Skip to content
Chinese Hackers Exploit ESXi Zero-Days via Hacked SonicWall VPN

Chinese Hackers Exploit ESXi Zero-Days via Hacked SonicWall VPN

First seen 9 Jan 2026, 20:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Chinese-speaking hackers exploited vulnerabilities in VMware ESXi by using a compromised SonicWall VPN. The attackers deployed a sophisticated toolkit that included a VM escape exploit, which appears to have been developed over a year before its public disclosure. This incident highlights the ongoing threat posed by advanced persistent threats targeting virtualization technologies.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 197d ago How this analysis works

More articles in this cluster (1)

Following this threat?

Track Sonicwall in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed