Landian News Technology
Preliminary investigation into the Virtualizor supply-chain attack: Hetzner IP range redirected to a hacker-controlled server through BGP hijacking
#Security News Preliminary investigation into the Virtualizor control-panel supply-chain attack: the IP range of German cloud-computing giant Hetnzer was hijacked through BGP routing. A preliminary investigation published by Virtualizor developer Softaculous showed that hackers used Romanian server provider NexonHost/AS62390 to illegally announce a /24 route to override Hetnzer AS6204’s /16 route. Because routing generally prioritizes more-specific prefixes, networks accepting the route would prioritize the hacker-controlled /24 route. Let’s Encrypt domain certificate validation was also hijacked, allowing the hackers to issue Virtualizor certificates directly. Read more: https://ourl.co/126597