Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

URGENT: Virtualizor Compromised (31st AUG)

124»

Comments

  • nunimnunim Member
    edited 12:06PM

    Softaculous also got new SSL certs at the exact same time as this happened. All of these products received new SAN certs around the same time that don't match the previous issuance patterns:

    https://www.certkit.io/tools/ct-logs/?query=softaculous.com
    https://www.certkit.io/tools/ct-logs/?query=webuzo.com
    https://www.certkit.io/tools/ct-logs/?query=virtualizor.com

    So my worry is that other services were impacted.

  • @forest said:

    @WebProject said:
    This is not the first time such issues have arisen. While we are currently using Virtualizor, we plan to phase out the Virtualizor control panel in favor of our own, more secure, PHP-free panel, which is currently 60% complete.

    I hope it's not vibe-coded.

    This is why it takes time to thoroughly test each step, ensuring perfection without any hanging tasks like Virtualizor does.

  • jsgjsg Member, Resident Benchmarker

    @Jamie_DreamIT said:
    ... Australia's & New Zealand's Fastest Web Hosting

    Looking Glass? Speed test files?

    @virtualizor said:
    ...

    Between 28 Aug ~20:57 UTC and 30 Aug ~06:10 UTC (2026), a block of Hetzner IP addresses used by our services (162.55.80.0/24) was hit by a BGP hijack — internet traffic to those addresses was rerouted to an attacker's server (announced by AS62390 / NexonHost, via transit AS6204 / Zet.net). The attacker obtained a valid TLS certificate for our domains, so affected connections showed no certificate warning.

    (emphasis mine)

    Yeah, sakkurity at work:
    host -t caa virtualizor.com
    Result: virtualizor.com has no CAA record

Sign In or Register to comment.