[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhx_6BL8VATyxsXFCB1xs5K72lxS8RMZO1KBv18fKBdE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"bf67b7d2-d03b-410e-b321-f73eae8dd0ca","bgp-hijack-delivers-malicious-virtualizor-update-via-compromised-update-infrastructure","0b5fab7f-6fde-4dd5-ac02-e53d420d81b4","BGP Hijack Delivers Malicious Virtualizor Update via Compromised Update Infrastructure","Threat actors exploited BGP routing vulnerabilities to intercept and redirect traffic destined for Softaculous's update servers, allowing them to serve a trojanized version of Virtualizor to unsuspecting administrators who trusted the update process. The attack highlights a critical weakness in software supply chains: update mechanisms that lack cryptographic package signing can be weaponized once an attacker gains control of routing infrastructure. BGP hijacking is particularly dangerous because it operates at the internet routing layer, making it invisible to most endpoint and perimeter defenses. This incident underscores that trusting network-layer integrity alone — without cryptographic verification of software authenticity — leaves organizations exposed to man-in-the-middle attacks at scale.","**Immediate actions:**\n- Verify the integrity of any Virtualizor installations active between August 28–30 using the security tool released in the latest Softaculous update.\n- Audit all recently applied software updates across your environment for signs of tampering or unexpected behavior.\n- Enable BGP route origin validation (ROV) and RPKI on your network infrastructure to reject illegitimate route announcements.\n\n**Long-term improvements:**\n- Require cryptographic package signing and signature verification for all software update pipelines before applying any update.\n- Implement software supply chain controls such as verifying update server TLS certificates and pinning expected IP ranges for critical vendors.\n- Establish vendor communication channels (e.g., signed advisories, out-of-band notifications) to validate update authenticity during anomalous conditions.\n\n**Detection measures:**\n- Deploy BGP monitoring tools (e.g., BGPmon, Kentik) to alert on unexpected route changes involving your AS or trusted vendor prefixes.\n- Log and alert on unexpected changes to update server destinations or TLS certificate mismatches during software update processes.\n- Monitor host-based integrity tools for unauthorized file modifications following any software update activity.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management","NIST SP 800-53 SI-7: Software, Firmware, and Information Integrity","NIST SP 800-53 SC-23: Session Authenticity","NIST CSF ID.SC-4: Suppliers are routinely assessed","NIST SP 800-189: Resilient Interdomain Traffic Exchange (BGP Security)","RFC 8210 \u002F RPKI: Resource Public Key Infrastructure for BGP Route Origin Validation","ITIL Change Management: Controlled and verified software deployment processes","SLSA Supply Chain Levels for Software Artifacts (Level 2+: Signed provenance)","published","2026-09-01T16:20:26.765405+00:00","2026-09-01T16:20:26.621+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack\u002F","hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack-024e41","Hackers push malicious Virtualizor update in BGP hijacking attack",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":38,"name":39,"slug":40,"description":41,"color":42},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]