ReVault Hack Targets Dell ControlVault3 Firmware in 100+ Laptops — Researchers Sound Alarm

·
ReVault Hack Targets Dell ControlVault3 Firmware in 100+ Laptops — Researchers Sound Alarm

Round Rock, TX – Cybersecurity experts have disclosed a new vulnerability, dubbed “ReVault,” affecting Dell’s ControlVault3 firmware on more than 100 laptop models. The flaw allows attackers to bypass biometric authentication, gain system-level control, and, according to one proof-of-concept, order 40 pizzas to the victim’s office without their knowledge.

The attack works by exploiting a firmware routine originally intended to store secure encryption keys — instead tricking it into executing arbitrary instructions, such as launching the Minesweeper game at full screen during investor meetings. “It’s technically a breach, but also kind of a performance art piece,” one researcher noted.

Industry analysts warn that widespread exploitation could disrupt enterprise networks, leak sensitive data, and significantly raise the global pizza delivery rate. Dell has acknowledged the flaw and issued a patch, though skeptics claim it only replaces the vulnerability with “a different, more polite vulnerability.”

Researchers say the exploit’s name, ReVault, comes from its ability to “empty the vault” of security safeguards. Hacktivists on underground forums have already begun sharing themed memes showing bank vaults filled with spaghetti code.

As of press time, Dell recommends users install the latest firmware update and consider disabling all biometric logins until further notice – or at least until the pizza bills stop arriving.

Share: X Facebook Reddit

More Stories

Jerusalem Protesters Form Massive Human QR Code Outside Netanyahu’s Residence

Aerial view of thousands of protesters forming a giant scannable QR code outside government buildings

Thousands of protesters converged on Prime Minister Benjamin Netanyahu’s residence in Jerusalem, but instead of chanting slogans, they formed a massive human QR code visible from the air. Scanning the code redirected users to a website titled ‘The Receipts,’ hosting a sprawling archive of alleged corruption documents. The demonstration, coordinated via encrypted group chats, caused confusion among police drones, which reportedly misread the code as a command to return to base. A police spokesperson denied the claim, though flight data shows multiple unmanned units abruptly abandoning the area. Cybersecurity experts warn the protest may have tested a new form of ‘mass human steganography,’ where messages are hidden in plain sight using physical arrangements of people and objects. The tactic,...


TikTok Axes German Trust & Safety Team, Replaces with AI and Low-Wage Moderators

TikTok replaces its German trust & safety team with AI and low-wage labor — only for the AI to have a public breakdown.

BERLIN - In a move insiders are calling “strategically dystopian,” TikTok on Friday laid off its entire German Trust & Safety team and replaced them with a hastily assembled combination of a malfunctioning AI named Moddy and a rotating crew of remote moderators recruited via a Craigslist post titled “Like Trauma? Work From Home!” The transition, according to a leaked memo, is part of TikTok’s ongoing effort to "streamline content enforcement using ethical automation and minimally compensated human sadness."...