Let’s talk malformed AS_PATHs. Unless you’re enforcing the “First AS” of received routes, you’re vulnerable to hijacks that not even ASPA validation can prevent.
Read more here, and enforce the First AS in BGP.
https://blog.cloudflare.com/enforce-first-as-bgp/

