proomt

Search

Search posts, papers, and topics

All posts

HostingerSaulius Lazaravičius2 min readpostmortemintermediate

September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack

Summary

Hostinger detected a zero‑day exploit in LiteSpeed Web Server on a Brazil server on Sep 16 2026, giving the attacker root access and compromising 399 accounts. The team isolated the server, coordinated with LiteSpeed to patch the vulnerability, rolled out the fix fleet‑wide, and restored affected sites from backups within the same day.

  • Monitoring flagged the anomaly within minutes, enabling rapid incident identification.
  • The LiteSpeed <6.3.7 Build 2 zero‑day allowed privilege escalation past CloudLinux CageFS isolation.
  • Containment steps included blocking external access, suspending attacker accounts, removing malicious cron jobs, and preserving forensic evidence.
  • A vendor‑coordinated patch (6.3.7 Build 2) was deployed across all shared‑hosting servers the same day.

Ops and security engineers can learn a concrete, end‑to‑end response to a supply‑chain zero‑day in a shared‑hosting environment.

6/10

Related reading

  1. Happy BMO Push Day! (20260824.1)

    Mozilla BMO push day (20260824.1) shipped a batch of bug‑fixes and small feature tweaks: 2FA user docs, corrected file‑size error, phab‑bot review flag handling, UI button for external attachments, Docker build update for vendored JS, removal of CSP header from REST API, richer comment edit metadata, migration of Classification endpoint to native Mojo, dependency‑upgrade tracking, an index on tra…

    Mozilla Automation Teammozilla.org1 minrelease
  2. High-speed Release Trains – These Weeks in Firefox: Issue 209

    Firefox 155 shipped via a new 2‑week release train; the week’s highlights include a WebExtensions theme API addition, multi‑context address bar in Nightly, DevTools stylesheet editing in the JS debugger, and extensive New Tab page UI/telemetry work (stocks widget, privacy widget, policy‑locked settings). The post also calls out many volunteer contributors and a handful of infrastructure tweaks (T…

    Mozilla Automation Teammozilla.org9 min
  3. Twilio’s 2026 Heightened Awareness Period: Ensuring Reliable Messaging for Peak Season

    Twilio will run two Heightened Awareness Periods (Nov 2‑4 2026 for U.S. midterms and Nov 19 2026‑Jan 4 2027 for BFCM/holiday) to shift high‑volume short‑code and toll‑free traffic to market‑throughput mode, keeping messages out of carrier queues. Most users need no action; high‑volume senders should contact their account team and complete supplemental order forms by the listed deadlines to lock i…

    Twiliotwilio.com3 minrelease
  4. Server Monitoring in the age of AI: What static thresholds miss and how adaptive monitoring fixes it?

    Static CPU/memory thresholds generate noise because workloads vary by time‑of‑day, day‑of‑week, and long‑term trends. Adaptive monitoring learns per‑server baselines (using simple ML on historic metrics) and creates dynamic thresholds plus anomaly alerts. ManageEngine OpManager’s Zia engine is presented as a turnkey AIOps solution that auto‑learns baselines, lets you set sensitivity, and adds ale…

    SitePointsitepoint.com6 min