A 33-hour Border Gateway Protocol (BGP) hijacking incident diverted traffic intended for Softaculous, a web hosting software vendor, to an attacker-controlled server. This allowed the attacker to deliver malware to a small number of Virtualizor installations and potentially intercept user credentials and payment information. The hijacking was facilitated by announcing a more specific IP address range, which took precedence in BGP routing, and even allowed the attacker to obtain a valid TLS certificate from Let's Encrypt. AI
IMPACT This incident highlights vulnerabilities in BGP routing and software update mechanisms, potentially impacting the security of web hosting infrastructure.
RANK_REASON Security incident affecting a software vendor's product distribution.
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →