<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access]]></title><description><![CDATA[<p dir="auto">Virtualizor has disclosed that attackers abused a <em>Border Gateway Protocol (BGP) hijack</em> to intercept update traffic belonging to Softaculous, allowing them to distribute a malicious Virtualizor package to a subset of installations. The tampered update is reported to establish persistent root-level access on affected systems, marking a significant supply-chain incident for hosting providers relying on the platform.</p>
<p dir="auto">According to an account from a hosting provider, <em>5 out of 34</em> Virtualizor hypervisors that were checked showed signs of root-level compromise. The malicious activity is believed to have occurred within a specific window, beginning around <em>August 28 at 20:57</em> (exact end time not disclosed).</p>
<ul>
<li>The attack vector involved hijacking BGP routes to redirect Softaculous update traffic, rather than compromising the software repository directly.</li>
<li>The delivered payload targeted Virtualizor installations, with the goal of maintaining stealthy, persistent administrative access.</li>
<li>Hosting providers are advised to audit their Virtualizor hypervisors for unauthorized root access, especially if updates were applied during the incident window.</li>
</ul>
<p dir="auto">Since the exact scope of affected installations is not yet confirmed, immediate steps for administrators include:</p>
<ul>
<li>Reviewing system logs for any unauthorized SSH sessions or unexpected root-level commands during the specified timeframe.</li>
<li>Checking for newly created user accounts or modified SSH authorized_keys files.</li>
<li>Reinstalling or restoring Virtualizor from a verified, clean source if compromise is suspected.</li>
<li>Rotating all root and administrative credentials across affected and potentially affected systems.</li>
</ul>
<p dir="auto">This incident underscores the risk inherent in relying on internet routing infrastructure for software updates, as a single BGP hijack can silently corrupt the trust chain of widely used management tools.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/bgp-hijack-delivers-malicious.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has your team started auditing Virtualizor hypervisors for indicators of this attack, and what steps are you taking to verify the integrity of your current installations?</p>
]]></description><link>https://xploitlk.com/topic/234/bgp-hijack-delivers-malicious-virtualizor-update-that-establishes-persistent-root-access</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:28:17 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/234.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 06 Sep 2026 06:30:23 GMT</pubDate><ttl>60</ttl></channel></rss>