BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Summary
Ars Technica covers a supply chain-style BGP hijack that infected Softaculous updates by hijacking a small IP space via Hetzner Online and other providers. The attack exploited lax routing security, allowed by misconfigured ROA/RPKI settings and a too-permissive /24 prefix, enabling malware delivery and TLS validation bypass until mitigations were enacted.