Attackers hijacked update servers for 33 hours.

Any server that trusted the update channel for Virtualizor could have received malware instead.

Internet routing runs on assertion, not authentication, so announcing someone else’s address space is simply a claim a network can make.

Hetzner and Softaculous cannot yet produce a definitive list of affected servers.

How each outlet framed it
Ars Technica
details BGP hijacking of Softaculous via Hetzner's lax routing security and TLS certificate validation lapses

Sources: Ars Technica