
You are touching the third rail. The documented kill chain … CVE-2023-20198: Perfect 10.0 severity score. Creates admin accounts remotely. No authentication needed. CVE-2023-20273: Elevates to root access. CVE-2018-0171: Patched SEVEN YEARS AGO. Still exploited because telecom infrastructure hadn’t updated since 2018. But here’s what should concern everyone: The malware, called Demodex, operates at KERNEL level. Below the operating system. It hooks into system calls to hide itself. When admins run diagnostics, the rootkit filters what they can see. You look for the infection. The infection decides what you find. It survives reboots. It survives reimaging. It survives patches. Cisco Talos documented one network compromised for 3+ years. CISA officially states they “cannot say with certainty” it’s been removed. You know what does remove it? Physical hardware replacement. That’s not a software problem. That’s an architecture problem. And you’re right to ask whether the architecture was the point all along.
Post summary
The message documents that several CVEs are actively abused by a kernel‑level rootkit, with evidence of persistence for years—highlighting active exploitation in the wild.

