Monday , August 24 2026
Dell Laptop

Dell Laptop PCs 100+ models affected through “ReVault” attack

More than 100 Dell laptop models in the Latitude and Precision series are vulnerable due to five common security issues affecting their firmware and Microsoft Windows APIs, according to a Cisco Talos report.

Talos researchers named the vulnerabilities ReVault. They allow an attacker to keep access to a victim’s device after Windows is reinstalled, bypass Windows Login, or grant a local user admin or system-level rights.

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

The Cl0p ransomware group has listed over 40 organizations that they say they targeted in a recent attack. This attack...
Read More
Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

Phillipe Laulheret, a senior vulnerability researcher at Cisco Talos, states that the vulnerabilities are related to the hardware ControlVault3 solution. This solution manages passwords and biometric templates within the device firmware on a board known as the Unified Security Hub (USH) by Dell. The hub can connect security peripherals like fingerprint readers or NFC devices.

In a blog post, Laulheret wrote that vulnerabilities on ControlVault USHs were potentially highly dangerous.

“These laptop models are widely-used in the cyber security industry, government settings and challenging environments in their rugged version. Sensitive industries that require heightened security when logging in – via smartcard or NFC – are more likely to find ControlVault devices in their environment, as they are necessary to enable these security features,” he explained.

Five new CVEs have been published: CVE-2025-24311 and CVE-2025-25050 for out-of-bounds flaws, CVE-2025-25215 for an arbitrary free vulnerability, CVE-2025-24922 for a stack overflow, and CVE-2025-24919 for an unsafe deserialization issue in ControlVault’s Windows APIs.

The Talos disclosure outlined various potential exploitation scenarios. One example involves an attacker with limited access using ControlVault firmware APIs to execute arbitrary code, allowing them to steal keys to permanently alter the firmware. This would let them maintain persistence without the victim’s knowledge and cause further harm later.

Dell released updates addressing the ReVault vulnerabilities on 13 June and advised customers at that time.

“Working with our firmware provider, we addressed the issues quickly and transparently disclosed the reported vulnerabilities in accordance with our Vulnerability Response Policy,” a spokesperson told Computer Weekly.

“Customers can review the Dell Security Advisory DSA-2025-053 for information on affected products, versions, and more. As always, it is important that customers promptly apply security updates that we make available and move to supported versions of our products to ensure their systems remain secure,” they said.

Dell added: “Collaborating with industry partners and the research community on coordinated disclosures is a key part of strengthening the security of our products and advancing the broader technology industry.”

Check Also

943

Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

Oracle has put out 943 new security updates in its August 2026 Critical Security Patch …