:

HACKERS HIJACK BGP TO PUSH MALICIOUS VIRTUALIZOR UPDATE

SECURITY DESK1 MIN READ
WED, SEP 2, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Attackers exploited BGP routing vulnerabilities to redirect Virtualizor VPS management software update requests to malicious servers. The compromise affected users attempting to download legitimate updates for the widely-used hosting control panel.

In the attack, hackers hijacked Border Gateway Protocol (BGP) routing for Virtualizor's update infrastructure, allowing them to intercept and redirect update traffic. Users who downloaded updates during the compromise period received malicious versions instead of legitimate software patches. Virtualizor is a popular VPS management platform used by hosting providers to manage virtual machine deployments and customer infrastructure. The software's update mechanism typically handles security patches and feature releases across thousands of installations. The BGP hijacking technique exploits weaknesses in internet routing protocols to redirect traffic destined for legitimate servers to attacker-controlled infrastructure. This supply chain attack vector bypasses traditional endpoint security measures since victims believe they are downloading authentic updates. Affected users should verify the authenticity of any Virtualizor installations and updates. The attack underscores persistent vulnerabilities in BGP security and the risks of relying on unverified update channels for critical infrastructure management tools.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Iran-linked hackers have compromised approximately 100 American water utilities in a sustained campaign targeting critical infrastructure. The EPA is allocating $11 million in funding to strengthen cybersecurity defenses across water systems.

1H AGOSecurity Desk

A critical authentication bypass vulnerability in JFrog Artifactory is being actively exploited to create administrative access tokens. The flaw (CVE-2026-82329) grants attackers full control over software repositories.

1H AGOSecurity Desk

Spyware was used against Serbian student activists and politicians organizing anti-corruption protests ahead of March local elections, according to a new report. The targeting allegedly focused on opponents of President Aleksandar Vucic.

1H AGOIndustry Desk

The New York Stock Exchange deployed Anthropic's Project Glasswing to identify and remediate cybersecurity vulnerabilities, NYSE President Lynn Martin disclosed to Congress.

1H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.