Security News

Hackers Hijack Internet Routing to Push Fake Virtualizor Update

Security Week · 2 Sept 2026
Key Takeaway Verify software update sources through secondary channels (such as vendor announcements or checksums) rather than relying solely on a valid-looking certificate or connection.

A threat actor exploited a technique known as BGP hijacking to intercept legitimate network traffic and redirect it to servers delivering a malicious update for Virtualizor, a server virtualization control panel from Softaculous. BGP, or Border Gateway Protocol, is the system that routes internet traffic between networks; when attackers manipulate it, they can silently reroute traffic meant for a trusted destination to one under their control.

What made this attack particularly convincing is that the attackers used a technically valid TLS certificate tied to Softaculous' own domains. This meant users attempting to reach legitimate update servers may have seen no obvious warning signs, such as certificate errors, that would typically indicate something was wrong. As a result, systems could have been tricked into downloading and installing a compromised update believing it came from a trusted source.

This incident highlights a growing concern in the cybersecurity world: attacks that target the fundamental infrastructure of the internet rather than individual devices or applications. Because BGP hijacking happens at the network routing level, it can be difficult for end users or even IT teams to detect, and it can affect anyone relying on the targeted software's update mechanism, regardless of their own security posture.

BGP hijacking supply chain attack Virtualizor TLS certificate abuse network security
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.