Security3 distinct publishers2 min readPublished
The hijacker forged Hetzner as the origin so origin validation passed, held the prefix from Friday night into Sunday morning, and Softaculous has no logs of any of it because none of the diverted traffic reached its servers.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Certificate issuance is the load-bearing step in this chain. Softaculous says the attacker obtained a TLS certificate in its name and served the malicious updates from a clone site [7]. Neither report names the certificate authority or the validation method it accepted, so that part is not on the record. What is on the record is that from 20:57 UTC on 28 August the traffic addressed to that prefix arrived at the attacker's infrastructure [3][8], and any validation check aimed at a host inside it would have been answered from there [6].
Doug Madory's observation explains why route filtering was not the backstop. The announcement carried AS24940 on the path as the apparent origin, so origin validation compared it against Hetzner's authorization and matched [5][6][3]. A route that is RPKI-valid and more specific than Hetzner's /16 wins selection on every network that accepts it [4].
The vendor's own timestamps bracket the window from 20:57 UTC on 28 August to 06:10 UTC on 30 August [12], which is 33 hours and 13 minutes [1]; the Risky Business newsletter rounds it to almost 33 hours [2]. The number that matters is not the total but how many installs had an update check land inside it, and nobody can produce that number, because none of the redirected requests reached Softaculous to be logged [15].
Softaculous says it will implement cryptographic signing for all software packages going forward [22], which places last week's packages outside that protection [2]. Without a signature, a client that checked a hostname and a certificate has confirmed only that it reached whoever held the route.
The vendor also puts the damage at a small number of installations, a handful of servers rather than the general user base [14]. That figure cannot come from its own telemetry [4], so the hunting falls to operators: look for the systemd unit /etc/systemd/system/java-jre-update.service [16], then rotate and restrict API credentials and audit for unauthorized SSH keys, accounts, scheduled tasks and outbound connections [17].
Virtualizor is where hosting providers create, sell and manage customer VPS [10], so those credentials and keys reach tenant machines, not just the panel [5]. The attacker also received client and billing portal traffic [13], and Virtualizor tells anyone who paid during the window to assume card data went with it, while noting it is unclear whether the attacker was collecting it at all [9][18]. Any update channel whose only integrity control is the transport inherits the security of the routing table underneath it.
Ranked by verification strength, evidence, and original report placement.
An unidentified threat actor pulled off a BGP hijack that commandeered part of the IP address space and internet routing for Softaculous in order to deliver malicious updates for the Virtualizor web hosting management platform.
The BGP hijack took place for almost 33 hours, from Friday to Sunday last week, according to the Risky Business newsletter.
The Virtualizor team says the hacker performed the BGP hijack, obtained a TLS certificate in its name, and hosted a clone website that delivered the malicious updates.
Virtualizor says it cannot tell how many users were affected because it did not see or log any of the hijacked traffic, which passed exclusively through the attacker's infrastructure.
Virtualizor warns that users who made payments on the site during the attack most likely had their financial data stolen as well, but it is unclear whether the hackers were even trying to collect such information.
Virtualizor is a legacy web control panel from Softaculous that hosting providers use to create, sell and manage virtual private servers.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
1 article · September 1, 2026
2 articles · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Route leak prevention moves into the protocol, and two Tier-1s are stripping the signal1 distinct publisher
build
The same gigabyte of VPS RAM sells for $0.47 and $58.00 on the same day1 distinct publisher
build
Cross-node pod traffic: routing or encapsulation, and why that choice is a debugging decision1 distinct publisher
build
A missing WHERE clause, 24 databases, and the case for guards over prompts1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Routing well-corroborated, impact vendor-only
Two halves of this story stand on very different ground. The routing mechanics are checkable and were checked: Doug Madory's public path analysis, carried by Risky Business, independently matches the prefix and the forged origin in the victim's own advisory. Everything about consequence — how many installs, whose card data, what the implant did beyond a systemd unit — traces to a single Softaculous notice written by a company that says it logged none of it.
A handful of servers, one patch, no census
Measurable real-world footprint here is thin by the vendor's own telling: an unspecified handful of installations that happened to poll for updates inside a 33-hour window, one patched build with a new Security Analyzer, and a certificate sent for revocation. No hosting provider has come forward, no third party has counted affected servers, and there is no evidence anyone has confirmed the implant outside Softaculous's advisory.
If anything, undersold
Both outlets stay close to the advisory, and the advisory's own framing pulls downward: 'a handful of servers rather than the general Virtualizor user base' is reassurance offered by a party with no logs. The structurally alarming facts get less air than the reassurance does — an RPKI-valid hijack, unsigned update packages, a valid certificate in the vendor's name, and credentials that reach customer VPS. Nobody is inflating this; the caution runs the other way.
Victim writes the scope, sponsors sit alongside
The one party with an interest in a small number is the only party supplying one, and it does so while conceding it cannot count. On the publishing side, both substantive items carry commercial furniture in plain sight: BleepingComputer closes with a promoted security-vendor report, and the Risky Business newsletter names its sponsor at the top. Neither shapes the routing facts, but the framing of severity travels entirely on the victim's terms.
Mechanics solid, blast radius open
We would bet on the how: two publishers, a quoted advisory and an external routing analyst agree on the prefix, the window and the forged origin. We would not bet on the how much. The victim count is unknowable from the inside, the investigation is still open, and no downstream hosting provider has yet described what the implant did on a real machine.