important · Infrastructure — Update chain
A BGP hijack turned Virtualizor's unsigned updater into persistent host compromise.
Affects
Virtualizor, a Linux virtualization-management control plane installed on servers that host and administer virtual machines
The unauthorized route diverted ACME and update traffic to a validly certified attacker endpoint. With no package-signature check, the updater installed a modified package and persistent systemd service.
Detail and 1 source
Package signing is promised, but the vendor did not say that enforcement has shipped.