A BGP hijack pushed a malicious Virtualizor update onto production hypervisors
Between August 28 and 30, 2026, attackers hijacked Softaculous’s 162.55.80.0/24 range to deliver a trojaned Virtualizor update to live hypervisors. Every Virtualizor operator should check for the java-jre-update.service, rotate credentials, and demand signed updates.