Critical

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

The Hacker News
Actively Exploited

Overview

Hackers have executed a Border Gateway Protocol (BGP) hijack to redirect traffic meant for Softaculous, allowing them to deliver a malicious update for Virtualizor. This incident has compromised at least five out of thirty-four Virtualizor hypervisors at a hosting provider, granting the attackers root access to these systems. The attack window is reported to have occurred on August 28. This breach raises concerns for users relying on Virtualizor for virtualization management, as the malicious update could lead to unauthorized control over their servers. Organizations using this software should take immediate steps to assess their systems for vulnerabilities and potential intrusions.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Virtualizor hypervisors, Softaculous traffic
  • Action Required: Users should assess their Virtualizor installations for unauthorized changes and apply any available security updates.
  • Timeline: Ongoing since August 28, 2023

Original Article Summary

Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise. The incident window ran from approximately August 28 at 20:57

Impact

Virtualizor hypervisors, Softaculous traffic

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since August 28, 2023

Remediation

Users should assess their Virtualizor installations for unauthorized changes and apply any available security updates. Regular monitoring of system logs and network traffic is also recommended.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Update, Malware.

Related Coverage

Jail time for Maine child in 764 marks turning point in federal law enforcement

CyberScoop

A recent case involving a minor in Maine has resulted in jail time and is being viewed as a significant moment for federal law enforcement regarding violent extremist crime. This case, referred to as '764', marks a first-of-its-kind legal outcome and is expected to influence how similar cases are handled in the future. Researchers tracking the development believe it will create a ripple effect across the landscape of violent extremism, potentially leading to more stringent measures and responses from law enforcement agencies. The implications of this case extend beyond the individual involved, as it could set precedents for dealing with youth and extremism in the United States.

Sep 2, 2026

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

darkreading

Recent reports indicate that SonicWall's SMA 1000 series devices are vulnerable to multiple zero-day exploits, allowing unauthorized remote code execution (RCE). This follows a series of attacks earlier this summer that targeted two other zero-day vulnerabilities in SonicWall's edge devices. The implications of this vulnerability are significant, as it could allow attackers to gain control over affected systems without any authentication. Organizations using these devices need to take immediate action to safeguard their networks, as the vulnerabilities are being actively exploited. Users are advised to monitor for updates from SonicWall and apply patches as soon as they are released to mitigate potential risks.

Sep 2, 2026

OpenLeash Adds a Human Check to Risky AI Agent Actions

SecurityWeek

OpenLeash has introduced a new security feature that acts as a safeguard against risky actions taken by AI agents. This tool monitors the actions of AI systems and can block those that pose clear risks. In situations where the intent of the AI is ambiguous, OpenLeash will prompt a human for approval before proceeding. This approach is particularly important as AI becomes more integrated into various applications, potentially leading to unintended consequences. By adding this layer of human oversight, OpenLeash aims to reduce the likelihood of harmful actions while maintaining the efficiency of AI operations. The development underscores the growing need for responsible AI deployment and oversight in technology.

Sep 2, 2026

The FCC wants consumers to rate their telecom’s anti-robocall protections

CyberScoop

The Federal Communications Commission (FCC) is taking steps to enhance consumer protection against robocalls. They are asking consumers to evaluate their telecom providers’ efforts in blocking these unwanted calls. This initiative aims to empower users while also holding providers accountable for their anti-robocall measures. Additionally, the FCC has removed 14 phone service providers from U.S. networks for failing to comply with existing robocalling regulations. This move underscores the FCC's commitment to reducing the prevalence of robocalls, which can often lead to scams and fraud, affecting millions of Americans.

Sep 2, 2026

Dogged Russia-based botnet dismantled after 23-year run

CyberScoop

The Sality botnet, which has been operating for 23 years, has finally been dismantled by cybersecurity experts and authorities. This Russia-based botnet was notorious for its peer-to-peer infrastructure, which allowed it to evade detection and disruption efforts for an extended period. It has been linked to various cybercrimes, including the distribution of malware and the theft of sensitive information. The takedown of Sality is significant as it represents a major victory in the fight against long-standing cyber threats. Its removal is expected to reduce the incidence of malware infections and enhance overall internet security for users worldwide.

Sep 2, 2026

UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

SecurityWeek

The UK government is taking significant steps to enhance its cybersecurity by introducing amendments to the Cyber Security and Resilience Bill. These changes will empower ministers to restrict access to technology providers deemed high-risk for critical infrastructure. This move comes as supply chain attacks are becoming more frequent and sophisticated, posing serious risks to national security and public safety. By limiting the involvement of potentially dangerous tech suppliers, the UK aims to protect essential services and maintain the integrity of its digital infrastructure. This decision affects various sectors, including telecommunications, energy, and transportation, where secure and reliable technology is vital.

Sep 2, 2026