Dell's Hard-Coded Flaw: A Nation-State Goldmine
ID: 28e872c2-f56d-5549-9332-7e4453f465b2
STIX ID: report--28e872c2-f56d-5549-9332-7e4453f465b2
Feed Name: Dark Reading
Mandiant and Dell disclosed that China-linked UNC6201 has been exploiting CVE-2026-22769, a CVSS 10 hard-coded admin credential in Dell RecoverPoint for Virtual Machines, to authenticate to Tomcat Manager, upload malicious WAR files, achieve root-level persistence on appliances, pivot to VMware environments, and deploy malware families including Slaystyle, Brickstorm, and a novel AOT-compiled C# backdoor called Grimbolt; Dell urges immediate upgrade or remediation to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
