惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
InfoQ
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Apple Machine Learning Research
Apple Machine Learning Research
月光博客
月光博客
B
Blog
罗磊的独立博客
GbyAI
GbyAI
博客园 - 三生石上(FineUI控件)
雷峰网
雷峰网
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Microsoft Security Blog
Microsoft Security Blog
宝玉的分享
宝玉的分享
The GitHub Blog
The GitHub Blog
人人都是产品经理
人人都是产品经理
博客园 - Franky
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
博客园 - 聂微东
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
MyScale Blog
MyScale Blog
Google DeepMind News
Google DeepMind News
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏

The Register - Security: Patches

Homeland security cybercops say patch TrueConf (Russia Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update Year-long Russian attacks infect users as soon as they look at an email Cisco SD-WAN make-me-root bug under attack Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 AI is making Patch Tuesday (kinda) fun again Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Critical cPanel, WHM flaw probs exploited as 0-day, pros say Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks Critical Fortinet sandbox bugs allow auth bypass and RCE Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Ransomware scum, other crims exploit 4 old Microsoft bugs Attackers exploited the FortiClient EMS bug as a 0-day Citrix NetScaler bug may be multiple flaws in one Ransomware crims abused Cisco 0-day weeks before disclosure Google rushes Chrome update to fix zero-days under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack LexisNexis Legal & Professional confirms data breach Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Patch these 4 critical, make-me-root SolarWinds bugs ASAP Attacker gets into France's DB listing all bank accounts CISA gives feds 3 days to patch actively exploited Dell bug Google fixes exploited Chrome CSS zero-day Critical Microsoft bug from 2024 under exploitation
CISA gives feds 3 days to patch actively exploited Dell bug
Carly Page Carly Page · 2026-02-20 · via The Register - Security: Patches

Patches

CISA gives federal agencies three days to patch actively exploited Dell bug

Hardcoded credential flaw in RecoverPoint already abused in espionage campaign

Uncle Sam's cyber defenders have given federal agencies just three days to patch a maximum-severity Dell bug that's been under active exploitation since at least mid-2024.

CISA this week added the flaw, tracked as CVE-2026-22769, to its Known Exploited Vulnerabilities catalog, ordering civilian agencies to secure affected systems by February 21 – giving them just three days to get fixes in place.

"These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA warned, underscoring the urgency behind the unusually tight remediation window.

The bug affects Dell RecoverPoint for Virtual Machines and stems from hardcoded credentials that can allow attackers to gain unauthorized access. Dell disclosed and patched the issue earlier this week, noting that criminals had already been exploiting it before a fix was available.

"We have received a report of limited active exploitation of this vulnerability," a Dell spokesperson told The Register at the time, urging customers to get the recommended mitigations in place pronto.

Researchers say the bug quickly found its way into a broader espionage playbook tied to suspected China-nexus operators. According to Google's Mandiant incident response team, miscreants have exploited the vulnerability since at least mid-2024 to move laterally across networks, maintain persistence, and deploy a range of malware families.

Among the tools seen in the wild are the Brickstorm backdoor and a newer implant called Grimbolt, which, in some cases, has been swapped in for older malware. Researchers also spotted attackers spinning up so-called "Ghost NICs" on virtual machines to quietly pivot around compromised environments without tripping alarms.

A cluster tracked as UNC6201 has used the flaw to deploy multiple payloads, including Slaystyle, Brickstorm, and Grimbolt, during long-running intrusions, according to Mandiant. The firm says it knows of fewer than a dozen confirmed victims so far, though the true number could be higher.

Mandiant says the activity shares some hallmarks with Silk Typhoon, a Chinese state-backed espionage crew known for targeting government agencies and previously tied to breaches involving custom malware. The group has repeatedly exploited zero-day bugs to break into sensitive networks, including US federal systems.

The latest directive continues a pattern of rapid-fire patch orders from CISA as it tries to shrink the window between disclosure and remediation for actively exploited bugs. Just last week, the agency similarly gave federal agencies three days to lock down BeyondTrust Remote Support instances against a separate remote code execution flaw.

When CISA slaps a bug on the KEV list with a three-day deadline, it's less a gentle reminder and more a flashing neon sign that says patch now, ask questions later. ®