← Back to feed
Vendors & MarketEmerging1 sourceSep 1, 2026 · 03:59via Cyber Security News

BGP Hijack Diverts Softaculous Traffic to Deliver Malicious Virtualizor Update

Brief

Attackers hijacked BGP routing for Softaculous last week and delivered a malicious Virtualizor update to a handful of hypervisor servers, according to a vendor incident report .

Hosting providers use Virtualizor to manage VPS nodes on KVM, Xen, LXC, OpenVZ, and Proxmox, and a single master can control hundreds of virtualization servers, placing a poisoned update high in the hosting stack. The product publicly lists hundreds of NOC partners, so a compromise here hits hosting infrastructure rather than a single website panel.

The hijack ran from about 20:57 UTC on 28 August 2026 until 06:10 UTC on 30 August. AS62390 (NexonHost) announced 162.

  • 80. 0/24, a Hetzner block used by Softaculous update and billing systems, through AS6204 (Zet. net).

BGP Hijack Diverts Softaculous Traffic

Hetzner normally advertised only 162.

  • 0.
Read more on Cyber Security News