#Virtualizor
Hackers hijacked BGP routing to deliver malicious Virtualizor updates, compromising root access on some servers and prompting security warnings.

#RootAccess #Vendor #infosec

Full synthesis & sources: yasna.io
33-hour BGP hijack of Softaculous traffic prompts security scramble
Hackers hijacked BGP routing to deliver malicious Virtualizor updates, compromising root access on some servers and prompting security warnings.
yasna.io
September 30, 2026 at 5:50 PM
Virtualizor: the Login Parameter That Skips the Login https://packetstorm.news/news/view/44081 #news
September 25, 2026 at 7:38 PM
Virtualizor: the Login Parameter That Skips the Login https://packetstorm.news/news/view/43847 #news
September 23, 2026 at 7:41 PM
Latest BGP hijack targets hosting software vendor
Discussion | lobsters | Author: fanf

#Networking
Latest BGP hijack targets hosting software vendor
Guest Post: An analysis of the BGP hijack against Softaculous that enabled an attacker to obtain a fraudulent TLS certificate and distribute a malicious Virtualizor update.
blog.apnic.net
September 23, 2026 at 12:00 PM
🚨 CVE-2026-43642 — CVSS 9.2 CRITICAL

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in t...

🔎 https://stemshop.top/cve/CVE-2026-43642

#CVE #CyberSecurity #InfoSec
September 22, 2026 at 8:08 PM
🚨 CVE-2026-43641 — CVSS 9.3 CRITICAL

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in ...

🔎 https://stemshop.top/cve/CVE-2026-43641

#CVE #CyberSecurity #InfoSec
September 22, 2026 at 8:08 PM
CVE-2026-43642 - virtualizor
The Virtualizor control panel (versions before 3.2.9 and 3.0.0) lets anyone on the internet send specially crafted data to its billing feature, causing the server to run…

Too many irrelevant or confusing CVEs? Use stackflag.com

#virtualizor #softaculous #CVE #infosec
CVE-2026-43642: Virtualizor permits remote code execution through billing module
The Virtualizor control panel (versions before 3.2.9 and 3.0.0) lets anyone on the internet send specially crafted data to its billing feature, causing.
stackflag.com
September 22, 2026 at 8:00 PM
CVE-2026-43641 - virtualizor
The Virtualizor control panel (versions before 3.2.9) can be tricked into running any command on the server without a password. This gives a remote attacker full control…

Too many irrelevant or confusing CVEs? Use stackflag.com

#virtualizor #softaculous #CVE #infosec
CVE-2026-43641: Virtualizor lets attackers run commands as root
The Virtualizor control panel (versions before 3.2.9) can be tricked into running any command on the server without a password.
stackflag.com
September 22, 2026 at 8:00 PM
🚨 EUVD-2026-84620
📊 9.3/10
🏢 softaculous

📝 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unau...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84620

#cybersecurity #infosec #cve #euvd
September 22, 2026 at 7:01 PM
🚨 EUVD-2026-84622
📊 9.2/10
🏢 softaculous

📝 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unaut...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84622

#cybersecurity #infosec #cve #euvd
September 22, 2026 at 7:00 PM
🚨 EUVD-2026-84624
📊 8.7/10
🏢 softaculous

📝 Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unau...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84624

#cybersecurity #infosec #cve #euvd
September 22, 2026 at 7:00 PM
right after the virtualizor attack, i started a thing that I now just hastily "finished" to try to explain (originally for CISOs — b/c most aren't/weren't cyber practitioners) PQ and why it's necessary.

this is said thing: https://inferenceandin.tel/stories/post-quantum-explained.html

still […]
Original post on mastodon.social
mastodon.social
September 17, 2026 at 2:40 PM
w/r/t that "post quantum" stuff I've been blathering abt for a couple weeks now.

i threw together a PQ "watch" on one of my sites back when we ($WORK) thought we might do a thing on PQ (we aren't this year) — https://rud.is/pqwatch/

then the Virtualizor attack ( […]
Original post on mastodon.social
mastodon.social
September 17, 2026 at 2:38 PM
Today we're re-sharing a post from Doug Madory at Kentik with technical details of the BGP hijack against Softaculous Ltd, the company behind the Softaculous auto-installer and the Virtualizor VM management platform.

Full article: manrs.org/2026/09/late...
Latest BGP Hijack Targets Hosting Software Vendor - MANRS
A BGP hijack targeting Softaculous shows how routing attacks can enable malicious software updates and bypass layers of Internet security.
manrs.org
September 14, 2026 at 2:05 PM
am a tad under the wx today (and fairly planted in a chair) so i took the domains from the cybersecurity vendor "llms.txt" post the other day and decided to see if they passed the `virtualizor` test (well, I didn't check BGP yet) and the post-quantum test.

The blog post title is kind of a TL;DR […]
Original post on mastodon.social
mastodon.social
September 11, 2026 at 5:54 PM
#セキュリティのアレ.316 の54:40〜くらいで「なた」というツールが出てきて気になったけど「nata」で検索してもなかなか出てこない
多分「Nezha(哪吒)」かな?

