Dell zero-day flaw unpatched for nearly two years

A security vulnerability in Dell software has reportedly remained unpatched for almost two years, allowing Chinese hackers to exploit it. The flaw involves hardcoded login credentials in a tool, raising concerns about data security.

Reports indicate that a zero-day flaw in Dell's software has gone unpatched for nearly two years, creating a significant security risk. According to TechRadar, this vulnerability stems from login credentials being hardcoded in a tool, which has reportedly been exploited by Chinese hackers.

The issue highlights ongoing challenges in software patching, particularly for enterprise tools where such oversights can lead to unauthorized access. No specific details on the affected products or the extent of exploitation were provided in the initial reports, but the duration of the unpatched status—nearly two years—underscores the urgency for remediation.

Dell has not yet issued a public response in the available information, leaving users potentially exposed. Cybersecurity experts emphasize the importance of timely updates to mitigate such risks, especially when state-sponsored actors are involved.

This incident adds to a series of supply chain vulnerabilities in major tech firms, reminding organizations to audit third-party tools rigorously.

Makala yanayohusiana

Cisco Talos has detailed how a Chinese-linked group is exploiting an unpatched zero-day in email security appliances since late November 2025, deploying backdoors and log-wiping tools for persistent access.

Imeripotiwa na AI

Two groups linked to China are exploiting a newly discovered vulnerability in Cisco's email security products. The campaign involves zero-day attacks, highlighting ongoing cybersecurity risks. The issue was reported on December 19, 2025.

Security researchers have uncovered critical vulnerabilities in the n8n automation tool. A previously released patch failed to fully address the issues, leaving users exposed. Experts provide guidance on protecting systems amid these discoveries.

Imeripotiwa na AI

A critical remote code execution vulnerability has been discovered in multiple BeyondTrust products. The flaw, rated 9.9 out of 10 in severity, allows hackers to run code on affected systems without needing to log in. The issue was reported on February 10, 2026.

Jumatano, 11. Mwezi wa tatu 2026, 14:00:34

Google report warns of shifting cloud threat landscape

Jumanne, 17. Mwezi wa pili 2026, 02:30:36

Research uncovers flaws in password managers' zero-knowledge claims

Jumatano, 4. Mwezi wa pili 2026, 19:25:39

Russian hackers exploit Microsoft Office vulnerability days after patch

Jumanne, 27. Mwezi wa kwanza 2026, 23:02:25

Microsoft patches security flaw in Office software

Ijumaa, 9. Mwezi wa kwanza 2026, 06:48:48

Linux kernel bugs can hide for up to 20 years

Alhamisi, 8. Mwezi wa kwanza 2026, 08:48:32

The myth of Linux's invincibility in enterprise security

Alhamisi, 8. Mwezi wa kwanza 2026, 07:13:23

Study uncovers long-hidden bugs in Linux kernel

Alhamisi, 8. Mwezi wa kwanza 2026, 06:04:40

Linux battery utility TLP patched after authentication bypass flaw

Jumatatu, 22. Mwezi wa kumi na mbili 2025, 16:25:40

HPE urges immediate patching of OneView after critical security flaw found

Jumanne, 16. Mwezi wa kumi na mbili 2025, 23:12:04

React2Shell exploits continue with large-scale Linux backdoor deployments and cloud credential theft

 

 

 

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa