Network & InfrastructureBleeping Computer
6.8 — HIGH
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Hackers exploited a BGP hijacking attack to deliver malicious Virtualizor updates, targeting hosting providers' VPS management software. The attackers successfully redirected update requests to malicious servers, affecting a small number of installations.
⚙️Technical Details
Affected Systems
Virtualizor VPS management software
Attack Vectors
BGP routing hijacking attackMalicious Virtualizor updates
💥Impact Assessment
Severity: high
Who Is at Risk
Hosting providers' users with outdated or vulnerable Virtualizor installations
🛡️Recommended Actions
1Rotate and restrict API credentials
2Audit systems for unauthorized SSH keys, accounts, scheduled tasks, and outbound connections
3Reset passwords, review account activity, and monitor card statements for users who accessed the Softaculous client area or entered payment information during the incident window
📦Affected Products
Virtualizor VPS management software
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
