logo

33-hour BGP hijack of Softaculous traffic prompts security scramble

ID: 38ab43c8-dac2-5197-8241-b782b295f757

STIX ID: report--38ab43c8-dac2-5197-8241-b782b295f757

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2026-09-01

Date Updated: 2026-09-05

...
...

Softaculous experienced a 33-hour BGP hijack that rerouted some traffic for its Virtualizor software and client services to an attacker-controlled server. The attacker obtained a Let's Encrypt TLS certificate for affected domains and served a malicious Virtualizor update package to a small number of installations because update packages were not cryptographically verified; Softaculous recommends credential resets, API key rotation, server inspections, and notes the IOCs include the systemd unit /etc/systemd/system/java-jre-update.service.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.