Hackers Push Malicious Virtualizor Update via BGP Hijacking Attack
Threat actors redirected Virtualizor update infrastructure traffic, distributing tampered software to VPS environments globally

Key Takeaways
- Threat actors hijacked BGP routing for Virtualizor's update infrastructure in September 2026
- Malicious updates were distributed to users redirecting update requests to attacker-controlled servers
- The attack targets VPS management software, potentially enabling full system takeover of affected environments
- No official patch available; mitigation focuses on verifying update integrity and monitoring BGP routing
- The incident highlights the risks of routing infrastructure attacks in supply chain compromises
Quick answers
- What happened?
- Cybersecurity researchers report that unidentified threat actors hijacked BGP routing for Virtualizor's update infrastructure, redirecting update requests to malicious servers. Users applying these compromised updates risk full system compromise of their VPS environments.
- Which products are affected?
- Virtualizor
- What should defenders do?
- Virtualizor administrators and users should verify update integrity through checksums, rely on official update channels, monitor BGP routing announcements for anomalies, and apply additional network segmentation for VPS environments. No official patch released as the issue involves infrastructure redirection.
According to reporting by BleepingComputer, unidentified threat actors executed a BGP hijacking attack targeting the update infrastructure of Virtualizor, a popular VPS management software platform. The attackers redirected legitimate update requests to malicious servers under their control, distributing tampered software updates to users. The incident, reported in September 2026, affects the global Virtualizor user base. The attack leverages BGP routing manipulation to intercept update traffic, with the malicious updates potentially containing backdoors or persistence mechanisms designed for VPS environments. The full extent of affected entities and specific payloads remains under investigation, with no official patch released as the issue centers on infrastructure redirection rather than a software vulnerability. Security experts recommend that Virtualizor administrators and users verify update integrity, rely on official update channels, and monitor for anomalous BGP routing activity.
Security Details
BGP hijacking redirected Virtualizor update infrastructure traffic to malicious servers. Tampered updates distributed to users may contain backdoors or persistence mechanisms for VPS environments. The attack exploits routing protocol vulnerabilities to intercept software update traffic.
Affected products
Virtualizor
Mitigation
Virtualizor administrators and users should verify update integrity through checksums, rely on official update channels, monitor BGP routing announcements for anomalies, and apply additional network segmentation for VPS environments. No official patch released as the issue involves infrastructure redirection.
Sources
BleepingComputer
Hackers push malicious Virtualizor update in BGP hijacking attack
Sep 1, 2026 · 14:45
Original link
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.


