Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Protests in Spain over government’s handling of Ceuta migrant crisis

    September 2, 2026

    Andy Burnham faces an impossible job. At least he’s got a secret weapon – Kemi Badenoch | John Crace

    September 2, 2026

    Uber announces 3,000 job cuts as part of major restructure

    September 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Protests in Spain over government’s handling of Ceuta migrant crisis
    • Andy Burnham faces an impossible job. At least he’s got a secret weapon – Kemi Badenoch | John Crace
    • Uber announces 3,000 job cuts as part of major restructure
    • ChatGPT Ads passes $1B run rate in 200 days
    • Malicious Virtualizor Update Served via BGP Hijacking
    • SEC Chair Predicts Clarity Act Passage This Month
    • Alzheimer’s may leave a mark on the brain long before plaques appear
    • Michael Painter put Indigenous land rights at the center of conservation
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Malicious Virtualizor Update Served via BGP Hijacking

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 2, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Softaculous’ Virtualizor users were served malicious software updates for two days after a threat actor diverted internet traffic to attacker-controlled servers.

    A provider of applications for web hosting, Softaculous offers an auto-installer tool for over 400 popular web applications. Virtualizor is its web-based Virtual Server (VPS) management control panel.

    Between August 28 and August 30, a block of Softaculous IP addresses was hit by a BGP hijack attack: a threat actor used a technically valid TLS certificate for the company’s domains to divert traffic to attacker infrastructure.

    The IP addresses affected by the BGP hijack, Softaculous says, were used for software updates, client area/billing, and other services.

    “We have confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted. This affected a handful of servers rather than the general Virtualizor user base,” the company says.

    Softaculous encourages all Virtualizor operators to check for potential compromises, as it cannot tell how many servers might have been affected. The malicious traffic never reached the company’s logs.

    Advertisement. Scroll to continue reading.

    “We have not identified a malicious package for any other product; that investigation is ongoing,” the company notes, adding that it has fully restored traffic to its legitimate servers.

    The BGP hijack started at approximately 20:57 UTC on 28 August 2026, when AS62390 (NexonHost) began announcing a portion of German web hosting provider and data center operator Hetzner’s address space, including IP addresses for Softaculous systems.

    “This announcement was more specific than Hetzner’s normal announcement of the surrounding block (162.55.0.0/16), so under standard BGP route selection it took precedence on every network that accepted it. The announcement retained AS24940 (Hetzner) on the AS path as the apparent origin,” Softaculous notes.

    Next, the threat actor obtained a valid TLS certificate for Softaculous domains from Let’s Encrypt, “because the certificate authority’s automated domain-ownership validation was also routed through the hijack,” the company explains.

    The hijacker could then redirect traffic to their server without triggering a browser or client certificate warning.

    According to Softaculous, only a small number of Virtualizor instances were served a malicious package: those that checked for an update and completed it during the hijack window. The traffic was intermittently diverted for 22 hours (and almost no diversion occurred during an 11-hour window mid-incident).

    “Our product update clients did not yet cryptographically verify update packages, so a modified package would not have been rejected on that basis. We believe only a small number of servers were actually affected, but we cannot produce a definitive list, so please treat every Virtualizor server as in scope for checks,” the company notes.

    Softaculous has provided a known indicator of compromise (IoC) and encourages users to reset their client-area passwords, review their account activity, and regenerate their API keys.

    The company has released a version of Virtualizor 3.2.9.9 containing a mitigation tool for known exploits and is implementing a code signing mechanism for all packages.

    Related: Rust Supply Chain Attack Linked to North Korean Hackers

    Related: Trivy, Not LiteLLM Behind the 2,500 Org Compromise

    Related: Fortune 500 Companies Hit in Azure Data Theft Campaign

    Related: Critical Flaw Allowed to Azure Cosmos DB Pwnage

    BGP Hijacking Malicious Served update Virtualizor
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Exploit Published for Fresh Cleo Harmony Vulnerability

    Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

    OpenLeash Adds a Human Check to Risky AI Agent Actions

    Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

    Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

    UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Protests in Spain over government’s handling of Ceuta migrant crisis

    September 2, 2026

    Andy Burnham faces an impossible job. At least he’s got a secret weapon – Kemi Badenoch | John Crace

    September 2, 2026

    Uber announces 3,000 job cuts as part of major restructure

    September 2, 2026

    ChatGPT Ads passes $1B run rate in 200 days

    September 2, 2026
    Latest Posts

    Australia news live: Reformers member tells hearing he used factional funds to pay for bucks night; Taylor refuses to answer multiple Icac-related questions | Australia news

    July 31, 2026

    Trump administration to end Medicare Part D subsidy program. Will costs increase?

    July 31, 2026

    FP Live: Daniel Yergin on Why Energy Prices Didn’t Soar Higher This Year

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Protests in Spain over government’s handling of Ceuta migrant crisis

    September 2, 2026

    Andy Burnham faces an impossible job. At least he’s got a secret weapon – Kemi Badenoch | John Crace

    September 2, 2026

    Uber announces 3,000 job cuts as part of major restructure

    September 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.