Latest BGP hijack targets hosting software vendor
Summary
The article details a BGP hijack used against the hosting software vendor Softaculous, explaining how the attacker obtained a valid TLS certificate and delivered a malicious update. It discusses the interplay between BGP routing, certificate issuance (MPIC and CA validation), and ROA-based protections, and highlights monitoring and security practices to mitigate such attacks.