LxLabs boss found hanged after vuln wipes websites
Shocking development in VAserv megahack affair
The boss of Indian software firm LxLabs was found dead in a suspected suicide on Monday.
Reports of the death of K T Ligesh, 32, come in the wake of the exploitation of a critical vulnerability in HyperVM, a virtualization application made by LXLabs, to wipe out data on 100,000 sites hosted by the UK web hosting firm VAserv.
The effect of his death on the development of updated software by LxLabs is unknown at time of writing.
Ligesh was found hanged in his Bangalore house on Monday morning, after a late night drinking session. The Times of India reports that he was upset with the loss of a recent contract. Ligesh was also still coming to terms with the suicides by hanging of his sister and mother five years ago.
Security researchers at Milw0rm warn that the Kloxo (formerly Lxadmin) web hosting platform from LxLabs contains 24 security vulnerabilities and exploits. The flaws include SQL injection vulnerabilities and flaws that create a way for hackers to gain file access to files hosted on a vulnerable system.
The vulnerabilities are confirmed to affect Klaxo version 5.75, though other versions may also be affected. Milw0rm went public with an alert on the vulnerability last Thursday after failing to hear back from LxLabs in what it considered to be a timely manner.
LxLabs recently said that more than 30,000 virtualized private servers (vpses) were managed by HyperVM, and more than 8,000 servers running Kloxo. The largest single installation of hyperVM centrally manages more than 4000 VPSes.
Virtualization features of HyperVM allow hosting firms such as VAserv to provide low-cost web hosting at a fraction of the price of dedicated server hosting. ®
- Black Hat
- Cisco ACE
- Common Vulnerability Scoring System
- Cybersecurity and Infrastructure Security Agency
- Cybersecurity Information Sharing Act
- Data Breach
- Data Protection
- Data Theft
- Digital certificate
- End-user computing
- Identity Theft
- Kenna Security
- Palo Alto Networks
- Trusted Platform Module
- Virtual machine
- Zero Day Initiative
- Zero trust