It seems that the upstream provider, Hetzner AG, does have an RPKI ROA for their /16 range, with a maxlength of /24; but that a lot of people out there still aren't doing RPKI validation. That would have blocked this hijack.
33-hour BGP hijack of Softaculous traffic prompts security scramble
Softaculous and Virtualizor customers are being urged to reset credentials and inspect their servers after a 33-hour BGP hijacking incident diverted traffic and delivered malware to a handful of installations. Softaculous makes software for the web hosting industry, while its Virtualizor control panel is used by providers and …
COMMENTS
-
Tuesday 1st September 2026 20:44 GMT Anonymous Coward
Certificate?
How could they get a certificate? I suppose if they got control of the IP, they'd send out a request to let's encrypt from there and let's encrypt would connect back to the attackers machine to authorize the certificate.
This would be a HUGE hole, as this is basically the whole point of having certificates in the first place.
What am I missing here?
-
Tuesday 1st September 2026 22:54 GMT DS999
Re: Certificate?
Yes having recently set up Let's Encrypt you can do it via placing something on your HTTP server (which I don't have) or in your DNS (which is what I used) That gives you two routes to fake a certificate though, taking control of their IP range lets you do it the HTTP way, taking control of their registrar's account (assuming they have them doing their DNS for them, which most do these days) lets you do it another way.
-
Wednesday 2nd September 2026 05:15 GMT Kurgan
Re: Certificate?
The fact that unless you have a real person come to see you and see your credentials (documents, etc) and validate that you are who you say you are, there is no way to completely avoid fake certs being issued. And even then, you could produce fake evidence, fake documents, etc. Or the whole CA could be compromised / colluded. Certificates are not 100% secure.
-