Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Cybersecurity News
  5. Hackers push malicious Virtualizor update in BGP hijacking attack

Hackers push malicious Virtualizor update in BGP hijacking attack

Scheduled Pinned Locked Moved Cybersecurity News
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Attackers compromised the update chain for Virtualizor, a web-based VPS control panel, by hijacking BGP routes tied to the software’s update infrastructure. This allowed them to intercept legitimate update requests and redirect them to attacker-controlled servers, which served malicious payloads in place of genuine patches.

    The incident underscores a broader risk: even signed updates can be weaponized if the distribution path is subverted. While the exact scope of affected users remains unclear, administrators running Virtualizor should treat any recent update as potentially compromised until verified against official checksums or re-downloaded from a trusted, out-of-band source.

    Key points for administrators:

    • The attack relied on BGP hijacking to reroute traffic destined for the vendor’s update servers.
    • No specific CVE or patch identifier was disclosed in the public report, so verification should focus on file integrity and server-side logs.
    • If you have applied a Virtualizor update recently, review your system for unexpected processes, new cron jobs, or modified startup scripts.
    • Check your BGP observability tools or ISP for any route anomalies during the suspected window.
    • Consider manual re-installation from the official website after confirming DNS and network paths are clean.

    This incident highlights how infrastructure-level attacks can bypass endpoint defenses. Even robust code-signing does not help if the transport layer is silently rerouted.

    Source: Unknown

    Has your organization implemented any specific monitoring for BGP anomalies or update-channel integrity after incidents like this?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World