Supply Chain Attacks

Tampering with the models, packages and tools a system is built from.

Korpalis selects material that helps builders and business teams understand what changed, why it matters and what to check next. Every entry below includes an original explanation and a direct link to its publisher.

Supply Chain AttacksAdvanced

Malicious Virtualizor Update Served via BGP Hijacking

A threat actor used BGP hijacking to redirect traffic intended for Softaculous' legitimate domains, serving malicious updates to virtualization hosting software by spoofing valid TLS certificates. The attack demonstrates how network-layer interception can compromise update mechanisms at scale.