A threat actor pushed malicious Virtualizor updates in a BGP hijack attack, directing users to attacker-controlled servers.