Virtualizor Update Hijack Puts VPS Hosts at Risk

BleepingComputer reports that attackers pushed a malicious Virtualizor update by hijacking BGP routing for the software's update infrastructure and redirecting update requests to attacker-run servers. The result was code delivered through what looked like the normal vendor update path. The trick was trust in the delivery route. Instead of breaching Virtualizor itself, the hijack made clients talk to a fake update server, which could hand back malicious code that the software accepted as legitimate. That means an installer or updater may have pulled in attacker code while appearing to update normally. For hosting providers and operators running Virtualizor on VPS management hosts, the exposure sits in the update channel itself: if that path can be redirected, the management plane can inherit malware without a direct compromise of vendor systems. The reporting does not settle how many installs were touched, but it does show why checking only the vendor site is not enough here.

Part of the PlainSec briefing for 2026-09-02

Editions

Sources