TechNewsReel
Live

BGP Hijack Exploits Hetzner Routing Lapses to Poison Software Updates

Attackers combined routing manipulation and valid TLS certificates to deliver malicious updates to cloud management software.

TechNewsReel Newsroom · September 2, 2026

Unknown attackers executed a sophisticated supply chain attack by hijacking BGP routing to impersonate update servers for cloud management software. The operation bypassed traditional security checks by combining network-level redirection with legitimate encryption certificates.

According to reports from Ars Technica and The Register, the attackers targeted the update mechanism of Virtualizor, a VPS and cloud management tool used by infrastructure providers. By exploiting routing security weaknesses at hosting provider Hetzner Online, the attackers announced more specific IP ranges than the legitimate owner, effectively redirecting traffic to servers under their control. To ensure the hijacked servers appeared authentic, the attackers obtained valid TLS certificates from Let's Encrypt, exploiting the fact that automated domain-ownership validation was routed through the hijacked path. This allowed the attackers to deliver a malicious Virtualizor update package to a handful of installations.

The Mechanics of Routing Trust

Border Gateway Protocol (BGP) serves as the fundamental system that routes traffic across the global internet. BGP hijacking occurs when an entity falsely announces ownership of IP prefixes, causing the rest of the internet to send traffic to the wrong destination. While such hijacks are frequently used for traffic interception or Distributed Denial of Service (DDoS) attacks, using them to poison software update streams represents a significant escalation in supply chain attacks. In this instance, the attackers did not just redirect traffic; they manipulated the trust chain of the web by securing certificates that validated their fraudulent servers as legitimate.

A Critical Failure in Validation

This incident demonstrates a systemic failure in the trust chain of internet routing and certificate validation. By pairing BGP hijacking with valid TLS certificates, the attackers proved that even HTTPS-secured updates—long considered the industry standard for safety—can be compromised if the underlying routing infrastructure is insecure. The attack highlights a dangerous blind spot: certificate authorities often rely on the very routing infrastructure that BGP hijacks are designed to undermine.

The Path Toward RPKI

Security experts point to this breach as an urgent call for the widespread adoption of Resource Public Key Infrastructure (RPKI). RPKI provides a way to cryptographically verify that a network is authorized to announce a specific IP prefix, which would prevent the unauthorized route announcements used in this attack. Until such standards are universally implemented, infrastructure providers remain vulnerable to high-level impersonation attacks that can bypass traditional encryption.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.