Latest BGP hijack targets hosting software vendor
A forged, RPKI-valid more-specific route helped attackers obtain a valid TLS certificate and deliver a malicious Virtualizor update to a small number of installations. The incident shows why RPKI validation alone cannot stop a determined route hijack.
The route redirected traffic for Softaculous update infrastructure by announcing a /24 inside Hetzner’s /16, with a forged origin and permissive ROA maxLength. The article argues strict ROAs and BGP monitoring could have limited propagation enough for multi-perspective certificate checks to detect the interception. Hetzner tightened three ROAs after disclosure, but the author says similar maxLength gaps remain in much of its address space. A Lobsters commenter called out the valid certificate as the especially alarming part.