negativeSYS.SOURCE: The Hacker News• 2026-09-02T18:42:45+05:30
BGP Hijack Exploits Virtualizor Update to Gain Persistent Root Access
A BGP hijack was used to deliver a malicious Virtualizor update, enabling persistent root access on compromised servers. Operators are advised to audit systems, rotate API keys, and use the official scanner to detect and remediate the exploit.
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise.
The incident window ran from approximately August 28 at 20:57
*** END OF TRANSMISSION ***