An RPKI-valid BGP hijack diverted Softaculous updates toward malware
Between 28 and 30 August 2026, an attacker announced a more-specific Hetzner prefix with a forged origin that passed RPKI validation, obtained a fraudulent TLS certificate, and delivered a malicious Virtualizor update. The full APNIC and Kentik analysis, published on 22 September, shows RPKI alone is not enough: tighten your ROAs, reject invalid routes, and deploy ASPA.