Softaculous hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Softaculous confirmed that Virtualizor update traffic was diverted in a BGP hijacking attack, allowing a malicious update package to reach a small number of installations. The compromise affected the update path and client/billing portal during August 28-30, creating a supply-chain risk for hosting providers. The vendor says the affected set was a handful of servers, and administrators were told to check for unauthorized service installation and credential misuse. Routing has since been restored and a new Virtualizor 3.2.9.9 release was issued with added defenses.
Timeline
-
01.09.2026 17:45 2 articles · 2h ago
Softaculous confirms malicious Virtualizor update delivery after BGP hijacking
Initial DisclosureSoftaculous confirmed that attackers rerouted Hetzner-hosted IP space in a BGP hijacking that diverted Virtualizor update traffic and the client/billing portal, allowing a malicious Virtualizor update package to reach a small number of installations. The company said routing has been restored, a fraudulent certificate was reported for revocation, and Virtualizor 3.2.9.9 was released with a Security Analyzer tool in the admin panel.
Show sources
- Hackers push malicious Virtualizor update in BGP hijacking attack — www.bleepingcomputer.com — 01.09.2026 17:45
- Hackers push malicious Virtualizor update in BGP hijacking attack — www.bleepingcomputer.com — 01.09.2026 17:45