Dell zero-day flaw unpatched for nearly two years

A security vulnerability in Dell software has reportedly remained unpatched for almost two years, allowing Chinese hackers to exploit it. The flaw involves hardcoded login credentials in a tool, raising concerns about data security.

Reports indicate that a zero-day flaw in Dell's software has gone unpatched for nearly two years, creating a significant security risk. According to TechRadar, this vulnerability stems from login credentials being hardcoded in a tool, which has reportedly been exploited by Chinese hackers.

The issue highlights ongoing challenges in software patching, particularly for enterprise tools where such oversights can lead to unauthorized access. No specific details on the affected products or the extent of exploitation were provided in the initial reports, but the duration of the unpatched status—nearly two years—underscores the urgency for remediation.

Dell has not yet issued a public response in the available information, leaving users potentially exposed. Cybersecurity experts emphasize the importance of timely updates to mitigate such risks, especially when state-sponsored actors are involved.

This incident adds to a series of supply chain vulnerabilities in major tech firms, reminding organizations to audit third-party tools rigorously.

Mga Kaugnay na Artikulo

Russian state-sponsored hackers quickly weaponized a newly patched Microsoft Office flaw to target organizations in nine countries. The group, known as APT28, used spear-phishing emails to install stealthy backdoors in diplomatic, defense, and transport entities. Security researchers at Trellix attributed the attacks with high confidence to this notorious cyber espionage unit.

Iniulat ng AI

A massive data breach in China has reportedly spilled 8.7 billion records after a gigantic database was left unlocked on the internet. The incident, detailed in recent reports, highlights vulnerabilities in data security practices. Authorities are yet to confirm the full extent of the exposure.

A vulnerability in a popular WordPress quiz plugin has impacted over 40,000 sites, allowing potential SQL injection attacks. Security researchers have identified the flaw, urging site owners to check for exposure. The issue was reported on February 4, 2026.

Iniulat ng AI

A security vulnerability in the WordPress plugin Ally has been identified as an SQL injection flaw. This issue could potentially affect up to 250,000 websites using the plugin. The flaw was reported in a TechRadar article published on March 12, 2026.

Gumagamit ng cookies ang website na ito

Gumagamit kami ng cookies para sa analytics upang mapabuti ang aming site. Basahin ang aming patakaran sa privacy para sa higit pang impormasyon.
Tanggihan