Welcome to the Mandos Brief: Strategic insights to help you stay ahead of threats and the market.
In this week's analysis:
- VMware ESXi Ransomware Exploitation: CISA confirmed ransomware gangs are actively exploiting a high-severity ESXi sandbox escape flaw that's been a zero-day since at least February 2024. Action: If you haven't patched CVE-2025-22225 across ESXi, Fusion, and Cloud Foundation, treat this as your top priority this week - attackers already have a head start.
- Near-Perfect Prompt Injection Attacks on LLMs: Researchers showed that black-box prompt injection can achieve near-100% malicious content retrieval across major embedding models, coercing GPT-4o into exfiltrating SSH keys for as little as $0.21 per query. So What: If you're deploying RAG or multi-agent systems in production, existing defenses are not enough - start evaluating retrieval-layer controls and assume this attack surface will only grow.
- Indurex Launches for Cyber-Physical Security: A new startup from the former Applied Risk founder emerged from stealth with a platform unifying cyber, process, and safety context for industrial environments. Strategy: For security vendors eyeing OT and critical infrastructure, this signals growing demand for converged visibility platforms - fragmented tooling in these environments is becoming a real market gap to fill.

Threats
CISA Confirms VMware ESXi Vulnerability Exploited In Ransomware Attacks
-
I've confirmed that ransomware gangs are now actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability that has been used in zero-day attacks since at least February 2024.
-
The vulnerability allows attackers with privileged access to trigger an arbitrary kernel write leading to sandbox escape, affecting multiple VMware products including ESXi, Fusion, Cloud Foundation, and vSphere.
-
CISA has updated its Known Exploited Vulnerabilities catalog to specifically flag this flaw as being used in ransomware campaigns, though federal agencies were already required to patch by March 25, 2025 under BOD 22-01.
OpenClaw Integrates VirusTotal Scanning to Detect Malicious ClawHub Skills
-
OpenClaw has partnered with Google-owned VirusTotal to scan all skills uploaded to ClawHub marketplace using SHA-256 hashes and Code Insight capability, automatically approving benign skills while flagging suspicious ones and blocking malicious content.
-
Recent security research has uncovered hundreds of malicious skills on ClawHub that masquerade as legitimate tools but harbor functionality to exfiltrate data, inject backdoors, or install stealer malware through cleverly concealed prompt injection payloads.
-
The platform faces significant security challenges including cleartext credential storage, ineffective guardrails against prompt injection attacks, and over 30,000 exposed instances accessible over the internet, prompting China's Ministry of Industry and Information Technology to issue security warnings.
Rapid7 Discovers Chrysalis Backdoor Used by Lotus Blossom APT
-
Rapid7 uncovered a sophisticated campaign by Chinese APT group Lotus Blossom that compromised Notepad++ infrastructure to deliver a previously unknown custom backdoor called Chrysalis, which features extensive command and control capabilities including file transfer, remote shell access, and comprehensive system reconnaissance.
-
The attack chain leverages DLL sideloading using a renamed Bitdefender Submission Wizard to load malicious log.dll, which then decrypts and executes shellcode that deploys the main Chrysalis backdoor with RC4 encryption and custom API hashing to evade detection.
-
Additional forensic analysis revealed the threat actors also deployed Cobalt Strike beacons through multiple loader variants, including one that abuses Microsoft Warbird code protection framework via undocumented NtQuerySystemInformation system calls for stealthy shellcode execution.



