Tuesday, 1 September 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

33-hour BGP hijack of Softaculous traffic prompts security scramble

The Register ·
33-hour BGP hijack of Softaculous traffic prompts security scramble

Softaculous and Virtualizor customers are being urged to reset credentials and inspect their servers after a 33-hour BGP hijacking incident diverted traffic and delivered malware to a handful of installations.

Softaculous makes software for the web hosting industry, while its Virtualizor control panel is used by providers and administrators to deploy and manage virtual private servers.

Beginning at around 20:57 UTC on August 28, an unrelated network began announcing a block of Hetzner IP addresses used by Softaculous, diverting some traffic intended for the vendor's systems to an attacker-controlled server.

German hosting provider Hetzner is one of Softaculous's upstream infrastructure providers.

The affected addresses served "a number of Softaculous systems," including Virtualizor's software update endpoint and Softaculous's client and billing site.

The attacker pulled off the BGP hijack by announcing a more specific IP address range than Hetzner normally advertised.

Under standard BGP route selection, the more specific route took precedence wherever it was accepted.

According to Softaculous, the attacker was also able to secure a valid TLS certificate from Let's Encrypt because the certificate authority's automated domain-ownership validation was routed through the hijack too.

This allowed affected connections to reach the attacker's server without triggering the certificate warnings that might otherwise have alerted users.

According to the vendor's timeline, the unauthorized route was initially "accepted by essentially every internet vantage point that receives it," although it flapped repeatedly rather than remaining continuously available.

Softaculous said it reported the issues to Hetzner at around 08:50 UTC on August 29.

The hosting provider began directly announcing the same, more-specific address range, cutting the observed diversion to almost zero for roughly 11 hours.

The unauthorized announcement returned at around 20:00 UTC and was again widely accepted, beginning a second wave that lasted roughly ten hours.

The route was withdrawn between 05:50 and 06:10 UTC on August 30, after which normal routing was restored globally.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›