Skip to main content
CyberSingle-sourceHighDevelopingFeatured
7.6

BGP hijack serves malicious Virtualizor update via valid TLS cert

A threat actor hijacked BGP routes to Softaculous domains and served a malicious Virtualizor update using a technically valid TLS certificate, indicating a sophisticated supply-chain attack. The incident underscores the risk of BGP vulnerabilities and the limits of certificate validation in software update integrity. The scope of affected users remains unclear.

SecurityWeekabout 24 hours agoengCredibility 58%View source

Score Breakdown

Mosaic Score7.6
Confidence0.7
Significance0.8
Source credibility0.6
Source

Related signals

8 found