- 700% surge in hypervisor attacks: Reports indicate a 700% increase in attacks targeting VMware’s ESXi hypervisors.
- 100% coverage of ESXi threats: ZeroLock addresses all attack techniques cataloged for ESXi in MITRE ATT&CK framework.
- Preemptive defense: ZeroLock prevents attacks before they execute, reducing reliance on reactive measures.
Experts would likely conclude that this partnership represents a critical advancement in securing government digital infrastructure by addressing the often-overlooked hypervisor layer with preemptive, AI-driven defenses.
Securing the Foundation: A New Defense for Government's Digital Core
NEW YORK, NY – June 23, 2026 – In a move to fortify the digital bedrock of U.S. government operations, cybersecurity innovator Vali Cyber has partnered with Carahsoft Technology Corp., the go-to solutions provider for the public sector. The partnership, announced today, will make Vali Cyber’s preemptive security platform, ZeroLock®, available to federal, state, and local agencies, addressing a critical and often overlooked vulnerability in modern IT infrastructure.
Under the agreement, Carahsoft will act as Vali Cyber’s Master Government Aggregator®, streamlining access to ZeroLock through its vast network of reseller partners and major government contracts, including NASA’s SEWP V and the Army’s ITES-SW2. This collaboration signals a significant shift in strategy, moving beyond reactive defenses to proactively shield the very foundation upon which government services, data processing, and even private AI initiatives are built.
“As the AI threat grows, our partnership with Carahsoft enables us to bring a new preemptive approach to infrastructure security to Government agencies,” said Anthony Gadient, CEO & Cofounder of Vali Cyber. “As threat actors increasingly target the virtualization layer, agencies need preemptive protections that secure the hypervisor without disrupting operations.”
The Hidden Battlefield: The Hypervisor Under Siege
For most, the term “hypervisor” is obscure technical jargon. Yet, this software layer is the linchpin of modern computing, creating and running the virtual machines (VMs) that power everything from government databases to cloud services. A single hypervisor can host dozens of VMs, making it an incredibly high-value target for adversaries. A successful attack doesn't just compromise one system; it can topple an entire digital ecosystem, representing what security experts call a catastrophic “blast radius.”
Historically, this foundational layer has been a blind spot for security. Traditional Endpoint Detection and Response (EDR) tools, designed for user laptops or individual servers, do not run on hypervisors. This has created a dangerous gap, one that threat actors are now exploiting with alarming frequency. Reports indicate that attacks targeting VMware’s ESXi, a dominant hypervisor in government and enterprise environments, have surged by over 700% in recent years. High-profile victims like MGM and Johnson Controls have suffered nine-figure losses from hypervisor-level ransomware attacks.
This escalating threat has not gone unnoticed. The cybersecurity community’s own standard-bearer, MITRE, recently updated its influential ATT&CK® framework to include specific Tactics, Techniques, and Procedures (TTPs) used to attack ESXi. This formal recognition validates the hypervisor as a distinct and critical battleground. In a stark illustration of the threat, MITRE itself disclosed in May 2024 that nation-state actors had breached its own network by targeting its ESXi infrastructure.
A Preemptive Shift in Cyber Defense
Vali Cyber’s ZeroLock platform is engineered to address this specific vulnerability with a philosophy of preemption, not reaction. Instead of waiting for an attack to execute and then cleaning up the damage, ZeroLock aims to prevent it from happening in the first place. Recognized by Gartner as a Key Startup in Security Software, the company’s solution provides a multi-layered defense directly at the hypervisor level.
One of its most crucial features is the implementation of command-line multifactor authentication (CLI-MFA). Many hypervisor breaches begin with stolen credentials used to log in via SSH, a common remote access method. By requiring a second factor of authentication, ZeroLock effectively neutralizes this primary attack vector. The platform also employs application filtering and behavioral controls, preventing unauthorized tools or malicious scripts from ever running on the hypervisor.
For threats that attempt to exploit unknown or unpatched vulnerabilities—so-called zero-days—ZeroLock deploys a form of “virtual patching.” It blocks the malicious behavior of an exploit at runtime, protecting the system without requiring immediate, disruptive patching and reboots. This is critical for government agencies running mission-critical systems where downtime is not an option. Crucially, the platform claims to address 100% of the ESXi attack techniques cataloged in the new MITRE ATT&CK framework.
Should an attack somehow bypass these preventive layers, ZeroLock’s AI-driven detection engine identifies and stops threats like ransomware in real time. Its automated remediation can instantly roll back any encrypted or damaged files to their pre-attack state, ensuring operational continuity. This entire system operates from a lightweight agent that, according to the company, has no discernible performance impact, a key factor for its certification by Broadcom as a validated solution for its VMware virtualization suite.
Bridging the Procurement Gap for National Security
The most advanced technology is ineffective if it can’t be deployed where it’s needed most. This is where Carahsoft’s role becomes pivotal. The world of government procurement is a labyrinth of regulations, contracts, and compliance requirements that can stall the adoption of innovative solutions. As a “Master Government Aggregator,” Carahsoft specializes in navigating this complexity.
By adding ZeroLock to established, pre-vetted contract vehicles like NASA SEWP V and ITES-SW2, Carahsoft provides government agencies a trusted and expedited pathway to acquire this specialized security. It removes the friction that often prevents cutting-edge tools from reaching the public sector IT managers on the front lines. This partnership effectively bridges the gap between a startup’s innovation and the immense scale of government need.
“Vali Cyber empowers agencies with a comprehensive, prevention-first platform to defend against evolving threats,” said Ryon Williams, the Sales Manager leading the Vali Cyber team at Carahsoft. “Carahsoft and our reseller partners look forward to working with Vali Cyber to deliver advanced, AI-driven detection and remediation capabilities to the Public Sector.”
As federal and defense organizations increasingly rely on private AI and virtualization to process sensitive and classified data, the security of the underlying infrastructure becomes a matter of national importance. This collaboration is more than a business deal; it is a systemic upgrade to the digital immune system that protects our collective public infrastructure, ensuring the systems that allow our communities to thrive are built on a foundation that is secure by design.
