Feed›Network & Infrastructure›Hackers push malicious Virtualizor update in BGP hijacking a...
Network & InfrastructureBleeping Computer
6.8 — HIGH

Hackers push malicious Virtualizor update in BGP hijacking attack

📅 1 September 2026 at 14:45 UTC📰 Bleeping ComputerView original source ↗
Hackers push malicious Virtualizor update in BGP hijacking attack

Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Hackers exploited a BGP hijacking attack to deliver malicious Virtualizor updates, targeting hosting providers' VPS management software. The attackers successfully redirected update requests to malicious servers, affecting a small number of installations.

⚙️Technical Details
Affected Systems
Virtualizor VPS management software
Attack Vectors
BGP routing hijacking attackMalicious Virtualizor updates
💥Impact Assessment
Severity: high
Who Is at Risk
Hosting providers' users with outdated or vulnerable Virtualizor installations
🛡️Recommended Actions
1Rotate and restrict API credentials
2Audit systems for unauthorized SSH keys, accounts, scheduled tasks, and outbound connections
3Reset passwords, review account activity, and monitor card statements for users who accessed the Softaculous client area or entered payment information during the incident window
📦Affected Products
Virtualizor VPS management software

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed