Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited Since Mid-2024
ID: b52ffaa1-735c-5eb5-aebf-5a0da120549c
STIX ID: report--b52ffaa1-735c-5eb5-aebf-5a0da120549c
Feed Name: The Hacker News
**Executive Summary:** UNC6201 has been exploiting a critical hard-coded credential vulnerability (CVE-2026-22769, CVSS 10.0) in Dell RecoverPoint for Virtual Machines since mid-2024 to deploy web shells (SLAYSTYLE) and high‑persistence backdoors (BRICKSTORM and the newer GRIMBOLT), using techniques like Tomcat Manager deployment, temporary virtual network interfaces (“Ghost NICs”), and iptables-based traffic redirection; affected versions should be patched to 6.0.3.1 HF1 (or migrated/updated per vendor guidance) and CISA has added the vulnerability to its KEV catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
