IN THE NEWS
Vali Cyber Announces New Integration with CrowdStrike Falcon Next-Gen SIEM
NEW YORK – Fal.Con 2026 – AUGUST 31, 2026 – Vali Cyber today at Fal.Con 2026 announced a new integration with CrowdStrike that enables security data from ZeroLock® to flow into CrowdStrike Falcon® Next-Gen SIEM. The integration enables security teams to correlate ZeroLock hypervisor security data with endpoint, identity, cloud, threat intelligence, and other security telemetry during investigations, providing additional context and faster response to threat activity.
As virtualization becomes the backbone of private AI and sensitive workloads, hypervisors have become an increasingly attractive target for adversaries. Compromised credentials, exploited vulnerabilities, and misconfigurations can provide attackers access to the virtualization layer for lateral movement, persistence, and ransomware. ZeroLock provides runtime protection at the hypervisor layer, enforcing behavior in real time to block malicious activity as it happens. By making ZeroLock security data available within Falcon Next-Gen SIEM, security teams can incorporate hypervisor activity into broader investigations and security operations workflows.
Falcon Next-Gen SIEM delivers more capabilities and up to 150x faster search performance than legacy SIEMs and solutions positioned as SIEM alternatives, at an 80% lower total cost of ownership.
The integration enables organizations to:
- Bring hypervisor security data into Falcon Next-Gen SIEM. A certified Push Data Connector and parser send ZeroLock data into Falcon Next-Gen SIEM over a standard HEC endpoint, with no middleware or additional agents required.
- Correlate hypervisor activity with broader security telemetry. ZeroLock events are normalized to the CrowdStrike Parsing Standard and ECS, enabling security teams to correlate detections with endpoint, identity, cloud, and other security data during investigations.
- Investigate and hunt hypervisor threats. Ransomware, tampering, unauthorized file and configuration access, and credential-abuse alerts are available as events in Falcon Next-Gen SIEM, enabling teams to build dashboards, create correlation rules, and hunt threats, with pivots back to the source alert for additional context.
“The hypervisor has become one of the most targeted and least visible layers in the modern data center. As attackers increasingly target this critical layer, security teams need real-time protection and visibility into hypervisor activity,” said Austin Gadient, CTO and co-founder of Vali Cyber. “We’re excited about this integration with CrowdStrike because it brings ZeroLock security data into Falcon Next-Gen SIEM, where teams can correlate it with security telemetry from across their environment. This is what real infrastructure security looks like: preemptive protection at the source, with the visibility to act on it at scale.”
To learn more about the integration, visit https://valicyber.com/resources/hypervisor-protection-in-crowdstrike-falcon-next-gen-siem/.
To learn more about the Vali Cyber and CrowdStrike partnership, visit https://marketplace.crowdstrike.com/listings/vali-cyber-zerolock/.
Schedule Your Demo of ZeroLock
About Vali Cyber
Vali Cyber® secures where attacks have the most impact: mission critical systems. While most defenses focus on endpoints, Vali Cyber identified Linux and hypervisors as critical yet under protected. Built for this reality, ZeroLock delivers preemptive security with command line native MFA, exploit prevention, deep hypervisor visibility, and AI-driven behavioral detection. By operating at the hypervisor layer, ZeroLock stops threats in real time without performance impact or added overhead. If incidents occur, automated rollback restores workloads in seconds, ensuring uptime. Recognized by Gartner as a Key Startup in Security Software, Vali Cyber leads by protecting the foundation of modern infrastructure others overlook.
Vali Cyber Launches ZeroLock® 5, Bringing Multi-Factor Authentication to the Hypervisor Command Line
No more unprotected root access: CLI-MFA brings second-factor authentication to the hypervisor CLI and SSH, plus auditable policy lifecycle management, distributed architecture, vCenter integration, and multi-SIEM forwarding.
NEW YORK, NY — SEPTEMBER 1, 2026 — Vali Cyber, the leading provider of preemptive hypervisor security, today announced the general availability of ZeroLock® 5, a major release focused on closing the two most dangerous gaps in hypervisor security: insider threats and stolen credentials on ESX and Linux hosts.
The Hypervisor Is Now the Target
Over the past two years, ransomware operators and nation-state actors alike have shifted their focus from individual endpoints to the hypervisor layer itself. In its Cybersecurity Forecast 2026, Google Cloud warned that adversaries are pivoting to the underlying virtualization infrastructure, which it calls a critical blind spot, as security controls mature inside guest operating systems.
