Mandiant and Google GTIG report zero-day exploitation of CVE-2026-22769 (CVSS 10.0) in Dell RecoverPoint by suspected PRC-nexus threat actor UNC6201 since mid-2024, enabling deployment of SLAYSTYLE, BRICKSTORM, and novel GRIMBOLT malware. The report includes technical analysis of exploitation methods, persistence mechanisms via convert_hosts.sh modification, newly observed VMware pivot tactics including Ghost NICs and iptables-based Single Packet Authorization, and comprehensive remediation guidance with IOCs and YARA rules.
Search
Congressional trades, bills, prediction markets, hearings, and intelligence signals. Signal search supports: AND OR "exact phrase" -exclude
Congress & Markets0 trades · 0 bills · 0 markets · 0 hearings
Found 1 results across signals (1)
No results in congress & markets for “Dell RecoverPoint”
1 signal for "Dell RecoverPoint"
Page 1 of 1
9.2/10·Mandiant Threat Intelligence