<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Security — LowEndTalk</title>
        <link>https://lowendtalk.com/</link>
        <pubDate>Mon, 31 Aug 2026 07:29:09 +0000</pubDate>
        <language>en</language>
            <description>Security — LowEndTalk</description>
    <atom:link href="https://lowendtalk.com/categories/security/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>URGENT: Virtualizor Compromised (31st AUG)</title>
        <link>https://lowendtalk.com/discussion/220625/urgent-virtualizor-compromised-31st-aug</link>
        <pubDate>Mon, 31 Aug 2026 00:32:14 +0000</pubDate>
        <category>Security</category>
        <dc:creator>Jamie_DreamIT</dc:creator>
        <guid isPermaLink="false">220625@/discussions</guid>
        <description><![CDATA[<p>Virtualizor has been compromised, their BGP hijack a few days ago seems to have a deployed a malicious package.</p>

<ul>
<li>RESET/LIMIT ALL API CREDENTIALS IN THE VIRT MASTER PANEL BY IP</li>
<li>CHECK FOR SUSPICIOUS KEYS AND ENSURE SSH IS LOCKED DOWN</li>
<li>CHECK IF THIS FILE EXISTS ( /etc/systemd/system/java-jre-update.service )</li>
</ul>

<p>If you're an affected host, NOC or provider and would want to work together, please DM me, we'll appreciate any assistance here.</p>

<p>Comms are being sent for existing customers, at this stage, we don't see evidence of VPS's being compromised.</p>

<p>Good luck to other providers out there.</p>
]]>
        </description>
    </item>
   </channel>
</rss>
