← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Hackers deliver malicious Virtualizor update via BGP hijacking

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • BGP hijacking redirected Virtualizor update traffic.
  • Malicious updates delivered to a small number of installations.
  • Softaculous released Virtualizor 3.2.9.9 with a Security Analyzer.
  • Users advised to check for a specific service and reset credentials.

BGP Hijacking Incident

Between August 28 and August 30, a BGP hijacking attack rerouted a block of Hetzner-hosted IP addresses belonging to Softaculous, the vendor of Virtualizor. This allowed attackers to divert traffic intended for Softaculous software update systems and its client/billing portal.

Malicious Update Delivery

The BGP hijacking enabled the attackers to deliver a malicious Virtualizor update package to a small number of installations that checked for updates during the incident window. Softaculous confirmed that only a handful of servers were affected, not the general user base.

Vendor Recommendations and Response

Softaculous recommends that Virtualizor operators check for the presence of a service named "/etc/systemd/system/java-jre-update.service". If found, administrators should rotate and restrict API credentials, and audit systems for unauthorized SSH keys, accounts, scheduled tasks, and outbound connections. Users who accessed the client area or entered payment information during the incident should reset passwords and monitor activity.

Routing has been restored, and a new version, Virtualizor 3.2.9.9, was released on September 1, including a "Security Analyzer" tool. Softaculous plans to implement cryptographic signing for all future software packages and migrate to new infrastructure.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~24 min · 20 stories · Sep 01

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Hackers used BGP hijacking to redirect traffic for Virtualizor's update infrastructure, delivering malicious updates to a small number of installations. Softaculous, the vendor, released a new Virtualizor version and advised users to check for a malicious service and reset credentials.