That shift is already visible in the wild: threat actor ShinyHunters has been observed developing “shinysp1d3r,” a ransomware-as-a-service platform built to encrypt VMware ESX environments by harvesting SSH keys and abusing stolen credentials. A single compromised credential is enough to take down dozens of virtual machines before a security team ever sees an alert.
Because hypervisors sit a layer beneath where most security tools can see, attackers who reach the CLI can operate largely unseen. That’s the threat ZeroLock 5 is built to address.
CLI-MFA: Multi-Factor Authentication Where It Matters Most
The centerpiece of this release is CLI-MFA, extended in 5 to govern file access, program execution, and network access at the hypervisor command line. A stolen credential is no longer enough. Any operation covered by a rule can now be set to require a time-based one-time password before it proceeds.
“We have seen firsthand what happens to a company after a hypervisor attack that started with one stolen credential. The aftermath is extraordinary, and it can bring production to a full stop,” said Anthony Gadient, CEO of Vali Cyber. “CLI-MFA cuts off that path. It lets our customers build a foundation that holds even when credentials are lost.”
Built to Scale Across the Largest, Most Segmented Enterprises
ZeroLock 5 is also architected for enterprises spanning multiple data centers and segmented network zones. The collector, the portion of the management console used to communicate with security agents, is now a standalone service. Collectors are deployable remotely and independent of where the central ZeroLock Management Console lives. Standardized, reusable deployments bundle all configuration into one definition that generates ready-to-run installer commands, letting teams roll out protection across dozens or hundreds of sites from a single repeatable blueprint.
“Patching is not a complete strategy at this layer. There will always be another ESX CVE, and an enterprise running hundreds of hosts across segmented zones cannot chase them fast enough,” said Austin Gadient, CTO and co-founder of Vali Cyber. “What companies can do is make the attacker’s post-access behavior impossible. ZeroLock 5 lets them enforce that at scale, from a single blueprint, across every site.”
Additional Capabilities
ZeroLock 5 also adds:
- Auditable policy lifecycle management, moving each policy from draft to published to retired with full revision tracking
- Standardized agent installation through named, reusable deployments that generate ready-to-run installer commands
- Multi-SIEM activity forwarding with presets for Microsoft Sentinel, Splunk, Sumo Logic, and Google SecOps
- Scheduled alert-only mode
- vCenter host inventory import
- Support for VCF as well as ESX 6.7+, older versions supported upon request
- Simplified licensing
Available Now
As attackers set their sights on the hypervisor layer, the question facing every enterprise is no longer whether that infrastructure will be targeted, but whether it’s well protected when it is. ZeroLock 5 is available now to existing customers as an upgrade and to new customers as part of a new deployment.
Schedule Your Demo of Version 5
________________________________________
About Vali Cyber
Vali Cyber® secures where attacks have the most impact: mission critical systems. While most defenses focus on endpoints, Vali Cyber identified Linux and hypervisors as critical yet under protected. Built for this reality, ZeroLock® delivers preemptive security with CLI-MFA, exploit prevention, deep hypervisor visibility, and AI-driven behavioral detection. By operating at the hypervisor layer, ZeroLock stops threats in real time without performance impact or added overhead. If incidents occur, automated rollback restores workloads in seconds, ensuring uptime. Recognized by Gartner as a Key Startup in Security Software, Vali Cyber leads by protecting the foundation of modern infrastructure others overlook.
Learn more at valicyber.com.
Media Contact
Megan Howard
VP Marketing, Vali Cyber
+1 (412) 551-0938
[email protected]
Overriding ESX Host Acceptance Level with Secure Boot Enabled
Vali Cyber and Carahsoft Partner to Deliver Preemptive Hypervisor Security Platform to Government Agencies
Announcing new partner-supported workflows for Google Security Operations
AI Is Moving Into Production Workflows, And So Are The Risks
How To Reduce Cyber Risk Before It Becomes Business Impact
When Ransomware ‘Brands’ Disappear, Their Tactics Don’t
As Workloads Move Back On-Prem, Hypervisors Emerge as a Quiet Mid-Market Risk
Hypervisor Ransomware: The Hidden Board-Level Attack Vector
Tech Scenes Unplugged Podcast
What Executives Need To Know About Threats Like Scattered Spider—And How To Avoid The Next Costly Breach
Vali Cyber Secures Growth Round to Meet Rising Demand for Hypervisor Ransomware Protection Amid Rising Attacks
How Virtual Patching Helps Protect Hypervisors Against Exploits
Hypervisor Ransomware: Why The C-Suite Can’t Ignore MITRE ATT&CK V17