Systems without current system updates can be hacked, nothing is "new" or "arguent" on this. And PVE7 and PVE8 won't get any security updates any more so it's somehow expected that they get owned. Even if you don't connect them directly to the Internet a bad actor could still first get some access to another (directly connected) machine in your network and use it as a jump host to your PVE host. Nothing on this an ProxmoxVE issue but with systems, which are not updates. It doesn't matter if the culprit is a lazy systemupdate or some some damager with title "change manager" or "compilance manager" who thinks "never change a running system" is still a good idea in the age of KI assisted "security research" and hacking. It wasn't a good idea before to install updates only one time a year or less. In this age it's gross neglect and incompetence to have a EOL system in production instead of a museum. Nothing on this is an ProxmoxVE or Debian or Linux issue at all.
And I also don't get the point of socket puppet accounts which says "I'm affected too". Yes, you are affected from your miss-management, change the broken processes in your company, but it's off topic here.