Chinese Actors Exploited Dell RecoverPoint for VMs Flaw Since 2024
The hardcoded credential vulnerability (CVE-2026-22769) exists in Dell RecoverPoint for Virtual Machines and has been exploited since mid-2024.
The hardcoded credential vulnerability (CVE-2026-22769) exists in Dell RecoverPoint for Virtual Machines and has been exploited since mid-2024.
The exploited vulnerabilities in question exist across various products, from Microsoft Word to Windows Shell.
UNC3886 is a Chinese espionage group known for targeting defense, tech, and telecom organizations across both the U.S. and Asia-Pacific-Japan regions.
CISA said potential exploitation of flaws in unsupported edge devices creates "a significant threat to federal property."
The series of incidents detailed by Mandiant researchers started in early to mid-January, and included a previously disclosed campaign involving Okta customers.
The vulnerabilities (CVE-2026-1281 and CVE-2026-1340) could lead to unauthenticated remote code execution if successfully exploited.