hole’s-‘dancing’-jets

Secrets of cosmic evolution could be hidden in this black hole’s ‘dancing’ jets

April 16, 2026
Vidianews

Trusted news coverage delivering accurate reporting, breaking headlines, and insightful analysis on global events, business, politics, and tech.

Follow Us

Browse by Category

  • Business
  • Entertainment
  • Faith
  • Gadget
  • Gaming
  • General
  • Health
  • Lifestyle
  • Movie
  • News
  • Politics
  • Review
  • Science
  • Sports
  • Startup
  • Tech
  • Travel
  • World

Recent News

did-the-mbappe-experiment-fail?-real-madrid’s-trophy-drought-stretches-to-2-years

Did the Mbappé experiment fail? Real Madrid’s trophy drought stretches to 2 years

April 16, 2026
a-strange-‘neutrino-force’-helped-close-a-crack-in-particle-physics

A strange ‘neutrino force’ helped close a crack in particle physics

April 16, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© © Copyrights 2026 Vidianews. All Rights Reserved. Designed by Vidianews

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result

© © Copyrights 2026 Vidianews. All Rights Reserved. Designed by Vidianews

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
Go to mobile version