www.securityweek.com 9/2/2026, 12:00:57 PM · external

Malicious Virtualizor Update Served via BGP Hijacking

Malicious Virtualizor Update Served via BGP Hijacking

SOFTACULOUS' , a web hosting application provider, experienced a BGP hijacking attack from August 28 to 30, 2026, which rerouted traffic to attacker-controlled servers. This attack led to a delivery of malicious software updates for its Virtualizor users. The hijacker used a valid TLS certificate from Let’s Encrypt to disguise the redirection, affecting a limited number of installations that checked for updates during the incident. Softaculous has advised users to review their systems for compromises and has released a patched version of Virtualizor with enhanced security features.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline