Home / Sep 04, 2026 / Story
0
#10 Ars Technica Security general September 02, 2026 at 11:00 UTC

BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

By Dan Goodin

AI Summary

A BGP hijacking incident resulted in a threat actor using a technically valid TLS certificate for Softaculous domains to redirect traffic and serve malicious Virtualizor software updates to production servers. The attack demonstrates how BGP route manipulation combined with legitimate-looking certificates can completely undermine software update trust chains. The incident is a practical case study in supply chain risk for infrastructure operators relying on third-party software delivery without additional integrity verification.

Relevance score: 80.0/100

# More from September 04