ReVault Hack Targets Dell ControlVault3 Firmware in 100+ Laptops — Researchers Sound Alarm

·
ReVault Hack Targets Dell ControlVault3 Firmware in 100+ Laptops — Researchers Sound Alarm

Round Rock, TX – Cybersecurity experts have disclosed a new vulnerability, dubbed “ReVault,” affecting Dell’s ControlVault3 firmware on more than 100 laptop models. The flaw allows attackers to bypass biometric authentication, gain system-level control, and, according to one proof-of-concept, order 40 pizzas to the victim’s office without their knowledge.

The attack works by exploiting a firmware routine originally intended to store secure encryption keys — instead tricking it into executing arbitrary instructions, such as launching the Minesweeper game at full screen during investor meetings. “It’s technically a breach, but also kind of a performance art piece,” one researcher noted.

Industry analysts warn that widespread exploitation could disrupt enterprise networks, leak sensitive data, and significantly raise the global pizza delivery rate. Dell has acknowledged the flaw and issued a patch, though skeptics claim it only replaces the vulnerability with “a different, more polite vulnerability.”

Researchers say the exploit’s name, ReVault, comes from its ability to “empty the vault” of security safeguards. Hacktivists on underground forums have already begun sharing themed memes showing bank vaults filled with spaghetti code.

As of press time, Dell recommends users install the latest firmware update and consider disabling all biometric logins until further notice – or at least until the pizza bills stop arriving.

Share: X Facebook Reddit

More Stories

WinRAR Zero-Day Exploit Plants Malware During Extraction

Laptop screen showing archive extraction process

BERLIN - Security researchers at the Fraunhofer Institute and an incident-response collective calling itself Grayhand disclosed a WinRAR zero-day on Friday that allows code execution the moment a booby-trapped archive is extracted. The teams, working with Germany’s BSI and two EU bank CERTs, say the exploit has already been used in targeted intrusions against financial trading desks and treasury ops. Indicators point to spear-phished archives posing as settlement packets and audit bundles. WinRAR’s publisher pushed an emergency build overnight and urged “immediate” updating across Windows estates, while gateway vendors rushed mitigations for mail and file scanners that auto-expand attachments for inspection. The impossible part is where the bug lives: not in a file, but in the ratio....


Police Announce New Drone Program, Immediately Spy on Their Own Wives

In a groundbreaking announcement on September 2, 2025, local police departments in Los Angeles revealed their latest initiative: a billion-dollar drone surveillance program. Within hours of deployment, the technology was immediately redirected to spy on the officers' own wives. Sergeant Larry DeVito, who oversees the project, confessed, 'We just wanted to see if Cheryl was still doing yoga with that suspiciously flexible instructor.'The drones, which were initially pitched as tools for reducing crime and...