← All stories
● Covered by 4 sources · 4 reportsMedium impact4 negative

Hackers deliver malicious Virtualizor update via BGP hijacking

🔄 Updated 29d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • BGP hijacking redirected Virtualizor update traffic.
  • Malicious updates delivered to a small number of installations.
  • Softaculous released Virtualizor 3.2.9.9 with a Security Analyzer.
  • Users advised to check for a specific service and reset credentials.
  • BGP hijack targeted IP addresses used by Softaculous.
  • Hetzner Online's routing security setup was exploited.
  • Attackers obtained valid TLS certificates for Softaculous domains.
  • Softaculous is based in the United Arab Emirates.
  • IP addresses were used for updates, client area, and billing.
  • Malicious updates were served between August 28 and August 30.
  • Five of 34 checked Virtualizor hypervisors sustained root-level compromise.
  • The incident window was from August 28 at 20:57 UTC to August 30 at 06:10 UTC.
  • Virtualizor released Patch 9 with a Security Analyzer on September 1.
  • Cryptographic package signing for Virtualizor remains future work.

BGP Hijacking Incident

Between August 28 and August 30, a BGP hijacking attack rerouted a block of Hetzner-hosted IP addresses belonging to Softaculous, the vendor of Virtualizor. This allowed attackers to divert traffic intended for Softaculous software update systems and its client/billing portal.

Malicious Update Delivery

The BGP hijacking enabled the attackers to deliver a malicious Virtualizor update package to a small number of installations that checked for updates during the incident window. Softaculous confirmed that only a handful of servers were affected, not the general user base.

Vendor Recommendations and Response

Softaculous recommends that Virtualizor operators check for the presence of a service named "/etc/systemd/system/java-jre-update.service". If found, administrators should rotate and restrict API credentials, and audit systems for unauthorized SSH keys, accounts, scheduled tasks, and outbound connections. Users who accessed the client area or entered payment information during the incident should reset passwords and monitor activity.

Routing has been restored, and a new version, Virtualizor 3.2.9.9, was released on September 1, including a "Security Analyzer" tool. Softaculous plans to implement cryptographic signing for all future software packages and migrate to new infrastructure.

Updates

🕒 2026-09-02 · new reporting from The Hacker News
  • Five of 34 checked Virtualizor hypervisors sustained root-level compromise.
  • The incident window was from August 28 at 20:57 UTC to August 30 at 06:10 UTC.
  • Virtualizor released Patch 9 with a Security Analyzer on September 1.
  • Cryptographic package signing for Virtualizor remains future work.
🕒 2026-09-02 · new reporting from Ars Technica, SecurityWeek
  • BGP hijack targeted IP addresses used by Softaculous.
  • Hetzner Online's routing security setup was exploited.
  • Attackers obtained valid TLS certificates for Softaculous domains.
  • Softaculous is based in the United Arab Emirates.
  • IP addresses were used for updates, client area, and billing.
  • Malicious updates were served between August 28 and August 30.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic and deliver a malicious Virtualizor update package, resulting in root-level compromise on some installations. The incident highlights the risks of unverified software updates and the potential for BGP vulnerabilities to be exploited for supply chain attacks.

Softaculous's Virtualizor users received malicious software updates for two days due to a BGP hijack that diverted internet traffic to attacker-controlled servers. This incident highlights the vulnerability of software update mechanisms to network-level attacks and the potential for supply chain compromise.

Attackers performed a BGP hijack targeting IP addresses used by Softaculous, a provider of cloud management software, to distribute malware disguised as updates. The incident exploited routing security weaknesses at hosting provider Hetzner Online and Softaculous's lack of cryptographic verification for update packages. This supply chain attack highlights vulnerabilities in update mechanisms for critical infrastructure software.

Hackers used BGP hijacking to redirect traffic for Virtualizor's update infrastructure, delivering malicious updates to a small number of installations. Softaculous, the vendor, released a new Virtualizor version and advised users to check for a malicious service and reset credentials.