<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bgp-Hijack on CuraSec</title><link>https://curasec.metacog.co.kr/tags/bgp-hijack/</link><description>Recent content in Bgp-Hijack on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/bgp-hijack/index.xml" rel="self" type="application/rss+xml"/><item><title>BGP Hijack Poisons Virtualizor Update Channel, 5+ Hypervisors Root-Compromised</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-bgp-hijack-delivers-malicious-virtualizor-update-that-establ/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-bgp-hijack-delivers-malicious-virtualizor-update-that-establ/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Any Virtualizor installation that auto-updated after August 28 at ~20:57 UTC may have received the trojanized package and should be treated as compromised; immediately audit those hypervisors for persistence mechanisms (cron, SSH keys, kernel modules) and isolate pending forensic review.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Confirmed root-level compromise on 5 hypervisors with an update-window starting August 28 at 20:57 — sweep all Virtualizor hosts for new root SSH authorized_keys, unexpected cron jobs, or novel init services added after that timestamp; initiate assume-breach IR process for any positive hits.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your infrastructure or a managed hosting vendor runs Virtualizor, request a written attestation from them confirming whether their hypervisors fell within the compromised update window, and add BGP-hijack supply-chain risk to the next vendor risk review cycle.&lt;/li>
&lt;/ul></description></item></channel></rss>