Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A 33-Hour BGP Hijacking Incident Sparks a Security Scramble for Softaculous and Virtualizor Customers



A 33-hour BGP hijacking incident has left Softaculous customers scrambling to reset their credentials and inspect their servers for potential malware. The incident, which involved a sophisticated BGP hijacking attack, has highlighted the importance of robust security measures and ongoing education. To protect themselves, Softaculous customers are advised to follow the steps outlined above and take immediate action to secure their installations.

  • Softaculous customers were affected by a 33-hour BGP hijacking attack that diverted traffic to an attacker-controlled server, delivering malware to a handful of installations.
  • A sophisticated attack began on August 28, 20:57 UTC, and lasted until August 29, 20:00 UTC, leaving customers to deal with the aftermath.
  • A significant portion of Softaculous customers (72% chance) may have been at risk of malware infection during the incident.
  • A malicious Virtualizor update package was delivered to installations whose update checks passed through the attacker's server, bypassing Softaculous's security checks.
  • Softaculous is advising customers to reset credentials and inspect servers for signs of malware, as well as take steps to secure their Virtualizor installations.



  • Softaculous, a popular software vendor for web hosting, has found itself at the center of a high-profile security incident that has left customers scrambling to reset their credentials and inspect their servers for potential malware. The incident, which lasted for 33 hours, involved a sophisticated BGP hijacking attack that diverted Softaculous traffic to an attacker-controlled server, delivering malware to a handful of installations.

    The BGP hijacking attack began on August 28, around 20:57 UTC, when an unrelated network started announcing a block of Hetzner IP addresses used by Softaculous. This diversion of traffic was made possible by the attacker's ability to secure a valid TLS certificate from Let's Encrypt, which was automatically validated through the hijack. As a result, affected connections to Softaculous's systems reached the attacker's server without triggering any warnings to users.

    Softaculous reported the issues to Hetzner at around 08:50 UTC on August 29, and the hosting provider quickly responded by announcing the same, more specific address range, effectively cutting the observed diversion to almost zero for roughly 11 hours. However, the unauthorized announcement returned at around 20:00 UTC, and the hijack lasted for another 10 hours, leaving Softaculous customers to deal with the aftermath.

    While the hijack was active, Softaculous estimates that a given server had a roughly 72 percent chance of being on a network that routed the affected address range through the attacker. This means that a significant portion of Softaculous customers may have been at risk of malware infection during the incident. To mitigate this risk, Softaculous is advising customers to reset their credentials and inspect their servers for any signs of malware.

    In addition to the BGP hijacking, Softaculous has also confirmed that a malicious Virtualizor update package was delivered to a handful of installations whose update checks passed through the attacker's server. The malicious package was not cryptographically verified by Softaculous, allowing it to bypass the vendor's security checks. As a result, Softaculous is advising Virtualizor operators to treat their servers as potentially compromised, even if they did not download the malicious update.

    To help its customers stay safe, Softaculous is providing a list of steps that operators can take to secure their Virtualizor installations. These steps include rotating and restricting API credentials, checking for unknown SSH keys and accounts, inspecting scheduled tasks and outbound connections, and regenerating client-area API keys. Softaculous is also invalidating client-area sessions created during the incident window.

    The 33-hour BGP hijacking incident has left many in the industry stunned by the sophistication of the attack. The incident highlights the importance of robust security measures, including regular software updates and secure configuration of BGP routing.

    In response to the incident, Softaculous is urging its customers to be vigilant and take immediate action to secure their installations. By following the steps outlined above, customers can significantly reduce the risk of malware infection and protect their data.

    The incident also serves as a reminder of the importance of ongoing security awareness and education. As the threat landscape continues to evolve, it is essential that individuals and organizations stay informed and take proactive steps to protect themselves.

    In conclusion, the 33-hour BGP hijacking incident has been a wake-up call for the Softaculous community, highlighting the need for robust security measures and ongoing education. By working together, we can create a safer and more secure digital landscape for all.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-33-Hour-BGP-Hijacking-Incident-Sparks-a-Security-Scramble-for-Softaculous-and-Virtualizor-Customers-ehn.shtml

  • https://www.theregister.com/security/2026/09/01/33-hour-bgp-hijack-of-softaculous-traffic-prompts-security-scramble/5293608


  • Published: Tue Sep 1 08:46:04 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us