TGViewer
Host Testing and evaluation Host Testing and evaluation @hostevaluate · 2.2K subscribers
Post #911 970

Forwarded from Low End Web Deals

⚡️ Virtualizor Support System Breach: Technical Details

Virtualizor has released the technical details regarding the recent wave of attacks on Cloudcone, HostSlick, and others. The breach was not a direct software exploit, but a session hijacking attack on their support ticket system.

Attackers gained access to approximately 1,500 tickets where providers had carelessly sent plain-text root credentials via email instead of using secure forms.

The compromised providers were vulnerable because they failed to rotate these passwords after support cases were resolved - some credentials were over a year old - and did not have IP whitelisting enabled for their Admin Panels or SSH.

Virtualizor is urging all admins to immediately rotate any root passwords previously shared in tickets and to restrict Admin Panel access to trusted IPs only.

Source: Hosteroid on LET
More from @hostevaluate
  1. May 1, 2026#synexvm #HK Host Provider: SynexVM Location: HongKong Specification: 4vCore (Xeon Platinu…
  2. Apr 6, 2026#skystroll #jp #hnd Host Provider: SkyStroll Location: Tokyo, Japan Specification: Intel X…
  3. Feb 12, 2026#GTHost #fr #cdg Host Provider: GTHost (PAR-VPS-4) Location: Paris, France Specification:…
  4. Feb 11, 2026#easyheberg #fr #cdg Host Provider: EasyHeberg (KVM) Location: Paris, France Specification…
  5. Jan 30, 2026#EthernetServers #FRA #DE Host Provider: EthernetServers Location: Frankfurt am Main, Germ…
  6. Jan 29, 2026#ISIF #KR #ICN Host Provider: ISIF Cloud (KR.GMP-B.2C4G-COM) Location: Seoul, South Korea…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →