ELSEIF
Your brief EB
225 stories from 207 feeds 1243 clusters Refreshed 46 minutes ago next pull 00:30

SECURITY Signal 124

BGP hijack of Softaculous IP space delivered malicious Virtualizor updates with valid TLS certificates

Illustration only Photo by Alp Duran on Unsplash

A BGP hijack of Softaculous's 162.55.80.0/24 block at Hetzner diverted traffic to an attacker who obtained valid Let's Encrypt certificates and pushed malicious Virtualizor update packages to a small number of servers.

WHY IT MATTERS

The attacker bypassed TLS validation by hijacking the certificate authority's domain-ownership check, so affected clients saw no warnings. Softaculous cannot produce a definitive list of affected servers because malicious responses were served directly by the attacker and never reached their logs, meaning every Virtualizor operator must self-check.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

AS62390 (NexonHost) announced 162.55.80.0/24 without authorization via AS6204 (Zet.net), overriding Hetzner's legitimate /16 route with a more specific /24.

02

The attacker obtained valid Let's Encrypt TLS certificates for virtualizor.com and related domains because the CA's automated domain validation was also routed through the hijack.

03

A malicious Virtualizor update package was delivered to a small number of installations that checked for updates during the diversion, but no definitive list of affected servers exists.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
virtualizor.com via Lobsters Security Incident – BGP Hijacking – Virtualizor Open ↗