September 3, 2026
- The Virtualizor poisoning was a properly executed BGP hijack, with a valid TLS certificate to match (earlier coverage). Attackers exploited routing-security gaps at Hetzner and the certificate issuance process to take over Softaculous IP space and serve a malicious Virtualizor update over trusted TLS (Ars Technica). One hosting provider reported root-level compromise on 5 of 34 hypervisors it checked, with the window opening around 20:57 on 28 August (The Hacker News). (discussion) · Supply Chain
in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion