Skip to finding
important · Infrastructure — Update chain

A BGP hijack turned Virtualizor's unsigned updater into persistent host compromise.

Affects

Virtualizor, a Linux virtualization-management control plane installed on servers that host and administer virtual machines

The unauthorized route diverted ACME and update traffic to a validly certified attacker endpoint. With no package-signature check, the updater installed a modified package and persistent systemd service.

Detail and 1 source

Package signing is promised, but the vendor did not say that enforcement has shipped.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 3, 2026