{"id":10138,"date":"2026-09-17T17:19:20","date_gmt":"2026-09-17T17:19:20","guid":{"rendered":"https:\/\/www.hostinger.com\/blog\/?p=10138"},"modified":"2026-09-17T17:22:40","modified_gmt":"2026-09-17T17:22:40","slug":"september-16-2026-incident","status":"publish","type":"post","link":"https:\/\/www.hostinger.com\/blog\/september-16-2026-incident\/","title":{"rendered":"September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack"},"content":{"rendered":"<p class=\"wp-block-paragraph\">On September 16, 2026, we faced a zero-day attack targeting one of our servers in Brazil.<\/p><p class=\"wp-block-paragraph\">Our security team detected an attack exploiting a previously undetected vulnerability in one of our vendors, LiteSpeed Web Server. We worked with LiteSpeed to develop and deploy a fix, and secured our web hosting environment against the vulnerability the same day.<\/p><p class=\"wp-block-paragraph\">This post covers what happened and how we responded.<\/p><p class=\"wp-block-paragraph\"><strong>What happened<\/strong><\/p><p class=\"wp-block-paragraph\">On September 16, at 13:08 UTC, our monitoring systems flagged unusual activity on one of our servers in the Brazil data center. The security team identified an incident within minutes and began investigating.<\/p><p class=\"wp-block-paragraph\">They found a sophisticated, targeted attack that, based on its near-continuous activity and repeated patterns, appeared to be automated and AI-driven.<\/p><p class=\"wp-block-paragraph\">The attacker had exploited a zero-day critical vulnerability in LiteSpeed Web Server (versions before 6.3.7 Build 2), the software we use to serve websites. The vulnerability allowed the attacker to gain root-level access on one server. In this scenario, a low-privileged user on a shared hosting server could bypass expected isolation boundaries, such as those provided by CloudLinux CageFS, and append data to files with elevated, root-level privileges.<\/p><p class=\"wp-block-paragraph\">The attacker deployed a webshell on 399 accounts hosted on the affected server; we detected unauthorized commands on 11 of them. We reached out to all of the potentially affected customers individually.<\/p><p class=\"wp-block-paragraph\"><strong>What we did<\/strong><\/p><p class=\"wp-block-paragraph\">Following the alert, we disabled external access to the affected server, suspended the attacker&rsquo;s accounts, removed malicious scheduled tasks, and preserved evidence for forensic analysis. As a precaution, we also disabled an internal tooling integration after observing attacker activity against it.<\/p><p class=\"wp-block-paragraph\">In parallel, we identified the exact vulnerability and worked directly with LiteSpeed to fix it. By 23:00 UTC on September 16, the patched version (<a href=\"https:\/\/docs.litespeedtech.com\/lsws\/changelog\/#v6-3-7-build-2\" target=\"_blank\" rel=\"noreferrer noopener\">6.3.7 Build 2<\/a>) was deployed across our entire shared hosting fleet.<\/p><p class=\"wp-block-paragraph\">As part of our incident response, we restored affected websites from the most recent backups taken before the attack and migrated them to a new server.<\/p><p class=\"wp-block-paragraph\"><strong>Final notes<\/strong><\/p><p class=\"wp-block-paragraph\">Security is a continuous effort, and we take it very seriously. We acknowledge the changing security landscape with AI-driven attacks and remain committed to protecting our client websites with 24\/7 monitoring, malware scanning, firewall protection, and continuous vulnerability checks to safeguard our supply chain.<\/p><p class=\"wp-block-paragraph\">The number of researchers working with us through our <a href=\"https:\/\/hackerone.com\/hostinger\" target=\"_blank\" rel=\"noreferrer noopener\">bug reward program<\/a> is already growing, and we&rsquo;re increasing rewards for critical zero-day vulnerabilities. We&rsquo;re also setting up a dedicated lab with the latest AI models to simulate real-world attacks.<\/p><p class=\"wp-block-paragraph\">We&rsquo;ll update this post if our ongoing investigation uncovers any new information.<\/p><p class=\"wp-block-paragraph\">If you have questions, please reach out to our support team or email security@hostinger.com.<\/p><p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On September 16, 2026, we faced a zero-day attack targeting one of our servers in Brazil.<\/p>\n<p>Our security team detected an attack exploiting a previously undetected vulnerability \u2026<\/p>\n","protected":false},"author":495,"featured_media":9745,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[82],"tags":[],"hashtags":[],"class_list":["post-10138","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-engineering"],"hreflangs":[],"_links":{"self":[{"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/posts\/10138","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/users\/495"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/comments?post=10138"}],"version-history":[{"count":2,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/posts\/10138\/revisions"}],"predecessor-version":[{"id":10141,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/posts\/10138\/revisions\/10141"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/media\/9745"}],"wp:attachment":[{"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/media?parent=10138"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/categories?post=10138"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/tags?post=10138"},{"taxonomy":"hashtags","embeddable":true,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/hashtags?post=10138"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}