Malicious Virtualizor Update Served via BGP Hijacking
A threat actor leveraged BGP hijacking to redirect traffic intended for Softaculous domains, then used a valid TLS certificate to serve malicious virtualization software updates to unsuspecting users. This attack demonstrates how network-level routing manipulation combined with legitimate cryptographic credentials can enable sophisticated supply chain compromises.
An active campaign is distributing malware through counterfeit installers that impersonate legitimate software vendors using fraudulent download pages and modified archives. Microsoft Defender Experts documented the attack techniques, detection methods, and indicators of compromise to help organizations identify and block these threats. The campaign demonstrates the effectiveness of social engineering at the software distribution stage and highlights the importance of verifying installer authenticity before execution.
A 33-hour BGP hijacking incident redirected Softaculous traffic, prompting the hosting software vendor to issue urgent guidance for customers to reset their credentials and investigate potential malicious package installations. The attack highlights the continued vulnerability of internet routing infrastructure and the cascading impact such hijacks can have on software supply chains and customer trust.
A security researcher has identified nine vulnerabilities in ATM encryption and authentication software that expose critical weaknesses in the broader software supply chain. The flaws suggest that security issues affecting ATMs have implications reaching well beyond individual machines to impact interconnected systems and dependencies across the financial technology ecosystem.
VulnCheck has discovered two pre-installed firmware implants in ZBT routers that enable unauthenticated attackers to achieve root-level command execution on affected devices. The implants, designated CVE-2026-74232 and CVE-2026-74233 and named SPEAKINGSTONE and DARKLANTERN respectively, represent a significant supply-chain risk for organizations deploying these Shenzhen Zhibotong Electronics devices.