09/03/2026
A trusted update can still be the wrong update.
Softaculous says an unauthorized BGP route hijack between August 28–30 temporarily redirected traffic for part of its infrastructure. BleepingComputer reports that a malicious Virtualizor update reached a small number of installations checking for updates while traffic was diverted. Softaculous says its investigation is ongoing and reports no evidence that other Softaculous products were compromised.
The bigger SMB lesson: HTTPS alone isn’t the whole identity check. If traffic is rerouted, a connection can still look legitimate while reaching the wrong server.
Before your next update:
• Use official vendor advisories and admin portals: not email links.
• Verify signatures or checksums when available.
• Test updates outside production and keep a known-good backup.
• Review new services, scheduled tasks, admin accounts, API keys, and outbound connections after unusual updates.
• Know who can pause patching when a vendor incident is active.
Virtualizor operators should review the vendor advisory and check for /etc/systemd/system/java-jre-update.service. Don’t delete potential evidence: get expert help if you find it.
Poll: Which safeguard is strongest in your environment; signed updates, staged testing, backups, or post-update monitoring? Tell us below.
We’re sharing practical guidance in the B&R Computers Resources hub. Link in the first comment.
Source: Softaculous security advisory and BleepingComputer reporting.