第316回 励まして!褒めて!スペシャル! - podcast - #セキュリティのアレ https://www.tsujileaks.com/?p=2368
哪吒监控 V2 - 开源服务器监控与运维平台 | 官方文档 https://nezha.wiki/
第316回 励まして!褒めて!スペシャル!
・原宿餃子楼 ・August 27 outage: Incident report | Proton ・ラムネ|森永製菓株式会社 ・Security Incident – BGP Hijacking – Virtualizor ・Latest BGP Hijack Targets Hosting Software Vendor | Kentik Blog ・#StopRansomware: Medusa Ransomware | CISA ・The Crown Prince, Nezha | Huntress ・GTO | 関西テレビ放送 カンテレ ・俺のスカート、どこ行った?|日本テレビ 辻伸弘メモ:30分はかなり短い。不満。再放送してほしいねん。久々の3人でご飯。入ってきてからのこと。冷却故障再び。想定の幅。どんなお便りもありがたいんですよ。知らん人からの招待に気をつけて。日本にも来てるって!注意喚起って何かしら目を引くものあるといいですよね。Asanaとかもあるんかな。こういった攻撃は状況全体を見渡す形での管理しにくそう。知り合いや同じ組織の人から来るのは何故なのか。どこまでそういったリストを用いているのか知りたい。先行マルウェア。割とそこそこ発生しているんですね。BGPハイジャックの後、悪意のあるアップデートを配信ってこれきついなぁ。証明書まで用意されたらインストール後まで気付きようないやん。配布されたもので認証情報が取られた?狙われた顧客のジャンルを考えると影響範囲が広がりそうなインシデントですね。3CXの例ですね。自分たちの管理が及ぶところかそうでないところかでレスポンスの迅速さに影響でそう。便利さと安全性のバランス。バレンタインデーが最後のリークであるMadusaの話。保険というか医療関係でしたね。IABの募集は結構前の印象あった。広範囲に攻撃していけそうなところをフィルタする仕組み。開けて閉めて。ネットワーク全体を効率的に管理する方向に進んでいると思う。時間の経過で変化するものとしなさそうなものの見極め、ジェネリックな部分はどこかを考えることは大事です。28年ぶりでした。 【チャプター】 | いつもの雑談から | 00:00 | | お便りのコーナー | 05:27 | | (P) Slack の不正なワークスペース招待への注意喚起 | 18:50 | | (N) BGP ハイジャックによるソフトウェアサプライチェーン攻撃 | 30:40 | | (T) Medusa ランサムウェアの攻撃活動 | 46:54 | | オススメのアレ | 62:30 | https://www.tsujileaks.com/media/are_260907_tochigi.mp3 Podcast: Play in new window | Download Subscribe: RSS
www.tsujileaks.com
September 10, 2026 at 11:04 PM
🟢 BGP Attack Enables Distribution of Malicious Virtualizor Updates

🗨️ Experts at Softaculous, the company behind the Virtualizor control panel used by hosting providers to create and manage…

#news
BGP Attack Enables Distribution of Malicious Virtualizor Updates
Read more
hackmag.com
September 4, 2026 at 3:30 PM
This week's data breach roundup includes:
—FBI probes a massive breach of U.S. driver's licenses
—Dropbox accounts breached
—Border Gateway Protocol hijack compromises Virtualizor servers
—U.S. Coast Guard opens a cybersecurity policy office
www.databreachtoday.com/breach-round...
Breach Roundup: FBI Probes Sale of 153 Million Driver's Licenses
This week: a massive breach of U.S. driver's licenses, Dropbox accounts breached, a BGP hijack, Artifactory flaw, Russian national indicted, Aesto health breach, a
www.databreachtoday.com
September 4, 2026 at 1:50 PM
BGP route hijack report from the Virtualizor network successfully bypassed RPKI with valid but false certificates.

www.virtualizor.com/blog/securit...
Security Incident – BGP Hijacking – Virtualizor
www.virtualizor.com
September 4, 2026 at 9:39 AM
Drive-by data theft.

Nexus is reportedly selling over 153 million driver's license scans on the dark web, prompting an FBI investigation. OpenAI has announced its models have achieved a significant "Critical" capability threshold in cybersecurity. International law enforc…
#hackernews #news #openai
Drive-by data theft.
Nexus is reportedly selling over 153 million driver's license scans on the dark web, prompting an FBI investigation. OpenAI has announced its models have achieved a significant "Critical" capability threshold in cybersecurity. International law enforcement successfully disrupted a long-standing botnet known as Sality. Cybercriminals are now exploiting AI hallucinations for a tactic called "slop squatting." Urgent security patches have been released for Cleo Harmony and Virtualizor vulnerabilities. A significant healthcare data breach occurred at Nutex Health in Texas, with hackers threatening to leak stolen patient information. A Russian national faces charges for allegedly infecting tens of thousands of freelancers with remote-access malware. AI advancements may also complicate government access to hacking tools by impacting the supply chain for such software. Rob Allen from Threat Locker discussed strategies for protecting workplaces against AI threats. The episode also featured space-cyber news and encouraged listeners to engage with the podcast.
www.thecyberwire.com
September 3, 2026 at 9:22 PM