arstechnica.com 9/2/2026, 11:26:05 AM · external

Well-executed BGP hijattack uses hijacked IPs to infect real networks

Well-executed BGP hijattack uses hijacked IPs to infect real networks

A supply-chain attack was conducted by hackers exploiting BGP (Border Gateway Protocol) to hijack IP addresses assigned to Softaculous, a company providing software management solutions. This allowed the attackers to push malware disguised as legitimate updates to users. Major security flaws were identified, including lax routing security at Softaculous’s hosting provider, Hetzner Online, and a lack of software update validation by Softaculous.

The incident underscored vulnerabilities in BGP and the threats posed by lax configurations and inadequate monitoring. Despite measures like RPKI (Resource Public Key Infrastructure) to prevent such hijacks, the attack demonstrated that oversight could lead to significant cybersecurity breaches.

View full article

Article by CyberSIXT