# Latest BGP hijack targets hosting software vendor

DevFeed: [Latest BGP hijack targets hosting software vendor](<https://devfeed.tech/articles/latest-bgp-hijack-targets-hosting-software-vendor-57743.md>)

Original publisher: [Read original article](<https://blog.apnic.net/2026/09/22/latest-bgp-hijack-targets-hosting-software-vendor/>)

Author: Doug Madory

Published: 2026-09-22T04:04:24Z

Content type: article

Language: en

Sources: [APNIC Blog](<https://devfeed.tech/sources/apnic-blog.md>)

Topics: [BGP](<https://devfeed.tech/topics/bgp.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security](<https://devfeed.tech/topics/security.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [Software](<https://devfeed.tech/topics/software.md>), [Risk](<https://devfeed.tech/topics/risk.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [attack](<https://devfeed.tech/tags/attack.md>), [bgp](<https://devfeed.tech/tags/bgp.md>), [certificate](<https://devfeed.tech/tags/certificate.md>), [guest-post](<https://devfeed.tech/tags/guest-post.md>), [hijack](<https://devfeed.tech/tags/hijack.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [incident](<https://devfeed.tech/tags/incident.md>), [platform](<https://devfeed.tech/tags/platform.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [route](<https://devfeed.tech/tags/route.md>), [routing](<https://devfeed.tech/tags/routing.md>), [routing-table](<https://devfeed.tech/tags/routing-table.md>), [rpki](<https://devfeed.tech/tags/rpki.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [tech-matters](<https://devfeed.tech/tags/tech-matters.md>), [tls](<https://devfeed.tech/tags/tls.md>)

## AI overview

An analysis of a BGP hijack targeting Softaculous, a hosting software vendor. The incident enabled an attacker to obtain a technically valid TLS certificate and distribute a malicious Virtualizor update to a small number of installations.

## Source excerpt

Guest Post: An analysis of the BGP hijack against Softaculous that enabled an attacker to obtain a fraudulent TLS certificate and distribute a malicious Virtualizor update.