Skip to finding
important · Firmware — Virtualizor

A BGP hijack turned trusted Virtualizor updates into persistent root compromise.

Affects

Virtualizor, Linux-based virtualization and hosting-control software installed on hypervisor-management servers.

The attacker announced a more-specific route, diverted vendor traffic, and obtained a valid TLS certificate while certificate validation followed the diversion. Virtualizor then accepted a modified update package without independently checking a package signature.

Detail and 1 source

The malicious update executed as root and established persistence through an SSH key, an unauthorized account, and a systemd service.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 2, 2026