Tech News
← Home  ·  All topics

Hetzner

2 GoKawiil briefs on this topic

BGP hijack of Softaculous IP space let attackers push malware via fake Virtualizor updates

Attackers exploited weak routing-security configurations at hosting provider Hetzner Online, combined with lapses in TLS certificate issuance, to hijack IP addresses belonging to Softaculous. Because Softaculous used those addresses to distribute software updates, the attackers were able to serve malicious update packages disguised as legitimate Virtualizor updates to customer servers.

BGP hijack lets attackers push malicious update to Virtualizor VPS panel

Softaculous disclosed that attackers hijacked BGP routes for Hetzner-hosted IP space between August 28-30, redirecting traffic meant for Virtualizor's update servers and client portal. The diversion allowed a tampered Virtualizor update package to reach a small number of installations that happened to check for updates during the attack window.