logo

ReVault! When your SoC turns against you… deep dive edition

ID: bc9ae395-f8a5-53ed-98ed-4b048dd423b4

STIX ID: report--bc9ae395-f8a5-53ed-98ed-4b048dd423b4

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2025-08-09

Date Updated: 2026-04-27

Author: Philippe Laulheret

...
...

This technical deep-dive documents discovery and exploitation of multiple vulnerabilities in Dell ControlVault3 firmware and host drivers (Broadcom BCM5820X). The researchers reverse-engineered the bootloader and firmware decryption, reported several CVEs, demonstrated arbitrary code execution in firmware, showed how to extract device keys and install malicious firmware implants that can bypass Windows Hello and escalate to SYSTEM on Windows, and discussed detection and mitigation options.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.