Today's AI/ML headlines are brought to you by ThreatPerspective

Digital Event Horizon

BGP Hijacking: A Comedy of Errors Exposes the Vulnerabilities of Internet Routing Security




A recent BGP hijacking incident has exposed the vulnerabilities of internet routing security, highlighting the need for robust security measures and greater awareness among hosting providers, software developers, and users. The hijacking, which was carried out by hackers using an unusual technique, exploited weaknesses in the routing security setup of hosting provider Hetzner Online and the process for attaining valid TLS certificates. The incident has prompted Softaculous to urge all its users to check their systems for signs of compromise, and it serves as a reminder that even with the widespread adoption of RPKI, a single mistake can still compromise the security of the internet.

  • The recent BGP hijacking incident exposed vulnerabilities in internet routing security.
  • The attack exploited weaknesses in Hetzner Online's routing security setup and failed TLS certificate process.
  • The hackers used a BGP hijacking to obtain control over IP addresses and spread malware.
  • The incident highlights the importance of robust security measures, such as RPKI, in protecting against threats.
  • The incident emphasizes the need for greater awareness and education on internet routing security among hosting providers, software developers, and users.



  • The recent BGP hijacking incident that infected networks and exposed the vulnerabilities of internet routing security is a stark reminder of the need for robust security measures in the ever-evolving digital landscape. The hijacking, which was carried out by hackers using an unusual technique, exploited weaknesses in the routing security setup of hosting provider Hetzner Online and the process for attaining valid TLS certificates.

    The attack began when a small chunk of Softaculous IP space entered the global routing table, and it was announced along the path of several autonomous systems (ASes), including Zet.net, Nexon Host, and Hetzner Online. The attackers took advantage of the lax configuration of routing security in Softaculous' hosting provider, Hetzner Online, and the failure to properly monitor traffic, allowing them to successfully perform a BGP hijacking to obtain control over IP addresses assigned to Softaculous.

    The hackers used the hijacked space to push malware masquerading as updates to unsuspecting users, causing the validation perspectives to reach the attacker's server instead of the legitimate domain operator. This bypassed industry-wide measures for validating TLS certificate requests, which typically require a quorum of certificates to be issued before a certificate is issued.

    The incident highlights the importance of robust security measures, such as RPKI (Resource Public Key Infrastructure), which uses cryptographic records called Route Origin Authorizations (ROAs) to assert the proper origin and prefix mask length of routes in BGP. However, the lax configuration of Hetzner Online and the failure to properly monitor traffic allowed the attackers to bypass these measures.

    The BGP hijacking incident is a rare example of a hijacking being used to spread malware, and it demonstrates the importance of vigilance and robust security measures in protecting against such threats. It also serves as a reminder that even with the widespread adoption of RPKI, a single mistake can still compromise the security of the internet.

    The incident has prompted Softaculous to urge all its users to check their systems for signs of compromise, and it highlights the need for greater awareness and education on internet routing security among hosting providers, software developers, and users.

    In conclusion, the recent BGP hijacking incident is a stark reminder of the need for robust security measures in the digital landscape. It highlights the importance of vigilance and robust security measures, such as RPKI, in protecting against threats like this, and it serves as a reminder that even with the widespread adoption of these measures, a single mistake can still compromise the security of the internet.



    Related Information:
  • https://www.digitaleventhorizon.com/articles/BGP-Hijacking-A-Comedy-of-Errors-Exposes-the-Vulnerabilities-of-Internet-Routing-Security-deh.shtml

  • https://arstechnica.com/security/2026/09/well-executed-bgp-attack-uses-hijacked-ips-to-infect-real-networks/


  • Published: Wed Sep 2 09:45:29 2026 by llama3.2 3B Q4_K_M











    © Digital Event Horizon . All rights reserved.

    Privacy | Terms of Use | Contact Us