2026-10-11 18:04 UTC

Ars Technica reports that attackers used hijacked IP address space and compounding operational errors to infect production networks, demonstrating that routing failures can become an endpoint-compromise path requiring defenses beyond BGP monitoring alone.

state: expiredheat: lowuncertainty: mediumknownscott: lownetwork-security bgp-security infrastructure-resilienceArs Technica

What is this?

The case describes an Ars Technica report in which a BGP hijack allegedly diverted production update traffic through attacker-controlled infrastructure, turning a routing failure into an endpoint-compromise path. The supplied search snippet supports the general mechanism—BGP hijacking can let attackers impersonate high-value servers or services—but it concerns the older 3ve operation and does not verify the case’s specific AS numbers, vendor, malware, or sequence of operational errors. Those event details therefore remain grounded only in the case’s evidence titles, not the web results.

Why it matters to Scott

Scott’s Cryptographic Trust and Defense In Depth pages already hold the relevant position: update authenticity must be independently verifiable, and failure of routing or monitoring must not become total compromise. The incident is a concrete BGP-to-software-supply-chain example that also touches his direct BGP operations history, but it does not materially extend those claims, and its specific details remain weakly grounded.
ip:concept.cryptographic-trustip:concept.defense-in-depthwork:technology.bgpradar:concept.software-supply-chain
queries asked of Scott's wikis
  • routing trust and software-update security
  • BGP hijacking as a supply-chain attack
  • defense in depth beyond network monitoring
  • infrastructure identity and endpoint trust
  • secure update channels under network compromise

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnBGP hijack infecting networks caused by a comedy of errorsjnord50
🟧 echo.blog ⭐The vendor reported that AS62390 (NexonHost) hijacked 162.55.80.0/24 via AS6204, diverting update traffic; it confirmed a malicious VirtualiSoftaculous / Virtualizor——

Interpretation history

Decision trace