TL;DR

A critical vulnerability in Dell's RecoverPoint software, involving hardcoded credentials, has been exploited in espionage campaigns and requires urgent patching by federal agencies within days.

What happened

CISA has issued an emergency directive to federal agencies, giving them three days to patch a high-severity security flaw found in Dell's RecoverPoint data protection software. This bug has been actively exploited since mid-2024 for espionage purposes.

Why it matters for ops

The vulnerability poses significant risks due to its exploitation for malicious activities and the presence of hardcoded credentials that could be easily abused by attackers.

Action items

  • Immediately review all Dell RecoverPoint installations
  • Apply available patches within the specified timeframe
  • Enhance monitoring and incident response protocols

Source link

https://go.theregister.com/feed/www.theregister.com/2026/02/20/cisa_dell_vulnerability/