ELSEIF
Your brief EB
507 stories from 214 feeds 1270 clusters Refreshed 50 minutes ago next pull 00:39

SECURITY Signal 51

BGP hijack diverted Softaculous traffic for 33 hours, delivered malicious Virtualizor updates

A 33-hour BGP hijack diverted Softaculous traffic through an attacker-controlled server that held a valid Let's Encrypt TLS certificate, enabling delivery of malicious Virtualizor update packages to installations that lacked cryptographic package verification.

WHY IT MATTERS

The incident shows that BGP hijacking combined with automated certificate issuance can fully bypass TLS protections, and that software update mechanisms without cryptographic verification remain critically exposed to supply-chain compromise. Any Virtualizor operator whose server was active during the incident window should assume potential compromise, since no definitive list of affected installations exists.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

An attacker announced a more specific IP range than Hetzner's normal advertisement, causing standard BGP route selection to divert traffic to their server across two waves totaling roughly 33 hours.

02

The attacker obtained a valid Let's Encrypt TLS certificate because automated domain-ownership validation was also routed through the hijack, preventing certificate warnings on affected connections.

03

Virtualizor's update client did not cryptographically verify packages, allowing a malicious update to be delivered to an unknown number of installations with no definitive list of affected servers.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
www.theregister.com - Articles 33-hour BGP hijack of Softaculous traffic prompts security scramble Open ↗