Virtualizor BGP Hijack: Check the Server After the Update

Stephanie Adlam
6 Min Read
A gold railway switch sends a software-update parcel with a TLS certificate down a wrong track.

A Virtualizor update could arrive over a connection with a valid certificate and still come from an attacker. The vendor says a BGP routing hijack redirected traffic during parts of August 28–30 and delivered a malicious update to a handful of servers. Its update clients did not yet verify packages cryptographically. Normal routing has returned, but the vendor cannot identify every affected installation from its own logs. [1]

If you operate Virtualizor, check the server and its administrative access. A successful update today does not answer what an earlier update installed. Customers using a managed hosting service should ask the operator for the result of the vendor’s checks rather than attempting host-level cleanup themselves.

Start with the vendor’s indicator

The advisory identifies the systemd unit java-jre-update.service in /etc/systemd/system/. If it is present, Virtualizor says to contact support and preserve evidence instead of simply deleting it. The vendor also calls for API-key rotation, trusted-IP restrictions and an access audit. [1]

Check the exact location and surrounding evidence. A familiar Java-related name is not an explanation for an unexpected service. Conversely, do not remove legitimate Java components merely because their names share a word with the indicator.

Finding Next decision
The specified service exists Preserve its details and contact vendor support through the official advisory. Let the responder guide containment and evidence collection.
The service is absent Record that result and continue the access review. One absent indicator does not establish the entire server’s history.
An unknown API key, SSH key or account appears Identify its owner and creation time. Treat unexplained administrative access as an incident finding.
The host was updated during the incident period Keep the update time, source and retained package/log information for support. Current routing cannot reconstruct the earlier download by itself.

Use the official advisory for the current vendor procedure and support destination. It includes a vendor scanning option; review it with your response team before running cleanup. Do not paste a command from an unsolicited forum reply into a privileged server session.

Separate transport recovery from host recovery

BGP selects how traffic moves between networks. In this incident, the wrong route affected both the software request and certificate validation. A valid TLS session therefore did not supply the missing independent package-integrity check. This does not mean encryption is useless; it means the update’s authenticity needs its own verified basis.

For the operator, there are two records to maintain: when the service’s network route returned to normal and what was found on each potentially affected host. Avoid closing the second record merely because the first is resolved.

Retain update logs and relevant authentication evidence before changes overwrite them. Coordinate any isolation with the hosting operator so that the response accounts for the workloads and users on the server.

Client-area access is a separate exposure

Softaculous’s separate update describes two diverted intervals within the broader window, approximately August 28 at 20:57 UTC through August 30 at 06:10 UTC, with a gap between waves. It advises affected Client Area users to reset passwords, review unusual card activity if details were entered, and regenerate NOC API keys where used. It reports no evidence of compromise of its other products. [2]

Keep your times in UTC when comparing them with the advisory. If records only show a local time, note its time zone before deciding whether a login or update overlaps. The broad window is a way to organize review, not proof that every request within it reached the attacker.

A billing-account password reset and a Virtualizor administrative API-key reset address different credentials. List which ones you use, where replacements must be installed and who verifies that old values are no longer accepted. Follow up with the payment provider if account review reveals an unexplained transaction.

Ask for a concrete closure record

A useful hosting response states which servers were checked, whether the named indicator was found, which access credentials were changed and whether any unauthorized persistence remains under investigation. If the operator cannot determine exposure from retained evidence, that uncertainty should remain visible.

For future update design, ask how packages are authenticated independently of the network connection and how a verification failure is handled. An announced improvement is not the same as a deployed, verified control on the installation you operate.

References

  1. Virtualizor. BGP hijack advisory, server indicator and remediation guidance. August 31, 2026.
  2. Softaculous. Incident update and Client Area precautions. August 31, 2026.
Share This Article
Follow:
Stephanie is our wordsmith, transforming technical research into engaging content that resonates with users. Her expertise in cybercrime prevention and online safety ensures that Gridinsoft's advice is accessible to everyone—whether they’re tech-savvy or not.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?