Between August 28 and August 30, a BGP hijacking attack rerouted a block of Hetzner-hosted IP addresses belonging to Softaculous, the vendor of Virtualizor. This allowed attackers to divert traffic intended for Softaculous software update systems and its client/billing portal.
The BGP hijacking enabled the attackers to deliver a malicious Virtualizor update package to a small number of installations that checked for updates during the incident window. Softaculous confirmed that only a handful of servers were affected, not the general user base.
Softaculous recommends that Virtualizor operators check for the presence of a service named "/etc/systemd/system/java-jre-update.service". If found, administrators should rotate and restrict API credentials, and audit systems for unauthorized SSH keys, accounts, scheduled tasks, and outbound connections. Users who accessed the client area or entered payment information during the incident should reset passwords and monitor activity.
Routing has been restored, and a new version, Virtualizor 3.2.9.9, was released on September 1, including a "Security Analyzer" tool. Softaculous plans to implement cryptographic signing for all future software packages and migrate to new infrastructure.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic and deliver a malicious Virtualizor update package, resulting in root-level compromise on some installations. The incident highlights the risks of unverified software updates and the potential for BGP vulnerabilities to be exploited for supply chain attacks.
Softaculous's Virtualizor users received malicious software updates for two days due to a BGP hijack that diverted internet traffic to attacker-controlled servers. This incident highlights the vulnerability of software update mechanisms to network-level attacks and the potential for supply chain compromise.
Attackers performed a BGP hijack targeting IP addresses used by Softaculous, a provider of cloud management software, to distribute malware disguised as updates. The incident exploited routing security weaknesses at hosting provider Hetzner Online and Softaculous's lack of cryptographic verification for update packages. This supply chain attack highlights vulnerabilities in update mechanisms for critical infrastructure software.
Hackers used BGP hijacking to redirect traffic for Virtualizor's update infrastructure, delivering malicious updates to a small number of installations. Softaculous, the vendor, released a new Virtualizor version and advised users to check for a malicious service and reset credentials.