{
  "story_id": "efb443def343f78aa41444eb73bebe29",
  "desk": "drm3",
  "revision": 1,
  "published_at": "2026-09-02T13:12:45.000Z",
  "content_hash": "572fc456b1952e055e6e98451add5027973f25631368ec714cd5c6f04f45dd22",
  "hash_basis": "sha256 over `headline\\ndek\\nprose`, plus `\\n` + the canonical citations JSON when any source is placed, plus `\\n#blog` for blogs",
  "basis": {
    "headline": "BGP hijack exploits routing and TLS flaws to push malware via Softaculous updates",
    "dek": "Hackers hijacked BGP routes and TLS issuance to take over Softaculous IPs and distribute malware disguised as updates.",
    "prose": "Hackers carried out a supply chain attack that installed malware on networks by hijacking a chunk of Internet space used for updates of cloud management software. [^1]\n\nThe attackers performed a BGP hijacking to obtain control over IP addresses assigned to Softaculous, a company based in the United Arab Emirates. [^2]\n\nThe attackers used the hijacked IP addresses to push malware masquerading as updates to unsuspecting users. [^3]\n\nSoftaculous confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted by a BGP hijack. [^4]\n\nThe attackers delivered a malicious Virtualizor package to some installations by exploiting the diverted update traffic, and the update client lacked cryptographic package verification. [^5]\n\nVirtualizor reported that hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic to an attacker-operated server during the incident window from August 28 at 20:57 UTC to August 30 at 06:10 UTC. [^6]\n\nSoftaculous used the hijacked IP addresses to issue updates and host a client and billing site. [^7]\n\nSoftaculous encourages all Virtualizor operators to check for potential compromises, reset client-area passwords, review account activity, and regenerate API keys. [^8]\n\nSoftaculous notes that their product update clients did not yet cryptographically verify update packages, which allowed a modified package to be installed without rejection. [^9]\n\nThe BGP hijack started at approximately 20:57 UTC on August 28, 2026, when AS62390 (NexonHost) began announcing a portion of German web hosting provider Hetzner's address space. [^10]\n\nA hosting-provider account identified as AlbaHost said that 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise due to malicious commands inserted into legitimate files. [^11]\n\nVirtualizor released Patch 9 with a Security Analyzer on September 1, 2026, but stated that cryptographic package signing remained future work. [^12]",
    "cited": "[{\"statement\":\"Hackers carried out a supply chain attack that installed malware on networks by hijacking a chunk of Internet space used for updates of cloud management software.\",\"source\":\"arstechnica.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T11:00:43.000Z\",\"publisher_count\":1,\"sources\":[\"arstechnica.com\"]},{\"statement\":\"The attackers performed a BGP hijacking to obtain control over IP addresses assigned to Softaculous, a company based in the United Arab Emirates.\",\"source\":\"arstechnica.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T11:00:43.000Z\",\"publisher_count\":1,\"sources\":[\"arstechnica.com\"]},{\"statement\":\"The attackers used the hijacked IP addresses to push malware masquerading as updates to unsuspecting users.\",\"source\":\"arstechnica.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T11:00:43.000Z\",\"publisher_count\":1,\"sources\":[\"arstechnica.com\"]},{\"statement\":\"Softaculous confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted by a BGP hijack.\",\"source\":\"SecurityWeek\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T11:31:36.000Z\",\"publisher_count\":1,\"sources\":[\"SecurityWeek\"]},{\"statement\":\"The attackers delivered a malicious Virtualizor package to some installations by exploiting the diverted update traffic, and the update client lacked cryptographic package verification.\",\"source\":\"The Hacker News\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T13:12:45.000Z\",\"publisher_count\":1,\"sources\":[\"The Hacker News\"]},{\"statement\":\"Virtualizor reported that hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic to an attacker-operated server during the incident window from August 28 at 20:57 UTC to August 30 at 06:10 UTC.