Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
BGP Hijack Targets Softaculous, Delivers Malicious Update

BGP Hijack Targets Softaculous, Delivers Malicious Update

Posted on September 1, 2026 By CWS

Last week, cyber attackers executed a BGP routing hijack targeting Softaculous, redirecting traffic to distribute a malicious Virtualizor update. This incident, reported by a vendor, impacted several hypervisor servers.

Impact on Hosting Providers

Virtualizor is crucial for managing VPS nodes across platforms like KVM, Xen, LXC, OpenVZ, and Proxmox. A single master server can oversee hundreds of virtualization servers, making the malicious update a significant threat to hosting infrastructure, rather than isolated website panels. The product’s extensive list of network operations center (NOC) partners further highlights the potential for widespread impact.

The hijack occurred between 20:57 UTC on August 28, 2026, and 06:10 UTC on August 30. The attackers used AS62390 (NexonHost) to announce 162.55.80.0/24, a Hetzner block, through AS6204 (Zet.net), affecting Softaculous update and billing systems.

Routing Details and TLS Exploitation

Normally, Hetzner advertises 162.55.0.0/16, but the hijackers’ more specific prefix took precedence. By keeping AS24940 (Hetzner) in the routing path, they avoided detection as the origin. The diversion allowed the attackers to obtain a legitimate Let’s Encrypt certificate for Virtualizor domains, preventing TLS warnings and compromising client logins during the attack window.

According to RIPE RIS data, all 368 collector peers carried the rogue route at some point, with about 72% of them selecting the hijacked path during active phases. The diversion was intermittent due to approximately 10,600 withdrawals, limiting the number of update checks completed on the attacker’s server.

Security Measures and Recommendations

Virtualizor confirmed the interception on August 29, noting that its update clients did not cryptographically verify packages, making the hijack effective in executing attacker code. Although only a few installations received the malicious payload, the incident underscores the vulnerability of root-compromised hypervisors.

Operators are advised to treat every Virtualizor host as potentially compromised. The known indicator of compromise is the presence of /etc/systemd/system/java-jre-update.service. Virtualizor recommends contacting the vendor if found, rather than deleting it, and suggests rotating API keys, restricting SSH and API access to trusted IPs, and auditing for unknown accounts or scheduled jobs.

Users who accessed the Softaculous client area during the breach should reset passwords and regenerate API keys. Routing has since been restored, with no further diversions after 06:10 UTC on August 30.

Proactive threat intelligence and rapid incident response are essential to prevent future security breaches. Integrating threat intelligence into security operations centers (SOCs) can enhance defense mechanisms against such attacks.

Cyber Security News Tags:API security, BGP hijack, Cybersecurity, Hetzner, hijack prevention, hosting security, malicious update, network security, routing attack, server security, Softaculous, TLS certificate, Virtualizor, Virtualizor update, VPS management

Post navigation

Previous Post: PaperCut Vulnerabilities Lead to Active Cyber Intrusions

Related Posts

Notion Public Pages Expose Editor Information Notion Public Pages Expose Editor Information Cyber Security News
Critical Amazon Redshift JDBC Driver Flaw Exposes RCE Risk Critical Amazon Redshift JDBC Driver Flaw Exposes RCE Risk Cyber Security News
Malware Uses Compromised WordPress Sites for C2 Operations Malware Uses Compromised WordPress Sites for C2 Operations Cyber Security News
Eurofiber Data Breach – Hackers Exploited Vulnerability to Exfiltrate Users’ Data Eurofiber Data Breach – Hackers Exploited Vulnerability to Exfiltrate Users’ Data Cyber Security News
DHS Asks OpenAI To Share Information on ChatGPT Prompts Used By Users DHS Asks OpenAI To Share Information on ChatGPT Prompts Used By Users Cyber Security News
Ransomware Scam Targets Victims with Fake Recovery Offers Ransomware Scam Targets Victims with Fake Recovery Offers Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • BGP Hijack Targets Softaculous, Delivers Malicious Update
  • PaperCut Vulnerabilities Lead to Active Cyber Intrusions
  • Anthropic Enhances Claude Security Following AI Breaches
  • Brave’s Email Aliases Enhance Privacy in Browser Update
  • EU Classifies ChatGPT as Major Search Engine Post User Surge

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • BGP Hijack Targets Softaculous, Delivers Malicious Update
  • PaperCut Vulnerabilities Lead to Active Cyber Intrusions
  • Anthropic Enhances Claude Security Following AI Breaches
  • Brave’s Email Aliases Enhance Privacy in Browser Update
  • EU Classifies ChatGPT as Major Search Engine Post User Surge

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark