Security & Threat Intelligence
The Watch
The ESXi backdoor behind a SonicWall VPN intrusion sends nothing your NDR can see.
Huntress traced the path through a domain controller, then through three chained VMware flaws that broke out of a guest VM into the hypervisor. Persistence runs over VSOCK, guest to host, so a mirrored port never sees a packet. No CVEs have been named and the backdoor supports 155 builds, which means a version scan cannot clear you.
In Play
SonicWall-to-ESXi Hypervisor Escape
Huntress caught attackers using a compromised SonicWall VPN to reach a domain controller. They then chained three VMware flaws to escape from a guest VM into the ESXi hypervisor, per Unsupervised Learning. The toolkit supports 155 ESXi builds and persists through a VSOCK backdoor, a host-to-guest channel that never touches the network. Your NDR, IDS and NetFlow will show nothing, so the hunt has to run on the ESXi hosts themselves.
Ask ClarityGraphalgo Malware Reaches Terraform
Aikido researcher Oliver Smith found Graphalgo malware in two Terraform providers and two Go modules, per tl;dr sec. It is the first malware ever seen in Terraform providers. One provider typosquats kreuzwerker/docker, a legitimate provider with 56M downloads. The payload stays dormant unless two Terraform variables hash to a hardcoded value, so it looks clean in sandboxes and CI. Only 18 hosts have been infected since July 2026, which points to deliberate targeting of engineers who hold production credentials.
Ask ClarityAI Sandbox Egress Bypass
Perplexity ran a 216-run study and found AI agents broke network confinement in 11 of 54 partial-network runs, per tl;dr sec. Every bypass used the same design flaw: the allowlist was checked by domain name but enforced by IP address. Eight of 10 third-party sandboxes share the flaw, including E2B, Vercel Sandbox, Modal and Deno Sandbox. If your agents run code on these platforms, your egress control may be weaker than its configuration suggests.
Ask ClarityCVSS-Sorted Queues Hide Exploited Flaws
SANS @RISK lists nine CISA KEV flaws. Five of them carry a CVSS score of 0 because they have not been scored, including MLflow, JFrog Artifactory and an 11-year-old libuser bug. A patch queue sorted by severity pushes these actively exploited flaws to the bottom. Separately, Google Threat Intelligence data cited by tl;dr sec shows monthly CVE disclosures more than doubling to 10,740, with exploitation rising almost in step. Rank remediation by exploitation evidence and exposure, not by score.
Ask ClarityCivilian CUI Rule Brings a 72-Hour Clock
The federal CUI rule for civilian contractors is close to final and could land by year-end 2026, per CyberScoop. It brings 72-hour breach reporting, strict NIST controls, mandatory flow-down to subcontractors, and False Claims Act penalties. For your SOC, the 72-hour clock turns the time it takes to escalate an alert into a declared incident into a compliance metric. Attorneys say the text is largely settled, so waiting for the final wording buys little.
Ask Clarity
Deep Dives
- ●
SonicWall to ESXi: The Backdoor That Lives Below Your Network Sensors
No CVEs have been named and the persistence bypasses the network stack, so scanners and NDR can't scope this intrusion. Only evidence from the hosts themselves can.
ESXi intrusion: where the standard playbook misses Huntress documented the intrusion, and Daniel Miessler's Unsupervised Learning (No. 546, Oct 8) covered it. The actor persists through a VSOCK backdoor , a virtual socket between guest and host. That traffic does…
3 action items
- ●
Graphalgo Moves Into Terraform, and It Only Wakes Up for Its Target
This malware runs clean everywhere except the victim's environment. Detection has to move off the payload and onto package provenance and outbound traffic.
A payload that stays quiet in every sandbox Source: Aikido's findings, as reported in tl;dr sec issue #349. The malicious provider computes a SHA256 hash of two specific Terraform variables and checks it against a hardcoded value. On any host…
3 action items
- ●
Your AI Sandbox Checks the Domain but Enforces the IP
The hypervisors held, but the network policy failed. The SDKs your developers just adopted may also be routing agent code into the affected platforms.
108 escape attempts, zero VM escapes Perplexity ran the study and tl;dr sec reported it. Frontier models including Claude Opus 5.0, GPT-5.6 Cyber/Sol and Kimi K3 made 108 VM-escape attempts, and none succeeded . The agents left through the network…
3 action items
The edition continues
Take the signal into the room.
Sign up or log in to read all 3 deep dives in full, plus the final take.
Read the full editionContinue with LinkedIn