The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

Independent. Nonpartisan. Untested in production.

Wednesday, September 2, 2026 ARS TECHNICA
Security!

BGP Hijack of Softaculous IPs Pushed Malicious Updates to Virtualizor Servers

Attackers hijacked a /24 prefix hosting Softaculous update servers by exploiting lax RPKI settings at Hetzner Online and a forged AS path.

ARS TECHNICA — Because Virtualizor update clients did not verify packages cryptographically, diverted traffic could receive malware disguised as updates. The hijack ran intermittently over 33 hours and also defeated Let's Encrypt domain validation.

Read the original source ↗

Rate this article: 0

Readers’ Forum

No contributions yet — open the debate.

◀ Briefs — Page D1

All stories real, just louder · The Daily Commit · Screen edition · Imprint · Privacy Policy