A valid TLS certificate didn't save Virtualizor from a BGP hijack
The attacker's certificate for Virtualizor's domains was real, correctly chained, and issued by Let's Encrypt. That's the actual story: certificate validity checks the cert, not the network path serving it.