important · Firmware — Virtualizor
A BGP hijack turned trusted Virtualizor updates into persistent root compromise.
Affects
Virtualizor, Linux-based virtualization and hosting-control software installed on hypervisor-management servers.
The attacker announced a more-specific route, diverted vendor traffic, and obtained a valid TLS certificate while certificate validation followed the diversion. Virtualizor then accepted a modified update package without independently checking a package signature.
Detail and 1 source
The malicious update executed as root and established persistence through an SSH key, an unauthorized account, and a systemd service.