BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

Hackers successfully executed a BGP hijacking attack against hosting provider Hetzner Online to distribute malware through Softaculous software updates. The attack succeeded due to lax routing security and a failure to implement code signing for software updates.
Why it matters
This incident demonstrates the critical vulnerability of supply chain software distribution when basic security protocols like code signing and routing validation are ignored.
HACKING INTERNET ROUTING BGP hijack infecting networks caused by a comedy of errors that’s not funny at all What can we learn from a BGP hijacking that poisoned production software? Plenty.
8 Credit: Getty Images Credit: Getty Images Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Hackers carried out a supply chain attack that installed malware on networks using an unusual technique: hijacking a chunk of Internet space where cloud management software used by hosting providers, data centers, and other large infrastructure companies is updated.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in