Compromised VM gave attacker access to the entire ESXi host
Huntress has published an analysis of an intrusion observed in December 2025. A threat actor first compromised a guest virtual machine, then moved on to every workload on the ESXi host. Huntress has not been able to conclude with full certainty, but its main hypothesis is that three vulnerabilities from a VMware advisory published in March the previous year were exploited. Initial access likely came through a compromised SonicWall VPN, and known exploits were already circulating when the advisory was released.
What this means for your organisation
The virtualisation platform is often the last layer to be patched, precisely because it is not internet-facing and because reboots require planned downtime. This incident shows why that is a risky prioritisation: when the boundary between guest and host breaks, the entire virtualisation environment falls at once, including systems that are otherwise well segmented. An exposed VPN combined with an unpatched host makes for a short path from the perimeter to full control.
Berigo recommends
- Establish a fixed patching window for virtualisation hosts as well, and accept planned downtime as part of the operating cost.
- Separate the ESXi management network from ordinary client and server networks, and require dedicated authentication for access.
- Prioritise updates to VPN solutions and other perimeter components, and verify that multi-factor authentication is enabled.
- Test that backups can be restored without access to the compromised virtualisation environment.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch