<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Virtualizor on CuraSec</title><link>https://curasec.metacog.co.kr/tags/virtualizor/</link><description>Recent content in Virtualizor on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/virtualizor/index.xml" rel="self" type="application/rss+xml"/><item><title>BGP Hijack Poisons Virtualizor Update Channel, 5+ Hypervisors Root-Compromised</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-bgp-hijack-delivers-malicious-virtualizor-update-that-establ/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-bgp-hijack-delivers-malicious-virtualizor-update-that-establ/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Any Virtualizor installation that auto-updated after August 28 at ~20:57 UTC may have received the trojanized package and should be treated as compromised; immediately audit those hypervisors for persistence mechanisms (cron, SSH keys, kernel modules) and isolate pending forensic review.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Confirmed root-level compromise on 5 hypervisors with an update-window starting August 28 at 20:57 — sweep all Virtualizor hosts for new root SSH authorized_keys, unexpected cron jobs, or novel init services added after that timestamp; initiate assume-breach IR process for any positive hits.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your infrastructure or a managed hosting vendor runs Virtualizor, request a written attestation from them confirming whether their hypervisors fell within the compromised update window, and add BGP-hijack supply-chain risk to the next vendor risk review cycle.&lt;/li>
&lt;/ul></description></item><item><title>BGP Hijack Delivers Malicious Updates to Virtualizor VPS Software</title><link>https://curasec.metacog.co.kr/insights/2026-09-01-hackers-push-malicious-virtualizor-update-in-bgp-hijacking-a/</link><pubDate>Tue, 01 Sep 2026 15:28:52 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-01-hackers-push-malicious-virtualizor-update-in-bgp-hijacking-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Any environment running Virtualizor may have received a trojaned update; immediately verify installed binary integrity against known-good checksums and audit servers for post-compromise artifacts. If update timestamps align with the hijack window, treat the host as compromised and scope accordingly.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Identify all Virtualizor-managed hosts in the estate and flag them for assume-breach review; hunt for unusual process execution, outbound connections, or file modifications following recent update activity on those hosts.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> BGP hijacking to intercept software update traffic is a sophisticated supply-chain vector that bypasses code-signing assumptions when the update mechanism itself is redirected; useful context for reviewing how third-party software update trust is modeled in your vendor risk program.&lt;/li>
&lt;/ul></description></item></channel></rss>