ThreatPaper
Unverified

The Virtualizor compromise affected only a handful of servers

Assessment

The characterisation originates with Softaculous, which stated the incident "affected a handful of servers rather than the general Virtualizor user base," and was carried into reporting from there. It may prove correct. It is not currently supportable, and the same advisory explains why. Because the malicious responses were served by the attacker's system and never reached Softaculous's own logs, the company states it "cannot produce a definitive list" of affected installations. A vendor that cannot enumerate which installations received a package is not in a position to bound how many did. The vendor's own guidance points the other way. Every Virtualizor operator is told to treat their server as in scope for checks, to run the new Security Analyzer, to rotate API credentials and to audit for unauthorised SSH keys and accounts. That is instruction appropriate to unknown exposure, not to a handful of known cases. Community reports from hosting operators describe finding multiple compromised hypervisors within a single fleet. Rated Unverified rather than False because no evidence contradicts the estimate — the point is that no evidence supports it either, and a reassuring number repeated from a vendor that has said it cannot count is the kind of figure that hardens into fact before anyone checks.

Where this claim appeared

BleepingComputer · 2026-09-01

https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

Virtualizor Supply Chain Compromise: 33 Hours of Hijacked Routes and Unsigned Updates

Think this assessment is wrong? Report an error.