Vali Cyber’s ZeroLock 5 extends multi-factor authentication and policy controls directly to the hypervisor command line.

Vali Cyber Targets a Critical Blind Spot With Multi-Factor Authentication for Hypervisors

As enterprises have moved more workloads into virtualised environments, the hypervisor has become a critical piece of infrastructure. Yet security strategies have traditionally focused heavily on endpoints, applications and guest operating systems, leaving the underlying virtualisation layer with comparatively fewer defensive controls.

Vali Cyber is targeting that gap with ZeroLock 5, the latest version of its hypervisor security platform. The company says the release is designed to address two major risks at the hypervisor layer: insider threats and compromised credentials on ESX and Linux hosts. 

The central addition is CLI-MFA, which brings multi-factor authentication directly to the hypervisor command line. Under the new release, administrators can require a time-based one-time password for operations covered by security policies, including file access, program execution and network access.

That matters because command-line access can provide an attacker with a powerful route into underlying infrastructure. A compromised credential may provide far greater reach at the hypervisor layer than it would on an individual endpoint. Once an attacker gains control of that environment, multiple virtual machines and workloads can potentially be affected.

The security industry has increasingly focused on this problem as ransomware groups and other threat actors look for ways to maximise the impact of a single compromise. Vali Cyber points to growing attention on virtualisation infrastructure, including attacks involving VMware ESX environments and the theft or abuse of SSH credentials. (Business Wire)

ZeroLock 5 is designed around the principle that credentials alone should not be sufficient to perform sensitive actions. By requiring a second authentication factor at the command line, the platform adds another barrier between stolen credentials and privileged activity.

For enterprises, the challenge is not simply implementing stronger authentication. Large organisations often operate hundreds of hosts across multiple data centres and segmented networks, making security policies difficult to deploy consistently. Vali Cyber has therefore designed ZeroLock 5 with distributed enterprise environments in mind.

The platform’s collector has been separated into a standalone service, allowing collectors to be deployed remotely and independently of the location of the central ZeroLock Management Console. Standardised deployments can package configuration into reusable definitions that generate installer commands, allowing security teams to replicate configurations across multiple sites. (Business Wire)

The release also adds auditable policy lifecycle management. Policies can move through draft, published and retired states with revision tracking, giving security teams greater visibility into how controls have changed over time. Other additions include reusable agent installations, multi-SIEM activity forwarding, scheduled alert-only mode and vCenter host inventory import.

The SIEM integration is particularly relevant for enterprises that already operate centralised security operations centres. ZeroLock 5 supports presets for Microsoft Sentinel, Splunk, Sumo Logic and Google SecOps, allowing activity from the hypervisor layer to feed into established monitoring workflows. (Business Wire)

The platform supports VMware Cloud Foundation as well as ESX 6.7 and later versions, with older versions available upon request. Licensing has also been simplified, according to the company. (Business Wire)

The broader strategic issue is that patching alone may not be enough to protect critical virtualisation infrastructure. Vulnerabilities will continue to emerge, and enterprises operating complex environments cannot assume that every threat will be eliminated before an attacker exploits it.

That is where behavioural and access controls become important. Security teams increasingly need to assume that credentials can be stolen and then limit what an attacker can do after gaining access. For hypervisors, that means protecting not just the perimeter but the commands and actions that determine what happens underneath enterprise workloads.

Vali Cyber describes ZeroLock as a preemptive security platform focused on Linux and hypervisors, combining CLI-MFA, exploit prevention, hypervisor visibility and behavioural detection. The company says its approach is designed to stop threats at the infrastructure layer without adding performance overhead. (Business Wire)

ZeroLock 5 is now available to existing customers as an upgrade and to new customers as part of a new deployment. More information is available at Vali Cyber.

As virtualisation remains central to modern enterprise computing, securing the hypervisor is becoming less of a specialist concern and more of a board-level resilience issue. The ability to enforce strong authentication and policy controls directly where critical workloads are managed could become an increasingly important part of the enterprise cybersecurity stack.

Share this article

Categories