www.kentik.com/blog/latest-...
www.kentik.com/blog/latest-...
-Indian authorities take down Telegram doxing bot
-Composer packages deliver iOS badness
-Tectonic hacked for $75m
-White House launches Project Watershed 250
-Andrew Tate's War Room leak
P: risky.biz/RBNEWS608/
N: news.risky.biz/risky-bullet...
-Indian authorities take down Telegram doxing bot
-Composer packages deliver iOS badness
-Tectonic hacked for $75m
-White House launches Project Watershed 250
-Andrew Tate's War Room leak
P: risky.biz/RBNEWS608/
N: news.risky.biz/risky-bullet...
Hijackers forged the origin to make the route RPKI-valid:
... 6204 62390 24940 (hijack AS path)
... 24940 (legit AS path)
More from the victim here:
www.virtualizor.com/blog/securit...
Hijackers forged the origin to make the route RPKI-valid:
... 6204 62390 24940 (hijack AS path)
... 24940 (legit AS path)
More from the victim here:
www.virtualizor.com/blog/securit...
The Virtualizor control panel (versions before 3.2.9) can be tricked into running any command on the server without a password. This gives a remote attacker full control…
Too many irrelevant or confusing CVEs? Use stackflag.com
#virtualizor #softaculous #CVE #infosec
The Virtualizor control panel (versions before 3.2.9) can be tricked into running any command on the server without a password. This gives a remote attacker full control…
Too many irrelevant or confusing CVEs? Use stackflag.com
#virtualizor #softaculous #CVE #infosec
The Virtualizor control panel (versions before 3.2.9 and 3.0.0) lets anyone on the internet send specially crafted data to its billing feature, causing the server to run…
Too many irrelevant or confusing CVEs? Use stackflag.com
#virtualizor #softaculous #CVE #infosec
The Virtualizor control panel (versions before 3.2.9 and 3.0.0) lets anyone on the internet send specially crafted data to its billing feature, causing the server to run…
Too many irrelevant or confusing CVEs? Use stackflag.com
#virtualizor #softaculous #CVE #infosec
Also shows how limited RPKI is against a determined attacker. They simply spoofed the AS path so the hijack looked RPKI-valid.
Nice write-up by @eldomador.bsky.social
www.kentik.com/blog/latest-...
Also shows how limited RPKI is against a determined attacker. They simply spoofed the AS path so the hijack looked RPKI-valid.
Nice write-up by @eldomador.bsky.social
www.kentik.com/blog/latest-...
A 33-hour BGP hijack diverted Softaculous and Virtualizor traffic, potentially leading to credential compromise and malware delivery. Old-school internet routing exploits still hit hard.
A 33-hour BGP hijack diverted Softaculous and Virtualizor traffic, potentially leading to credential compromise and malware delivery. Old-school internet routing exploits still hit hard.
https://isc.sans.edu/podcastdetail/10078
https://isc.sans.edu/podcastdetail/10078
#Virtualizor #BGPHijacking #CyberSecurity #SupplyChainAttack #Malware
#Virtualizor #BGPHijacking #CyberSecurity #SupplyChainAttack #Malware
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in ...
🔎 https://stemshop.top/cve/CVE-2026-43641
#CVE #CyberSecurity #InfoSec
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in ...
🔎 https://stemshop.top/cve/CVE-2026-43641
#CVE #CyberSecurity #InfoSec
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in t...
🔎 https://stemshop.top/cve/CVE-2026-43642
#CVE #CyberSecurity #InfoSec
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in t...
🔎 https://stemshop.top/cve/CVE-2026-43642
#CVE #CyberSecurity #InfoSec
📊 8.7/10
🏢 softaculous
📝 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unau...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84624
#cybersecurity #infosec #cve #euvd
📊 8.7/10
🏢 softaculous
📝 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unau...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84624
#cybersecurity #infosec #cve #euvd
📊 9.3/10
🏢 softaculous
📝 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unau...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84620
#cybersecurity #infosec #cve #euvd
📊 9.3/10
🏢 softaculous
📝 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unau...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84620
#cybersecurity #infosec #cve #euvd
📊 9.2/10
🏢 softaculous
📝 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unaut...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84622
#cybersecurity #infosec #cve #euvd
📊 9.2/10
🏢 softaculous
📝 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unaut...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84622
#cybersecurity #infosec #cve #euvd
12/5 VPS 离线,提 ticket
12/9 依然离线,且发现 Virtualizor 账号被删除
12/11 Trustpilot 一星好评
12/16 终于回复:
"It seems this expired in 13.12.2024"
12/17 我回复:
I kindly remind you that the ticket was submitted Dec 5. :)
12/5 VPS 离线,提 ticket
12/9 依然离线,且发现 Virtualizor 账号被删除
12/11 Trustpilot 一星好评
12/16 终于回复:
"It seems this expired in 13.12.2024"
12/17 我回复:
I kindly remind you that the ticket was submitted Dec 5. :)