Hackers push malicious Virtualizor update in BGP hijacking attack
Overview
Hackers have managed to hijack Border Gateway Protocol (BGP) routing to deliver malicious updates to the Virtualizor VPS management software. This attack redirected legitimate update requests to compromised servers, allowing the attackers to install harmful software on systems that rely on Virtualizor. As a result, users of this VPS management tool are at risk of having their servers compromised. This incident underscores the vulnerabilities in the update mechanisms of software and the potential for BGP hijacking to disrupt services. Companies using Virtualizor should take immediate steps to secure their systems and monitor for any unauthorized changes.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Virtualizor VPS management software
- Action Required: Users should check for any unauthorized updates and revert to known good versions of the software.
- Timeline: Newly disclosed
Original Article Summary
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
Impact
Virtualizor VPS management software
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should check for any unauthorized updates and revert to known good versions of the software. Additionally, implementing security measures to protect BGP routing and regularly monitoring update sources is recommended.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability, Update, Malware.