Chinese hackers exploited a Dell zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-22769 | Hard-coded credentials in Dell RecoverPoint for Virtual Machines allow root OS access Dell RecoverPoint for Virtual Machines (RP4VMs) versions prior to 6.0.3.1 HF1 contain hard-coded credentials (CWE-798) for the appliance's underlying operating system. An unauthenticated remote attacker who knows the hard-coded credential can authenticate over the network with no user interaction and gain root-level access and persistence on the underlying OS — beyond just the RecoverPoint application — which is why the flaw scores a maximum CVSS of 10.0 with scope changed. Any organization running an affected RP4VMs release is exposed, with risk highest where appliance management interfaces are reachable from broader networks. The vulnerability is confirmed exploited in the wild: it was added to CISA's KEV catalog on 2026-02-18, and reporting indicates China-linked actors exploited it as a zero-day since at least 2024, prompting an emergency federal patch directive; related coverage ties the activity to the China-linked VerdantBamboo actor deploying BRICKSTORM-family backdoors on appliances. Do: Upgrade all RP4VMs appliances to 6.0.3.1 HF1 or apply Dell's published remediations immediately — federal agencies must patch per BOD 22-01 by the KEV deadline (reported as 'by Saturday'). Because exploitation has occurred since at least 2024, treat deployed appliances as potentially compromised: review the underlying OS for unexpected accounts, modified services, and root persistence, and restrict the appliance's management/replication network reachability until patched. | 10.0 | 13% | KEV |
| moderate≈ tens of thousands of appliances worldwide (estimated from deployment patterns; internet-exposed count unknown) |
Full article831 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Google researchers said Chinese attackers have been exploiting a zero-day since mid-2024, and they’ve moved on to a more advanced version of Brickstorm malware called Grimbolt.
Listen to this article
0:00
Learn more.
Researchers uncovered more worrying details about a long-running cyber espionage campaign suspected to be backed by the Chinese government, exemplifying how such attacks often go undetected until they’ve already caused significant damage.
Google Threat Intelligence Group and Mandiant said the Chinese threat group UNC6201 has been exploiting a zero-day vulnerability in Dell RecoverPoint for Virtual Machines since at least mid-2024. The group overlaps with UNC5221, also known as Silk Typhoon, which has been burrowing into critical infrastructure and government agency networks undetected since at least 2022.
The zero-day exploitation marks an escalation from this particular cluster of actors. State-sponsored attackers spent years implanting Brickstorm malware into networks before the campaign was finally detected last summer. By September, however, the attackers had replaced Brickstorm with Grimbolt, a more advanced malware that’s harder to detect, Google security researchers said Tuesday.
The zero-day vulnerability — CVE-2026-22769 — hinges on a hardcoded administrator password in Dell RecoverPoint for Virtual Machines that was pulled from Apache Tomcat. It carries a 10/10 CVSS rating. The Chinese threat group has been using the hardcoded password, which triggers the vulnerability and allows unauthenticated remote attackers to gain full system access with root-level persistence for at least 18 months, Google said.
Dell Technologies disclosed and released a patch for the vulnerability Tuesday. A company spokesperson urged customers to follow guidance in its security advisory.
“We are aware of less than a dozen impacted organizations, but because the full scale of this campaign is unknown we recommend that organizations previously targeted by Brickstorm look out for Grimbolt in their environments,” Austin Larsen, principal analyst at GTIG, told CyberScoop.
When the Cybersecurity and Infrastructure Security Agency unveiled new details about the campaign in December, Google said dozens of U.S. organizations, not including downstream victims, had already been impacted by Brickstorm.
“The actor is likely still active in unpatched and remediated environments, and because exploitation has been occurring since mid-2024, they have had significant time to establish persistence and carry out long-term espionage,” Larsen added.
The campaign — one of many concurrent efforts by China state-sponsored groups to embed themselves into networks for long-term access, disruptions and potential sabotage — remains a top area of concern for national security.
CISA, the National Security Agency and Canadian Centre for Cyber Security released new analysis on Brickstorm last week to share indicators and compromise that could help potential victims detect malicious activity on their networks.
Yet, the China-linked groups involved in this campaign have already moved on to Grimbolt, in some cases replacing older Brickstorm binaries with the new backdoor that’s more difficult to reverse engineer, according to Google.
Marci McCarthy, director of public affairs at CISA, told CyberScoop the agency will share further information on Wednesday.
Google’s fresh research on the China state-sponsored campaign demonstrates how the threat group’s tenacity, and ability to dwell undetected in networks longer than 400 days, keeps defenders and cyber authorities at a disadvantage.
The threat groups typically target edge applications and devices running on systems without endpoint detection and response, but researchers don’t know how attackers broke into the networks of the most recently discovered victims.
Researchers only have a narrow view of the threat groups’ activities at large.
“We suspect a significant portion of UNC5221 and UNC6201’s activity likely remains unknown, and there is a strong probability that they are developing or using undiscovered zero-days and malware,” Larsen said. “The most concerning aspect of this campaign is that additional organizations were likely compromised as part of this campaign and do not know it yet.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/china-brickstorm-grimbolt-dell-zero-day/