Chinese APT Group Exploits Dell Zero-Day for Two Years
ID: edb0c5e7-7b77-597e-aca2-258ba3994497
STIX ID: report--edb0c5e7-7b77-597e-aca2-258ba3994497
Feed Name: Infosecurity Magazine (News)
Dell patched a critical zero-day (CVE-2026-22769) in RecoverPoint for Virtual Machines— a hardcoded-credential issue with a CVSS score of 10.0—after Mandiant reported that UNC6201 (a suspected PRC-linked threat cluster) had been exploiting it since mid-2024 to gain root access, maintain persistence, move laterally, and deploy backdoors and other malware (Grimbolt, Brickstorm, Slaystyle); the report also describes novel TTPs targeting VMware environments (ghost NICs) and use of iptables for single-packet authorization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
