<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Hackers push malicious Virtualizor update in BGP hijacking attack]]></title><description><![CDATA[<p dir="auto">Attackers compromised the update chain for <strong>Virtualizor</strong>, a web-based VPS control panel, by hijacking BGP routes tied to the software’s update infrastructure. This allowed them to intercept legitimate update requests and redirect them to attacker-controlled servers, which served malicious payloads in place of genuine patches.</p>
<p dir="auto">The incident underscores a broader risk: even signed updates can be weaponized if the distribution path is subverted. While the exact scope of affected users remains unclear, administrators running <strong>Virtualizor</strong> should treat any recent update as potentially compromised until verified against official checksums or re-downloaded from a trusted, out-of-band source.</p>
<p dir="auto">Key points for administrators:</p>
<ul>
<li>The attack relied on <strong>BGP hijacking</strong> to reroute traffic destined for the vendor’s update servers.</li>
<li>No specific CVE or patch identifier was disclosed in the public report, so verification should focus on file integrity and server-side logs.</li>
<li>If you have applied a <strong>Virtualizor</strong> update recently, review your system for unexpected processes, new cron jobs, or modified startup scripts.</li>
<li>Check your BGP observability tools or ISP for any route anomalies during the suspected window.</li>
<li>Consider manual re-installation from the official website after confirming DNS and network paths are clean.</li>
</ul>
<p dir="auto">This incident highlights how infrastructure-level attacks can bypass endpoint defenses. Even robust code-signing does not help if the transport layer is silently rerouted.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack" target="_blank" rel="noopener noreferrer nofollow ugc">Unknown</a></p>
<p dir="auto">Has your organization implemented any specific monitoring for BGP anomalies or update-channel integrity after incidents like this?</p>
]]></description><link>https://xploitlk.com/topic/180/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:37:29 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/180.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 01 Sep 2026 16:30:24 GMT</pubDate><ttl>60</ttl></channel></rss>