Home / Sep 03, 2026 / Story
0
#6 The Hacker News general September 02, 2026 at 13:12 UTC

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

By [email protected] (The Hacker News)

AI Summary

Threat actors executed a BGP hijack against Softaculous update infrastructure to deliver a malicious Virtualizor VPS management update package, establishing persistent root access on compromised hypervisors. The attack window ran from approximately August 28 at 20:57 UTC, and a hosting provider confirmed root-level compromise on 5 of 34 checked Virtualizor nodes. The use of a technically valid TLS certificate for Softaculous domains allowed the attack to bypass certificate validation checks, underscoring BGP's role as a critical trust dependency.

Relevance score: 83.0/100

# More from September 03