惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
Recent Announcements
Recent Announcements
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
MyScale Blog
MyScale Blog
人人都是产品经理
人人都是产品经理
aimingoo的专栏
aimingoo的专栏
U
Unit 42
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
T
Tailwind CSS Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 三生石上(FineUI控件)
Apple Machine Learning Research
Apple Machine Learning Research
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
腾讯CDC
I
InfoQ
GbyAI
GbyAI
博客园_首页

Security Affairs

Carding service Jerry’s Store leak exposes 345,000 stolen payment cards Anthropic launches Claude Security to counter rapid AI-Powered exploits SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now Copy Fail: New Linux bug enables Root via page‑cache corruption Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog
Dutch authorities dismantle hosting network allegedly use...
Pierluigi Paganini · 2026-05-25 · via Security Affairs

Dutch authorities arrested two suspects and seized 800 servers tied to Stark Industries, a hosting firm linked to cyberattacks and disinformation.

Dutch financial crime investigators arrested two men and seized 800 servers connected to Stark Industries, a hosting provider accused of enabling cyberattacks, interference operations, and disinformation campaigns.

Authorities said the suspects supported Russian and Belarusian entities under EU sanctions. Investigators launched the probe into the company, founded shortly before Russia invaded Ukraine. Authorities searched three business premises in Enschede and Almere, along with two data centers in Dronten and Schiphol-Rijk, seizing administrative records, laptops, phones, and more than 800 servers.

“The criminal investigation focuses on a web hosting company that was established on February 10, 2022, two weeks before the Russian invasion of Ukraine.” reads the press release published by Dutch FIOD. “In the years that followed, this company was used, among other things, to facilitate destabilizing activities directed against the European Union, including interference, cyberattacks, and the dissemination of disinformation.”

Dutch investigators said a web hosting company established on February 10, 2022, acted as a front for sanctioned hosting provider Stark Industries. After the EU sanctioned Stark Industries in May 2025, operators reportedly moved much of its infrastructure to a Dutch company controlled by a 57-year-old suspect. A second Dutch firm allegedly helped keep the servers connected to the internet.

“The FIOD tracks down individuals and entities attempting to circumvent these sanctions or failing to comply with them.” continues the press release. “According to the investigation team, the web hosting company provided support to actions by the Russian Federation that undermine democracy and security, including through information manipulation and disruption of public and economic systems.”

A report by De Volkskrant identifies the Dutch company WorkTitans B.V.

“A confidential technical overview, seen by de Volkskrant and Denmark’s public broadcaster DR, shows the networks most used in pro-Russian attacks on Danish government bodies.” states De Volkskrant. “Between 13 and 19 November 2025 this was the infrastructure of two companies: the Enschede-based WorkTitans, owned by organizational consultant Youssef Z., and Mirhosting of Almere, owned by concert pianist Andrey N.”

Stark was founded just before Russia’s 2022 invasion of Ukraine by Moldovan Ivan Neculiti from Transnistria, with his brother Iurie involved as director. Investigations by Correctiv and a 2024 intelligence report allege links between the brothers, their companies, and Russian intelligence, with Iurie described as a key link. They deny working for any security services and call the claims defamation.

Analysts say Stark’s infrastructure carried large volumes of pro-Russian cyberattack traffic, including NoName057(16) activity, and functioned as a proxy network obscuring attack origins. Mirhosting in the Netherlands allegedly helped route this traffic via EU infrastructure. EU sanctions in 2025 targeted Stark and the Neculiti brothers for facilitating Russian cyber operations.

“Nine days after the EU sanctions, one of Neculiti’s three internet companies, PQ Hosting, officially changed its name to THE.Hosting, the same name under which the Enschede-based WorkTitans operates its hosting activities. THE.Hosting was registered by a Russian network operator on behalf of the Neculiti brothers.” conlcudes the De Volkskrant.

“In addition, de Volkskrant found that specific IP addresses used by the hacker group NoName057(16) for attacks on European targets, including at least one Danish municipal website, were transferred from Stark to WorkTitans.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, disinformation)