SOFTACULOUS' , a web hosting application provider, experienced a BGP hijacking attack from August 28 to 30, 2026, which rerouted traffic to attacker-controlled servers. This attack led to a delivery of malicious software updates for its Virtualizor users. The hijacker used a valid TLS certificate from Let’s Encrypt to disguise the redirection, affecting a limited number of installations that checked for updates during the incident. Softaculous has advised users to review their systems for compromises and has released a patched version of Virtualizor with enhanced security features.
Malicious Virtualizor Update Served via BGP Hijacking
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Malicious Virtualizor Update Served via BGP Hijacking
www.securityweek.com
-
Virtualizor Supply-Chain Attack: BGP Hijack Plants Backdoors
securityonline.info