Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: bgp-hijack (1 article)Clear

BGP hijack poisons a server-panel update to plant persistent root access

Attackers used a BGP hijack, a manipulation of internet routing, to divert update traffic for Virtualizor, a widely used server and hypervisor management panel, to a server they controlled. During the diversion, which began August 28, they obtained a valid TLS certificate so the connection looked legitimate, then delivered a malicious update that installed persistent root access on affected hosts. One hosting provider found root-level compromise on five of thirty-four hypervisors it checked. Because the software's updates were not cryptographically signed, transport encryption alone did not stop the tampering once routing was hijacked. The vendor released a scanner and patch, but package signing remains unfinished, leaving update integrity dependent on routing security.

Check
Run the vendor's scanner on Virtualizor hosts, check for the published indicators like the malicious service and payload file, rotate and IP-restrict API keys, and audit for unknown SSH keys and users.
Affected
Hosting providers and organizations running Virtualizor that pulled updates during the hijack window; a malicious signed-looking update could install persistent root access on hypervisors, exposing every virtual machine they host.
Fix
Scan and remediate affected hosts preserving evidence, rotate credentials and API keys, verify update integrity independently of transport encryption, monitor routing for hijacks of critical vendors, and prefer vendors that sign updates.