Security Incident – BGP Hijacking – Virtualizor
Between 28 August 2026 and 30 August 2026, a block of IP addresses used by Softaculous services on Hetzner's infrastructure was affected by a BGP hijack. An unauthorized network announced the address space 162.55.80.0/24, diverting traffic to an attacker's server. The attacker obtained a valid TLS certificate for Softaculous domains, so affected connections showed no certificate warning.
The hijack impacted our software update endpoint and client area/billing site. A malicious Virtualizor update package reached a few servers that checked for updates during the disruption. Routing has been restored, and we are still investigating other products.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.