CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: BGP hijack delivers malicious Virtualizor updates

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6073

As cited

Copy frozen at (site build).

Risky Bulletin: BGP hijack delivers malicious Virtualizor updates

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Risky Bulletin: BGP hijack delivers malicious Virtualizor updates

A Border Gateway Protocol (BGP) hijack was used to distribute malicious updates to Virtualizor hosting software, marking a sophisticated supply chain attack. The White House announced Project Watershed 250, and Indian authorities disrupted a Telegram-based doxing operation. Compromised Composer packages also delivered malware targeting iOS systems.

Why it matters: Hosting providers and their customers using Virtualizor face immediate risk from poisoned updates; system administrators should verify update integrity and monitor for unauthorized version changes. iOS developers relying on Composer dependencies need to audit affected packages for compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Risky Bulletin: BGP hijack delivers malicious Virtualizor updates

A Border Gateway Protocol (BGP) hijack was used to distribute malicious updates to Virtualizor hosting software, marking a sophisticated supply chain attack. The White House announced Project Watershed 250, and Indian authorities disrupted a Telegram-based doxing operation. Compromised Composer packages also delivered malware targeting iOS systems.

Why it matters: Hosting providers and their customers using Virtualizor face immediate risk from poisoned updates; system administrators should verify update integrity and monitor for unauthorized version changes. iOS developers relying on Composer dependencies need to audit affected packages for compromise.

VendorsApple
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary