# BGP hijack used to push malware through Virtualizor update path

_Wednesday, September 2, 2026 at 7:00 AM EDT · Security · Latest · Tier 1 — Major_

![BGP hijack used to push malware through Virtualizor update path — Primary](https://cdn.arstechnica.net/wp-content/uploads/2022/09/GettyImages-11477585601-1000x648.jpg)

Unknown attackers used a BGP hijack to control IP addresses used by Softaculous and push malware posing as updates to Virtualizor users, according to the report. The attack exploited routing-security weaknesses at hosting provider Hetzner Online and failures in obtaining valid TLS certificates. Softaculous said its update clients did not cryptographically verify packages and advised every Virtualizor server to be treated as in scope for checks. Hetzner's routing response left two hijack periods spanning 33 hours.

## Sources

- [Ars Technica](https://arstechnica.com/security/2026/09/well-executed-bgp-attack-uses-hijacked-ips-to-infect-real-networks/)

---
Canonical: https://techandbusiness.org/newswire/vlNSnjKt4HGxeIunWesEyI
Retrieved: 2026-09-03T20:29:50.141Z
Publisher: Tech & Business (techandbusiness.org)
