[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-hijacked-ips-let-hackers-push-malware-as-software-updates":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},5986,"hijacked-ips-let-hackers-push-malware-as-software-updates","Hijacked IPs Let Hackers Push Malware as Software Updates","Attackers exploited weak BGP routing security and TLS certificate issuance flaws to hijack Softaculous's IPs and push malware disguised as updates.","Hackers pulled off a rare BGP hijacking to hand out malware disguised as routine software updates.\n\nThe attackers exploited weaknesses in the routing security setup at hosting provider Hetzner Online, plus gaps in the process for verifying who controls an IP address before a certificate authority issues a TLS certificate for it. That combination let them hijack a block of IP addresses assigned to Softaculous, a UAE-based company known for its web-software installer platform and for Virtualizor, a management tool for virtualized environments used by hosting providers and data centers. Softaculous used those same IPs to distribute updates and run its client and billing site. Once the attackers controlled the address space, they used it to serve malware dressed up as legitimate updates, though it is not confirmed whether Virtualizor's own update channel was compromised or only Softaculous's broader platform.\n\nThis is a supply chain attack aimed at the infrastructure layer, not end users browsing the web. Softaculous and Virtualizor sit inside hosting providers and data centers, so a single successful hijack can plant malware wherever those tools are trusted to auto-update. Getting a valid TLS certificate for hijacked IPs is the part that should worry defenders most, since that certificate is exactly what's supposed to prove nothing has gone wrong.\n\nBGP hijacks are not new, and neither are rogue certificates, but pulling off both at once is a reminder that routing security and certificate issuance are still two separate systems, each assuming the other one caught the problem.","[\"bgp-hijacking\",\"supply-chain-attack\",\"tls-certificates\",\"hosting-infrastructure\"]","2026-09-02T11:00:43.000Z","2026-09-02T12:41:26.363Z","2026-09-02T12:41:38.256Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The dek claims attackers 'forged TLS certificates,' but the body (and source) describe them exploiting weaknesses in the certificate issuance process to obtain valid certs via the hijacked IPs — not forging certs; fix the dek\u002Fheadline to match the body's accurate technical description, and clarify whether Virtualizor updates specifically (not just Softaculous) were confirmed as part of the malware push.","resolved","security",[32,33,34,35],"bgp-hijacking","supply-chain-attack","tls-certificates","hosting-infrastructure",[37],{"name":38,"url":39},"Ars Technica","https:\u002F\u002Farstechnica.com\u002Fsecurity\u002F2026\u002F09\u002Fwell-executed-bgp-attack-uses-hijacked-ips-to-infect-real-networks\u002F",0,{"sections":42},[43,48,52,57,62,67,72,77,82,87,92,97,102,107],{"name":44,"slug":45,"count":46,"latest_published_at":47},"AI","ai",3385,"2026-09-04T22:17:36.000Z",{"name":49,"slug":30,"count":50,"latest_published_at":51},"Security",565,"2026-09-05T00:03:08.000Z",{"name":53,"slug":54,"count":55,"latest_published_at":56},"Policy","policy",300,"2026-09-04T22:18:34.000Z",{"name":58,"slug":59,"count":60,"latest_published_at":61},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":63,"slug":64,"count":65,"latest_published_at":66},"Hardware","hardware",152,"2026-09-03T09:26:48.000Z",{"name":68,"slug":69,"count":70,"latest_published_at":71},"Consumer Tech","consumer-tech",97,"2026-09-04T15:29:18.000Z",{"name":73,"slug":74,"count":75,"latest_published_at":76},"Science","science",96,"2026-09-03T22:30:00.000Z",{"name":78,"slug":79,"count":80,"latest_published_at":81},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":83,"slug":84,"count":85,"latest_published_at":86},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":88,"slug":89,"count":90,"latest_published_at":91},"Startups","startups",54,"2026-09-04T23:36:14.000Z",{"name":93,"slug":94,"count":95,"latest_published_at":96},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":98,"slug":99,"count":100,"latest_published_at":101},"General","general",37,"2026-09-04T20:22:41.000Z",{"name":103,"slug":104,"count":105,"latest_published_at":106},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":108,"slug":109,"count":110,"latest_published_at":111},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]