CyberHighSingle-sourceAccelerating
7.6
BGP hijack used to push malicious Virtualizor update to VPS hosts
BleepingComputer·2 days ago
A threat actor hijacked BGP routes to Softaculous domains and served a malicious Virtualizor update using a technically valid TLS certificate, indicating a sophisticated supply-chain attack. The incident underscores the risk of BGP vulnerabilities and the limits of certificate validation in software update integrity. The scope of affected users remains unclear.
Entities