\",\"source\":\"The Hacker News\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T13:12:45.000Z\",\"publisher_count\":1,\"sources\":[\"The Hacker News\"]},{\"statement\":\"Softaculous used the hijacked IP addresses to issue updates and host a client and billing site.\",\"source\":\"arstechnica.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T11:00:43.000Z\",\"publisher_count\":1,\"sources\":[\"arstechnica.com\"]},{\"statement\":\"Softaculous encourages all Virtualizor operators to check for potential compromises, reset client-area passwords, review account activity, and regenerate API keys.\",\"source\":\"SecurityWeek\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T11:31:36.000Z\",\"publisher_count\":1,\"sources\":[\"SecurityWeek\"]},{\"statement\":\"Softaculous notes that their product update clients did not yet cryptographically verify update packages, which allowed a modified package to be installed without rejection.\",\"source\":\"SecurityWeek\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T11:31:36.000Z\",\"publisher_count\":1,\"sources\":[\"SecurityWeek\"]},{\"statement\":\"The BGP hijack started at approximately 20:57 UTC on August 28, 2026, when AS62390 (NexonHost) began announcing a portion of German web hosting provider Hetzner's address space.\",\"source\":\"SecurityWeek\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T11:31:36.000Z\",\"publisher_count\":1,\"sources\":[\"SecurityWeek\"]},{\"statement\":\"A hosting-provider account identified as AlbaHost said that 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise due to malicious commands inserted into legitimate files.\",\"source\":\"The Hacker News\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T13:12:45.000Z\",\"publisher_count\":1,\"sources\":[\"The Hacker News\"]},{\"statement\":\"Virtualizor released Patch 9 with a Security Analyzer on September 1, 2026, but stated that cryptographic package signing remained future work.\",\"source\":\"The Hacker News\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T13:12:45.000Z\",\"publisher_count\":1,\"sources\":[\"The Hacker News\"]}]",
    "kind": "news"
  },
  "receipt_verify": "Ed25519 over the dot-joined string `slice_hash.cursor_from.cursor_to.view.view_version.row_count`; public_key and sig are base64url of the raw 32-byte key / 64-byte signature",
  "receipt": null,
  "receipt_note": "this revision predates receipt-keeping (before v0.37.0); the filed row lives in the record",
  "generation_chain": {
    "wire": {
      "stream": "fountain_news",
      "story_id": "40aab4566826e5975c55a7cc32abd78e",
      "thread_id": "fb649ff068c820ac867d85cea7625039",
      "thread_label": "Softaculous",
      "novelty": "UPDATE",
      "content_hash": "7be0e528bc1c7f781afce40b1edfe0e8cdab81b1e50096be2f85e6ff2bf02bd0",
      "last_published_at": "2026-09-02T13:12:45.000Z",
      "read_receipt": {
        "slice_hash": "a31312843791ba4a7f7197e2064bbc6dbbaeb27a8fa6493248b66c9a78988338",
        "cursor_from": "eyJ0cyI6IjIwMjYtMDktMDJUMTI6NDA6MzYuMzIwMDAwWiIsImlkIjoiYjE4N2ZiMmNmNTAwZDFlMTk5ZWUzYmFjODc1NzlkYzEiLCJ2IjoiMSJ9",
        "cursor_to": "eyJ0cyI6IjIwMjYtMDktMDJUMTM6MjE6NDUuMDAwMDAwWiIsImlkIjoiY2FjYjg1OTkyMDViN2I3MWM0YzhmYmUyYWMyZDA1OWYiLCJ2IjoiMSJ9",
        "view": "v_fountain_news",
        "view_version": "1",
        "row_count": 100,
        "window_days": 3,
        "bytes_scanned": 10113494,
        "credits": 8,
        "price_per_100_rows": 8,
        "sig": "lGlnB4PdzwLqn0AEsyMHFy7UTUb8zVWclGH7al5myhkRCtkla9YXgJJlVAdBHqRFnLKXX-yW3yJ_HnDUo0LlAA",
        "public_key": "bMUigy8O0jOnBxQ4Sc-5lwhIZ8LQVAhxMbR7qESVuUE",
        "signer_path": "lakehouse/data-extract/v1",
        "alg": "Ed25519",
        "signed": true
      }
    },
    "written_at": "2026-09-03T00:31:24.665Z"
  },
  "cited_facts": [
    {
      "statement": "Hackers carried out a supply chain attack that installed malware on networks by hijacking a chunk of Internet space used for updates of cloud management software.",
      "source": "arstechnica.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T11:00:43.000Z",
      "publisher_count": 1,
