Malicious Virtualizor Update Served via BGP Hijacking
Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates. The post Malicious Virtualizor Update Served via BGP Hijacking appeared first on SecurityWeek.
Softaculous’ Virtualizor users were served malicious software updates for two days after a threat actor diverted internet traffic to attacker-controlled servers.
A provider of applications for web hosting, Softaculous offers an auto-installer tool for over 400 popular web applications. Virtualizor is its web-based Virtual Server (VPS) management control panel.
Between August 28 and August 30, a block of Softaculous IP addresses was hit by a BGP hijack attack: a threat actor used a technically valid TLS certificate for the company’s domains to divert traffic to attacker infrastructure.
Source: https://www.securityweek.com/malicious-virtualizor-update-served-via-bgp-hijacking/
Related breach coverage
- PaperCut Flaws Exploited in AI-Powered Attacks2026-09-11
A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide. The post PaperCut Flaws Exploited in AI-Powered Attacks appeared first on SecurityWeek.
- AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million2026-09-03
The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks. The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek.
- Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia2026-08-20
Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks. The post Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia appeared first on SecurityWeek.
- Fortune 500 Companies Hit in Azure Data Theft Campaign2026-08-17
A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations. The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek.