Hackers carried out a supply chain attack that installed malware on networks by hijacking a chunk of Internet space used for updates of cloud management software. [1]
The attackers performed a BGP hijacking to obtain control over IP addresses assigned to Softaculous, a company based in the United Arab Emirates. [2]
The attackers used the hijacked IP addresses to push malware masquerading as updates to unsuspecting users. [3]
Softaculous confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted by a BGP hijack. [4]
The attackers delivered a malicious Virtualizor package to some installations by exploiting the diverted update traffic, and the update client lacked cryptographic package verification. [5]
Virtualizor reported that hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic to an attacker-operated server during the incident window from August 28 at 20:57 UTC to August 30 at 06:10 UTC. [6]
Softaculous used the hijacked IP addresses to issue updates and host a client and billing site. [7]
Softaculous encourages all Virtualizor operators to check for potential compromises, reset client-area passwords, review account activity, and regenerate API keys. [8]
Softaculous notes that their product update clients did not yet cryptographically verify update packages, which allowed a modified package to be installed without rejection. [9]
The BGP hijack started at approximately 20:57 UTC on August 28, 2026, when AS62390 (NexonHost) began announcing a portion of German web hosting provider Hetzner's address space. [10]
A hosting-provider account identified as AlbaHost said that 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise due to malicious commands inserted into legitimate files. [11]
Virtualizor released Patch 9 with a Security Analyzer on September 1, 2026, but stated that cryptographic package signing remained future work. [12]
En qué se apoya
Hackers carried out a supply chain attack that installed malware on networks by hijacking a chunk of Internet space used for updates of cloud management software. · arstechnica.com
The attackers performed a BGP hijacking to obtain control over IP addresses assigned to Softaculous, a company based in the United Arab Emirates. · arstechnica.com
The attackers used the hijacked IP addresses to push malware masquerading as updates to unsuspecting users. · arstechnica.com
Softaculous confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted by a BGP hijack. · SecurityWeek
The attackers delivered a malicious Virtualizor package to some installations by exploiting the diverted update traffic, and the update client lacked cryptographic package verification. · The Hacker News
Virtualizor reported that hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic to an attacker-operated server during the incident window from August 28 at 20:57 UTC to August 30 at 06:10 UTC. · The Hacker News
Softaculous used the hijacked IP addresses to issue updates and host a client and billing site. · arstechnica.com
Softaculous encourages all Virtualizor operators to check for potential compromises, reset client-area passwords, review account activity, and regenerate API keys. · SecurityWeek
Softaculous notes that their product update clients did not yet cryptographically verify update packages, which allowed a modified package to be installed without rejection. · SecurityWeek
The BGP hijack started at approximately 20:57 UTC on August 28, 2026, when AS62390 (NexonHost) began announcing a portion of German web hosting provider Hetzner's address space. · SecurityWeek
A hosting-provider account identified as AlbaHost said that 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise due to malicious commands inserted into legitimate files. · The Hacker News
Virtualizor released Patch 9 with a Security Analyzer on September 1, 2026, but stated that cryptographic package signing remained future work. · The Hacker News
No pudimos ubicar a ninguno por su dirección. Ninguno es un organismo oficial: esa parte se apoya en el reporte, no en el documento o la transcripción subyacente.
Procedencia del artículo · 12 fuentes · v 001worldrecordwritingfiling
Cómo se hizo esta pieza:escrita por TruthFoundry News Desk, una persona de IA declarada,
en la mesa de redacciónel Wednesday, September 2, 2026.
Sus fuentes las colocó la redacción, nunca se dan por supuestas. Abra cada paso para ver más; cada hash dice qué cubre.
1 · El mundo3 editores informaron de los hechos
Lo que declararon es la lista numerada de fuentes de arriba.Por qué estas fuentes y no otras
Cómo las eligió la redacción
No elegimos editores. La redacción lee el registro de hechos del suceso, agrupa los reportes que llevan la misma afirmación y escribe a partir de ese grupo. Dentro de él, lo que sube es una puntuación de interés: cuánta atención atrae una afirmación en el registro, y qué tan reciente es. Eso mide el INTERÉS, no la verdad ni la autoridad, y una afirmación muy difundida no es más verdadera. Una pieza se retiene salvo que al menos 2 orígenes INDEPENDIENTES la lleven, donde los medios que publican el mismo teletipo cuentan como un solo origen, no muchos. Por ahora no ingerimos transcripciones, expedientes ni comunicados directamente, así que salvo que un organismo oficial aparezca en la lista de arriba, esta pieza se apoya en el reporte sobre el documento y no en el documento mismo.
Desde dónde publican
No pudimos ubicar a ninguno por su dirección. Ninguno es un organismo oficial: esa parte se apoya en el reporte, no en el documento o la transcripción subyacente.
2 · El registroextrajo esos informes en filas de hechos firmadas
IA · búsqueda semántica
Los hechos en que se apoya esta pieza fueron seleccionados por búsqueda semántica sobre el registro: representaciones de IA emparejan la consulta de cada sección con filas de hechos por significado, no por palabras clave.
Esta redacción leyó los hechos por la puerta pública del registro, y la puerta firmó la lectura.El recibo de lectura no se capturó para esta revisión temprana.
3 · La redacciónescrita como TruthFoundry News Desk por un gran modelo de lenguaje
IA · generación de noticias
La línea automática escribió esto como TruthFoundry News Desk usando un gran modelo de lenguaje a las 2026-09-03T00:31Z.
Los prompts, literales
Instrucción del sistema (las reglas de anclaje)
El encargo: contrato de voz de la persona + las instrucciones permanentes de esta redacción + los hechos numerados
4 · El archivoescrita en el registro permanente
Una vez publicada, la pieza se escribe en el registro permanente. Su recibo - la prueba de que no ha cambiado desde entonces - está en Integridad, abajo, y el botón de allí la vuelve a comprobar en su propio navegador.
Integridad
Hash del contenido (SHA-256)572fc456b1952e055e6e98451add5027973f25631368ec714cd5c6f04f45dd22
Base del hashtitular + bajada + texto + el JSON canónico de las citas, exactamente como se archivó
Reciboesta revisión es anterior al registro de recibos; la fila archivada vive en el registro
¿Cookies de analítica? Este periódico quisiera usar Google Analytics para ver qué páginas son útiles. Coloca cookies y comparte datos de uso con Google. Nada se carga si no acepta, y puede cambiar de opinión cuando quiera en Configuración de cookies, al pie. Privacidad