Malicious Virtualizor Update Served via BGP Hijacking

Malicious Virtualizor Update Served via BGP Hijacking
Softaculous said Virtualizor users were exposed to malicious software updates after a BGP hijack diverted update traffic to attacker-controlled servers for parts of two days. The company urges all Virtualizor operators to check for compromise, reset client-area passwords, review account activity, and regenerate API keys while it rolls out fixes and code signing. #Softaculous #Virtualizor #Letsencrypt #NexonHost #Hetzner

Keypoints

  • A BGP hijack diverted Softaculous traffic to attacker-controlled infrastructure.
  • Malicious Virtualizor update packages were delivered to a small number of installations.
  • The hijack used a valid TLS certificate obtained through diverted validation traffic.
  • Softaculous says update clients did not yet cryptographically verify packages.
  • Users are advised to check for compromise and update to Virtualizor 3.2.9.9.

Read More: https://www.securityweek.com/malicious-virtualizor-update-served-via-bgp-hijacking/