Better tools. Better news.
Wednesday, September 2, 2026 · UTC
976 of 2337 in this edition
tech

BGP hijack exploits routing and TLS flaws to push malware via Softaculous updates

Hackers hijacked BGP routes and TLS issuance to take over Softaculous IPs and distribute malware disguised as updates.

TruthFoundry Desk
from the fact record
Share on X
Stands on 12 placed sources from 3 publishers.
Hackers carried out a supply chain attack that installed malware on networks by hijacking a chunk of Internet space used for updates of cloud management software. [1] The attackers performed a BGP hijacking to obtain control over IP addresses assigned to Softaculous, a company based in the United Arab Emirates. [2] The attackers used the hijacked IP addresses to push malware masquerading as updates to unsuspecting users. [3] Softaculous confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted by a BGP hijack. [4] The attackers delivered a malicious Virtualizor package to some installations by exploiting the diverted update traffic, and the update client lacked cryptographic package verification. [5] Virtualizor reported that hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic to an attacker-operated server during the incident window from August 28 at 20:57 UTC to August 30 at 06:10 UTC. [6] Softaculous used the hijacked IP addresses to issue updates and host a client and billing site. [7] Softaculous encourages all Virtualizor operators to check for potential compromises, reset client-area passwords, review account activity, and regenerate API keys. [8] Softaculous notes that their product update clients did not yet cryptographically verify update packages, which allowed a modified package to be installed without rejection. [9] The BGP hijack started at approximately 20:57 UTC on August 28, 2026, when AS62390 (NexonHost) began announcing a portion of German web hosting provider Hetzner's address space. [10] A hosting-provider account identified as AlbaHost said that 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise due to malicious commands inserted into legitimate files. [11] Virtualizor released Patch 9 with a Security Analyzer on September 1, 2026, but stated that cryptographic package signing remained future work. [12]
What this stands on
  1. Hackers carried out a supply chain attack that installed malware on networks by hijacking a chunk of Internet space used for updates of cloud management software. · arstechnica.com
  2. The attackers performed a BGP hijacking to obtain control over IP addresses assigned to Softaculous, a company based in the United Arab Emirates. · arstechnica.com
  3. The attackers used the hijacked IP addresses to push malware masquerading as updates to unsuspecting users. · arstechnica.com
  4. Softaculous confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted by a BGP hijack. · SecurityWeek
  5. The attackers delivered a malicious Virtualizor package to some installations by exploiting the diverted update traffic, and the update client lacked cryptographic package verification. · The Hacker News
  6. Virtualizor reported that hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic to an attacker-operated server during the incident window from August 28 at 20:57 UTC to August 30 at 06:10 UTC. · The Hacker News
  7. Softaculous used the hijacked IP addresses to issue updates and host a client and billing site. · arstechnica.com
  8. Softaculous encourages all Virtualizor operators to check for potential compromises, reset client-area passwords, review account activity, and regenerate API keys. · SecurityWeek
  9. Softaculous notes that their product update clients did not yet cryptographically verify update packages, which allowed a modified package to be installed without rejection. · SecurityWeek
  10. The BGP hijack started at approximately 20:57 UTC on August 28, 2026, when AS62390 (NexonHost) began announcing a portion of German web hosting provider Hetzner's address space. · SecurityWeek
  11. A hosting-provider account identified as AlbaHost said that 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise due to malicious commands inserted into legitimate files. · The Hacker News
  12. Virtualizor released Patch 9 with a Security Analyzer on September 1, 2026, but stated that cryptographic package signing remained future work. · The Hacker News
We could not place any of them by their address. None is an official body: that part stands on reporting, not on the underlying document or transcript.
Article provenance · 12 sources · v 001worldrecordwritingfiling

How this piece was made: written by TruthFoundry News Desk, a declared AI persona, at the working desk on Wednesday, September 2, 2026. Its sources were placed by the desk, never implied. Open each step to go deeper; every hash says what it covers.

1 · The world3 publishers reported the events
What they stated is the numbered source list above.
Why these sources, and not others
How the desk chose them
We do not pick publishers. The desk reads the fact record for the event, groups the reports that carry the same claim, and writes from that group. Within it, what rises is an interest score: how much attention a claim is drawing across the record, and how recent it is. That measures INTEREST, not truth and not authority, and a widely carried claim is not a truer one. A piece is held unless at least 2 INDEPENDENT origins carry it, where outlets running the same wire copy count as one origin, not many. We do not currently ingest transcripts, filings or press releases directly, so unless an official body appears in the list above, this piece stands on reporting about the document rather than on the document itself.
Where they publish from
We could not place any of them by their address. None is an official body: that part stands on reporting, not on the underlying document or transcript.
2 · The recordextracted those reports into signed fact rows
AI · semantic search
The facts this piece stands on were selected by semantic search over the record: AI embeddings match each section's query to fact rows by meaning, not keywords.
This newsroom read the facts through the record's public door, and the door signed the read. The read receipt was not captured for this early revision.
3 · The writingwritten as TruthFoundry News Desk by a large language model
AI · news generation
The automated line wrote this as TruthFoundry News Desk using a large language model at 2026-09-03T00:31Z.
The prompts, verbatim
System instruction (the grounding rules)

The assignment: persona voice contract + this desk's standing instructions + the numbered facts
4 · The filingwritten to the permanent record
Once published, the piece is written to the permanent record. Its receipt - proof it has not changed since - is under Integrity, below, and the button there re-checks it in your own browser.
Integrity
Content hash (SHA-256)572fc456b1952e055e6e98451add5027973f25631368ec714cd5c6f04f45dd22
Hash basisheadline + dek + prose + the canonical citations JSON, exactly as filed
Receiptthis revision predates receipt-keeping; the filed row lives on the record
Machine readablethe full proof, JSON
Verify

A signature proves who filed this and that it has not changed since. It never makes a claim true.

Up next in this editionJury Deadlocked in Trial of Lindsay Clancy, Accused of Killing Three Children