BGP Hijacking Delivers Malicious Virtualizor Updates to Servers
Article Content
A BGP hijacking incident targeted Softaculous infrastructure, redirecting traffic for Virtualizor update services to attacker-controlled systems. This allowed the delivery of a malicious update package to a limited number of servers, specifically affecting the IP range 162.55.80.0/24 hosted by Hetzner. The attack occurred between 20:57 UTC on August 28 and 06:10 UTC on August 29, 2026. Virtualizor is widely used by hosting providers to manage VPS nodes across various virtualization technologies. The incident has raised concerns among users of the affected systems regarding the integrity of their updates and potential vulnerabilities introduced by the malicious package. The full scope of the impact and the number of affected servers remain unclear, but reports indicate that only a small number were compromised. Security teams are advised to monitor their systems for unusual activity related to Virtualizor updates.
Key Points: • BGP hijacking redirected Virtualizor update traffic to attackers. • Malicious updates affected servers in the IP range 162.55.80.0/24. • The attack occurred from August 28 to August 29, 2026.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.