      "sources": [
        "arstechnica.com"
      ]
    },
    {
      "statement": "The attackers performed a BGP hijacking to obtain control over IP addresses assigned to Softaculous, a company based in the United Arab Emirates.",
      "source": "arstechnica.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T11:00:43.000Z",
      "publisher_count": 1,
      "sources": [
        "arstechnica.com"
      ]
    },
    {
      "statement": "The attackers used the hijacked IP addresses to push malware masquerading as updates to unsuspecting users.",
      "source": "arstechnica.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T11:00:43.000Z",
      "publisher_count": 1,
      "sources": [
        "arstechnica.com"
      ]
    },
    {
      "statement": "Softaculous confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted by a BGP hijack.",
      "source": "SecurityWeek",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T11:31:36.000Z",
      "publisher_count": 1,
      "sources": [
        "SecurityWeek"
      ]
    },
    {
      "statement": "The attackers delivered a malicious Virtualizor package to some installations by exploiting the diverted update traffic, and the update client lacked cryptographic package verification.",
      "source": "The Hacker News",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T13:12:45.000Z",
      "publisher_count": 1,
      "sources": [
        "The Hacker News"
      ]
    },
    {
      "statement": "Virtualizor reported that hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic to an attacker-operated server during the incident window from August 28 at 20:57 UTC to August 30 at 06:10 UTC.",
      "source": "The Hacker News",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T13:12:45.000Z",
      "publisher_count": 1,
      "sources": [
        "The Hacker News"
      ]
    },
    {
      "statement": "Softaculous used the hijacked IP addresses to issue updates and host a client and billing site.",
      "source": "arstechnica.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T11:00:43.000Z",
      "publisher_count": 1,
      "sources": [
        "arstechnica.com"
      ]
    },
    {
      "statement": "Softaculous encourages all Virtualizor operators to check for potential compromises, reset client-area passwords, review account activity, and regenerate API keys.",
      "source": "SecurityWeek",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T11:31:36.000Z",
      "publisher_count": 1,
      "sources": [
        "SecurityWeek"
      ]
    },
    {
      "statement": "Softaculous notes that their product update clients did not yet cryptographically verify update packages, which allowed a modified package to be installed without rejection.",
      "source": "SecurityWeek",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T11:31:36.000Z",
      "publisher_count": 1,
      "sources": [
        "SecurityWeek"
      ]
    },
    {
      "statement": "The BGP hijack started at approximately 20:57 UTC on August 28, 2026, when AS62390 (NexonHost) began announcing a portion of German web hosting provider Hetzner's address space.",
      "source": "SecurityWeek",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T11:31:36.000Z",
      "publisher_count": 1,
      "sources": [
        "SecurityWeek"
      ]
    },
    {
      "statement": "A hosting-provider account identified as AlbaHost said that 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise due to malicious commands inserted into legitimate files.",
      "source": "The Hacker News",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T13:12:45.000Z",
      "publisher_count": 1,
      "sources": [
        "The Hacker News"
      ]
    },
    {
      "statement": "Virtualizor released Patch 9 with a Security Analyzer on September 1, 2026, but stated that cryptographic package signing remained future work.",
      "source": "The Hacker News",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T13:12:45.000Z",
      "publisher_count": 1,
      "sources": [
        "The Hacker News"
      ]
    }
  ],
  "note": "A signature proves who filed this and that it has not changed since. It never makes a claim true."
}