#Virtualizor
Wrote a post about the recent BGP hijack of Softaculous/Virtualizor that enabled the delivery of a malicious software update to some customers.
www.kentik.com/blog/latest-...
www.kentik.com
September 2, 2026 at 2:37 PM
Virtualizor: the Login Parameter That Skips the Login https://packetstorm.news/news/view/44081 #news
September 25, 2026 at 7:38 PM
-BGP hijack delivers malicious Virtualizor updates
-Indian authorities take down Telegram doxing bot
-Composer packages deliver iOS badness
-Tectonic hacked for $75m
-White House launches Project Watershed 250
-Andrew Tate's War Room leak

P: risky.biz/RBNEWS608/
N: news.risky.biz/risky-bullet...
September 2, 2026 at 7:33 AM
Taking a look at this BGP hijack of 162.55.80.0/24 that targeted Virtualizor in recent days.

Hijackers forged the origin to make the route RPKI-valid:

... 6204 62390 24940 (hijack AS path)
... 24940 (legit AS path)

More from the victim here:

www.virtualizor.com/blog/securit...
August 31, 2026 at 10:00 PM
Virtualizor: the Login Parameter That Skips the Login https://packetstorm.news/news/view/43847 #news
September 23, 2026 at 7:41 PM
CVE-2026-43641 - virtualizor
The Virtualizor control panel (versions before 3.2.9) can be tricked into running any command on the server without a password. This gives a remote attacker full control…

Too many irrelevant or confusing CVEs? Use stackflag.com

#virtualizor #softaculous #CVE #infosec
CVE-2026-43641: Virtualizor lets attackers run commands as root
The Virtualizor control panel (versions before 3.2.9) can be tricked into running any command on the server without a password.
stackflag.com
September 22, 2026 at 8:00 PM
CVE-2026-43642 - virtualizor
The Virtualizor control panel (versions before 3.2.9 and 3.0.0) lets anyone on the internet send specially crafted data to its billing feature, causing the server to run…

Too many irrelevant or confusing CVEs? Use stackflag.com

#virtualizor #softaculous #CVE #infosec
CVE-2026-43642: Virtualizor permits remote code execution through billing module
The Virtualizor control panel (versions before 3.2.9 and 3.0.0) lets anyone on the internet send specially crafted data to its billing feature, causing.
stackflag.com
September 22, 2026 at 8:00 PM
Great example of a targeted attack using a BGP hijack to obtain a valid TLS certificate.
Also shows how limited RPKI is against a determined attacker. They simply spoofed the AS path so the hijack looked RPKI-valid.

Nice write-up by @eldomador.bsky.social
www.kentik.com/blog/latest-...
Latest BGP Hijack Targets Hosting Software Vendor
This post analyzes the technical details of the BGP hijack against Softaculous Ltd, the company behind the Softaculous auto-installer and the Virtualizor VM management platform. The hijack enabled an ...
www.kentik.com
September 2, 2026 at 10:52 PM
New breach: ColoCrossing had 7k email addresses breached from their ColoCloud cloud/VPS service last month. Data also included name and MD5-Crypt password hash. 38% were already in @haveibeenpwned.com . Read more: lowendbox.com/blog/coloclo...
ColoCloud Breach: Virtualizor Bugs Lead to Wild LowEndTalk Thread
ColoCrossing's ColoCloud brand suffered a serious breach today. The CC team is working hard to remediate the situation. Here's what we know so far.
lowendbox.com
June 3, 2025 at 5:16 AM
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.
www.bleepingcomputer.com
September 1, 2026 at 2:45 PM
Softaculous traffic diverted for 33 hours

A 33-hour BGP hijack diverted Softaculous and Virtualizor traffic, potentially leading to credential compromise and malware delivery. Old-school internet routing exploits still hit hard.
September 1, 2026 at 12:48 PM
SANS Stormcast Wednesday, September 2nd, 2026: Guildma Update; Proxmox 7 Auth Bypass; Windows Hotpatch; Virtualizor BGP Hack
https://isc.sans.edu/podcastdetail/10078
September 2, 2026 at 2:01 AM
🚨 CVE-2026-43641 — CVSS 9.3 CRITICAL

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in ...

🔎 https://stemshop.top/cve/CVE-2026-43641

#CVE #CyberSecurity #InfoSec
September 22, 2026 at 8:08 PM
🚨 CVE-2026-43642 — CVSS 9.2 CRITICAL

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in t...

🔎 https://stemshop.top/cve/CVE-2026-43642

#CVE #CyberSecurity #InfoSec
September 22, 2026 at 8:08 PM
Latest BGP hijack targets hosting software vendor
Discussion | lobsters | Author: fanf

#Networking
Latest BGP hijack targets hosting software vendor
Guest Post: An analysis of the BGP hijack against Softaculous that enabled an attacker to obtain a fraudulent TLS certificate and distribute a malicious Virtualizor update.
blog.apnic.net
September 23, 2026 at 12:00 PM
🚨 EUVD-2026-84624
📊 8.7/10
🏢 softaculous

📝 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unau...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84624

#cybersecurity #infosec #cve #euvd
September 22, 2026 at 7:00 PM
🚨 EUVD-2026-84620
📊 9.3/10
🏢 softaculous

📝 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unau...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84620

#cybersecurity #infosec #cve #euvd
September 22, 2026 at 7:01 PM
🚨 EUVD-2026-84622
📊 9.2/10
🏢 softaculous

📝 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unaut...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84622

#cybersecurity #infosec #cve #euvd
September 22, 2026 at 7:00 PM
Virtualizor plugin vuln leads to major VPS ransomware attacks. CloudCone, HostSlick hit hard, with some data unrecoverable. 25% of HostSlick servers infected. Other providers (Virtono, SolidSEOVPS) warned: back up your data! #cybersecurity #VPS
February 1, 2026 at 3:36 AM
记一个很难绷的 One man provider:
12/5 VPS 离线,提 ticket
12/9 依然离线,且发现 Virtualizor 账号被删除
12/11 Trustpilot 一星好评
12/16 终于回复:
"It seems this expired in 13.12.2024"

12/17 我回复:
I kindly remind you that the ticket was submitted Dec 5. :)
December 17, 2024 at 4:37 AM
Virtualizor's BGP hijack shows why signed updates matter. A diverted route and valid TLS were enough to push a malicious package and gain root on some VPS hosts. Read more: https://www.hexon.bot/blog/virtualizor-bgp-hijack-unsigned-updates #Potatosecurity #Infosec
September 2, 2026 at 5:32 PM