An attacker executed a BGP hijack of 162.55.80.0/24 (a more specific prefix within Hetzner's 162.55.0.0/16 space) to redirect traffic to Softaculous's update endpoint, delivering a malicious Virtualizor update package to a small number of installations. The hijacked route was RPKI-valid due to a forged AS path appending AS24940, making it resistant to route filtering defenses. The incident highlights how gaps in upstream security at intermediate ASes (likely NexonHost, AS62390) can enable sophisticated routing attacks.
Background
BGP hijacking remains one of the most severe threats to internet infrastructure, allowing attackers to intercept or redirect traffic by announcing illegitimate routing prefixes. Softaculous is a widely deployed auto-installer for hosting panels and Virtualizor is a virtual machine management platform, making a compromised update channel a supply-chain risk for numerous downstream users.
- Source
- Lobsters
- Published
- Sep 23, 2026 at 07:55 PM
- Score
- 7.0 / 10