Dell zero-day flaw unpatched for nearly two years

A security vulnerability in Dell software has reportedly remained unpatched for almost two years, allowing Chinese hackers to exploit it. The flaw involves hardcoded login credentials in a tool, raising concerns about data security.

Reports indicate that a zero-day flaw in Dell's software has gone unpatched for nearly two years, creating a significant security risk. According to TechRadar, this vulnerability stems from login credentials being hardcoded in a tool, which has reportedly been exploited by Chinese hackers.

The issue highlights ongoing challenges in software patching, particularly for enterprise tools where such oversights can lead to unauthorized access. No specific details on the affected products or the extent of exploitation were provided in the initial reports, but the duration of the unpatched status—nearly two years—underscores the urgency for remediation.

Dell has not yet issued a public response in the available information, leaving users potentially exposed. Cybersecurity experts emphasize the importance of timely updates to mitigate such risks, especially when state-sponsored actors are involved.

This incident adds to a series of supply chain vulnerabilities in major tech firms, reminding organizations to audit third-party tools rigorously.

ተያያዥ ጽሁፎች

Cisco Talos has detailed how a Chinese-linked group is exploiting an unpatched zero-day in email security appliances since late November 2025, deploying backdoors and log-wiping tools for persistent access.

በAI የተዘገበ

Two groups linked to China are exploiting a newly discovered vulnerability in Cisco's email security products. The campaign involves zero-day attacks, highlighting ongoing cybersecurity risks. The issue was reported on December 19, 2025.

Security researchers have uncovered critical vulnerabilities in the n8n automation tool. A previously released patch failed to fully address the issues, leaving users exposed. Experts provide guidance on protecting systems amid these discoveries.

በAI የተዘገበ

A critical remote code execution vulnerability has been discovered in multiple BeyondTrust products. The flaw, rated 9.9 out of 10 in severity, allows hackers to run code on affected systems without needing to log in. The issue was reported on February 10, 2026.

 

 

 

ይህ ድረ-ገጽ ኩኪዎችን ይጠቀማል

የእኛን ጣቢያ ለማሻሻል ለትንታኔ ኩኪዎችን እንጠቀማለን። የእኛን የሚስጥር ፖሊሲ አንብቡ የሚስጥር ፖሊሲ ለተጨማሪ መረጃ።
ውድቅ አድርግ