BGP Hijack of Softaculous IPs Pushed Malicious Updates to Virtualizor Servers
Attackers hijacked a /24 prefix hosting Softaculous update servers by exploiting lax RPKI settings at Hetzner Online and a forged AS path. Because Virtualizor update clients did not verify packages cryptographically, diverted traffic could receive malware disguised as updates. The hijack ran intermittently over 33 hours and also defeated Let's Encrypt domain validation.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.