bleeping-computer · Crawled Sep 1, 2026
Hackers push malicious Virtualizor update in BGP hijacking attack
1 IoCs
Read original article ↗
AI Summary
Hackers conducted a BGP hijacking attack against Hetzner-hosted IP addresses used by Softaculous to redirect traffic from its software update systems and client portal. During the incident window from August 28 to August 30, 2026, a malicious Virtualizor update was delivered to a small number of installations. The attack allowed threat actors to intercept update requests and potentially compromise affected servers. Softaculous has since restored routing, revoked the fraudulent certificate, and released a new secure version of Virtualizor with improved security tooling.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | /etc/systemd/system/java-jre-update.service | Details → |