A California federal judge has once again dismissed a lawsuit brought by journalists from Salvadoran investigative outlet El Faro against ...
The research reportedly covered areas including artificial intelligence (AI), cybersecurity, covert communications and steganography.
The warning was issued in an MI5 Security Service Espionage Alert on September 30, 2026. According to MI5, the research funding was channelled through the China General Technology Research Institute (CGTRI), also known as the China Academy of General Technology (CAGT).
MI5 assessed that CGTRI is being used as a front for China’s MSS and claimed that its primary purpose is to fund research that can improve the Chinese intelligence service’s technical capabilities.
“The alert advises UK academic institutions to immediately review any ongoing or planned collaboration with CGTRI and advises academics to establish the ultimate funding source when conducting any research collaboration with Chinese institutions to ensure CGTRI are not involved,” reads the MI5 security alert.
The areas of research identified by MI5 are particularly significant from a cybersecurity and intelligence perspective. Artificial intelligence can be used for data analysis, automation and surveillance, while cybersecurity research can contribute to offensive and defensive cyber capabilities.
The alert also revealed covert communications and steganography. Steganography involves hiding information inside another form of digital content, such as an image or audio file, making it potentially useful for concealing communications.
MI5 said that more than 100 academics linked to the U.K. had contributed to projects funded through CGTRI. The agency also said that some researchers may not have known that CGTRI was financially supporting the research they were involved in.
MI5 further added, “It puts the fact that CGTRI has very strong ties to MSS in the public domain and states that academic institutions, staff and researchers should ensure they are aware of the National Security Act 2023. Any institution or individual continuing to conduct research ultimately funded by CGTRI should take their own independent legal advice.”
MI5 warned that research developed through these collaborations could potentially strengthen Chinese intelligence capabilities. The agency particularly highlighted the risk to the U.K. because some of the technologies involved could have applications in cyber operations and intelligence gathering.
China has rejected the allegations. The Chinese Embassy in the U.K. described the claims as fabricated and baseless, arguing that academic exchanges between British universities and China are voluntary, lawful and mutually beneficial.
Dell has shipped security fixes for six critical vulnerabilities in its Container Storage Modules (CSM) that could allow unauthenticated attackers to seize full administrative control over an organization's storage infrastructure and every node in a Kubernetes cluster. Four of the six flaws carry CVSS scores of 9.6 or higher, two of which hit the maximum possible rating of 10.0.
The bugs affect every version of CSM prior to 1.17.0, and Dell patched them in version 1.18.0. The company says no workarounds or interim mitigations exist, which means organizations running the affected software are down to one option: update now.
What CSM Does, and Why These Bugs Matter
Dell Container Storage Modules are Kubernetes-native extensions that manage persistent storage for containerized workloads across Dell's storage product families, including PowerFlex, PowerStore, PowerMax, PowerScale, and Unity XT. Because CSM sits at the intersection of storage credentials and cluster-level access controls, vulnerabilities in the platform carry a particularly high blast radius. An attacker who compromises CSM does not just gain access to data; they gain the ability to manipulate who can access what across every tenant connected to the system.
A closer look at the Six Vulnerabilities
The most severe of the six, CVE-2026-63688, scored a perfect 10.0. The flaw lives in the csm-authorization-storage gRPC server and requires no authentication to exploit. An attacker on the network can send requests directly to this endpoint and pull the backend administrator credentials for every storage array registered with the system. Dell's own advisory described it as enabling "a complete bypass of the csm-authorization security model," handing an attacker full administrative control over storage spanning all five supported Dell storage product families.
The second maximum-severity flaw, CVE-2026-63692, also a 10.0, targets the authorization proxy and tenant service. Like its counterpart, it requires zero credentials to exploit. A successful attack gives an adversary administrative control over the entire authorization service and the ability to access or manipulate storage resources across all connected tenants.
CVE-2026-67269 scored 9.9 and introduces a different threat model. It is a privilege escalation flaw in the ContainerStorageModule Custom Resource reconciler. A low-privilege attacker, not even a full admin, can submit a single maliciously crafted custom resource to the cluster and walk away with root-level access on every node in the environment. The attack surface is as small as one API call; the damage is cluster-wide.
Two of the remaining flaws center on hardcoded secrets. CVE-2026-54472 (CVSS 9.8) buries a static set of credentials inside the CSM Authorization module, allowing any remote attacker to forge cryptographically valid administrative tokens and seize control of the Authorization proxy. CVE-2026-61421 (also 9.8) compounds the problem: the JWT authentication component in karavi-authorization uses a hardcoded signing key. Because the signing secret is publicly available, anyone who locates it, something that is not especially difficult when code repositories are involved, can mint valid authentication tokens and claim administrative privileges without going through any login flow whatsoever.
The final flaw, CVE-2026-67273, scored 9.6 and is a template injection vulnerability. A low-privilege attacker with remote access can manipulate input fed through the template engine to escalate their own privileges, read sensitive information, and tamper with role-based access controls at the cluster scope. Dell's advisory noted that exploitation yields the ability to "create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls."
Context: Dell's Track Record With Exploited Flaws
This batch of CSM vulnerabilities does not arrive in isolation. Dell has faced repeated problems with critical infrastructure flaws being turned against real targets in the field. Earlier this year, researchers at Mandiant and Google's Threat Intelligence Group documented how CVE-2026-22769, a hardcoded-credential flaw in Dell RecoverPoint for Virtual Machines carrying a CVSS score of 10.0, had been actively exploited as a zero-day since mid-2024 before Dell published a fix in February 2026. CISA added it to its Known Exploited Vulnerabilities catalog the following day. Years earlier, CVE-2021-21551, an access control flaw in Dell's dbutil driver, made the same list after evidence of active exploitation emerged in the wild.
The pattern here is consistent: attackers increasingly go after enterprise infrastructure components that security teams tend to treat as inherently trusted. Storage management platforms and low-level system utilities rarely face the same scrutiny as public-facing applications, and that blind spot has proven to be consequential.
What to Do
Dell is directing all customers to upgrade CSM to version 1.18.0 immediately. For systems affected by CVE-2026-61421, the company is additionally recommending that JWT signing secrets be rotated post-upgrade, since those secrets were embedded in code that has been publicly accessible and should be treated as already compromised. No partial mitigations apply. The fix is available, and for organizations still running pre-1.17.0 versions, the exposure is active.