HostingerSaulius Lazaravičius2 min readpostmortemintermediate
September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack
Summary
Hostinger detected a zero‑day exploit in LiteSpeed Web Server on a Brazil server on Sep 16 2026, giving the attacker root access and compromising 399 accounts. The team isolated the server, coordinated with LiteSpeed to patch the vulnerability, rolled out the fix fleet‑wide, and restored affected sites from backups within the same day.
- Monitoring flagged the anomaly within minutes, enabling rapid incident identification.
- The LiteSpeed <6.3.7 Build 2 zero‑day allowed privilege escalation past CloudLinux CageFS isolation.
- Containment steps included blocking external access, suspending attacker accounts, removing malicious cron jobs, and preserving forensic evidence.
- A vendor‑coordinated patch (6.3.7 Build 2) was deployed across all shared‑hosting servers the same day.
Ops and security engineers can learn a concrete, end‑to‑end response to a supply‑chain zero‑day in a shared‑hosting environment.
6/10




