<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bgp-Hijacking on CuraSec</title><link>https://curasec.metacog.co.kr/tags/bgp-hijacking/</link><description>Recent content in Bgp-Hijacking on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 01 Sep 2026 15:28:52 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/bgp-hijacking/index.xml" rel="self" type="application/rss+xml"/><item><title>BGP Hijack Delivers Malicious Updates to Virtualizor VPS Software</title><link>https://curasec.metacog.co.kr/insights/2026-09-01-hackers-push-malicious-virtualizor-update-in-bgp-hijacking-a/</link><pubDate>Tue, 01 Sep 2026 15:28:52 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-01-hackers-push-malicious-virtualizor-update-in-bgp-hijacking-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Any environment running Virtualizor may have received a trojaned update; immediately verify installed binary integrity against known-good checksums and audit servers for post-compromise artifacts. If update timestamps align with the hijack window, treat the host as compromised and scope accordingly.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Identify all Virtualizor-managed hosts in the estate and flag them for assume-breach review; hunt for unusual process execution, outbound connections, or file modifications following recent update activity on those hosts.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> BGP hijacking to intercept software update traffic is a sophisticated supply-chain vector that bypasses code-signing assumptions when the update mechanism itself is redirected; useful context for reviewing how third-party software update trust is modeled in your vendor risk program.&lt;/li>
&lt;/ul></description></item></channel></rss>