A worrying Dell zero-day flaw has reportedly gone unfixed for nearly two years, and Chinese hackers are taking advantage



  • Dell fixed a critical flaw in RecoverPoint for virtual machines caused by encrypted credentials
  • Exploited as zero-day from mid-2024 by Chinese state-sponsored group UNC6201
  • The attackers implemented a new Grimbolt backdoor and used the novel “ghost NIC” technique for stealth and lateral movement.

Experts claim that Chinese state-sponsored threat actors have been abusing a rather embarrassing vulnerability in a Dell product for almost two years.

In a security advisory, Dell said its RecoverPoint for virtual machines contained an encrypted credential flaw.



Leave a Comment

Your email address will not be published. Required fields are marked *