A 33-hour BGP hijack delivered a malicious Virtualizor update and persistent root access
Starting August 28, 2026, a BGP hijack diverted Softaculous traffic to an attacker-controlled server for 33 hours, which served a malicious Virtualizor update to several hypervisors. Check for the java-jre-update.service unit, demand cryptographically signed update packages, and turn on RPKI filtering with your upstream.