Incident
Published 2026-08-31
Verified 2026-09-19

Softaculous/Virtualizor: BGP hijack delivered a malicious hypervisor update

Softaculous' Virtualizor incident post (31 August 2026) says IP block 162.55.80.0/24 (Hetzner space used by Softaculous services) was BGP-hijacked from about 20:57 UTC on 28 August to about 06:10 UTC on 30 August. An unauthorised announcement by AS62390 (NexonHost), transited via AS6204 (Zet.net), was more specific than Hetzner's 162.55.0.0/16 and diverted traffic, including the software-update endpoint and client-area/billing site. The attacker obtained a technically valid Let's Encrypt certificate for Virtualizor, Softaculous and related names, so diverted connections showed no certificate warning. The vendor confirmed a malicious Virtualizor update package reached a small number of installations that checked for updates during diversion; it cannot list every affected host. Known indicator: systemd unit /etc/systemd/system/java-jre-update.service. Routing has been restored. Operators should hunt that unit (and not only delete it), rotate Virtualizor API keys, and audit SSH keys, accounts and cron. The vendor shipped Virtualizor 3.2.9.9 with a mitigation tool and says package signing is coming. Other Softaculous products had no identified malicious package at the time of the post. Clients who logged into the billing site during the window should reset that password.

Product
Virtualizor (Softaculous update infrastructure)
Versions
Installations that checked for updates between 28 Aug ~20:57 UTC and 30 Aug ~06:10 UTC
Exploited in Australia?
unknown
Patch to
Hunt java-jre-update.service; rotate API keys; restrict SSH/API; Virtualizor 3.2.9.9 mitigation build

Primary: Virtualizor incident post (31 Aug 2026) · Vendor: Softaculous / Virtualizor (vendor) · Ars Technica (2 Sep 2026)

tech cloud