DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Security Incident – BGP Hijacking – Virtualizor

Quality: 8/10 Relevance: 9/10

Summary

Between 28-30 Aug 2026 a BGP hijack redirected traffic for 162.55.80.0/24 (Hetzner), enabling an attacker to obtain a valid TLS certificate and deliver a malicious Virtualizor update to a subset of installations. The post provides a minute-by-minute reconstruction using RIPE RIS data, details two diversion waves, and outlines mitigations (Hetzner's direct /24 announcement, certificate revocation, and a patched Virtualizor release 3.2.9.9) along with concrete remediation steps for operators.

🚀 Service construit par Johan Denoyer