Hackers executed a sophisticated BGP hijacking attack against Softaculous, a popular web software management platform, by exploiting lax routing security at hosting provider Hetzner Online and the absence of code signing for software updates. The attackers redirected update traffic to their own servers, pushing malware disguised as legitimate Virtualizor and Softaculous updates to infrastructure providers, data centers, and hosting companies worldwide.
Background
Softaculous and Virtualizor are widely used by web hosting providers and data centers for automating software installation and virtual environment management, making any compromise of their update infrastructure potentially impactful across thousands of networks globally.
- Source
- Ars Technica
- Published
- Sep 2, 2026 at 07:00 PM
- Score
- 8.0 / 10