惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
V
Visual Studio Blog
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
B
Blog
I
InfoQ
博客园 - 三生石上(FineUI控件)
阮一峰的网络日志
阮一峰的网络日志
F
Fortinet All Blogs
H
Help Net Security
博客园 - Franky
宝玉的分享
宝玉的分享
博客园 - 司徒正美
C
Check Point Blog
G
Google Developers Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Jina AI
Jina AI
T
The Blog of Author Tim Ferriss
MongoDB | Blog
MongoDB | Blog
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner
Dutch authorities dismantle hosting network allegedly use...
Pierluigi Paganini · 2026-05-25 · via Security Affairs

Dutch authorities arrested two suspects and seized 800 servers tied to Stark Industries, a hosting firm linked to cyberattacks and disinformation.

Dutch financial crime investigators arrested two men and seized 800 servers connected to Stark Industries, a hosting provider accused of enabling cyberattacks, interference operations, and disinformation campaigns.

Authorities said the suspects supported Russian and Belarusian entities under EU sanctions. Investigators launched the probe into the company, founded shortly before Russia invaded Ukraine. Authorities searched three business premises in Enschede and Almere, along with two data centers in Dronten and Schiphol-Rijk, seizing administrative records, laptops, phones, and more than 800 servers.

“The criminal investigation focuses on a web hosting company that was established on February 10, 2022, two weeks before the Russian invasion of Ukraine.” reads the press release published by Dutch FIOD. “In the years that followed, this company was used, among other things, to facilitate destabilizing activities directed against the European Union, including interference, cyberattacks, and the dissemination of disinformation.”

Dutch investigators said a web hosting company established on February 10, 2022, acted as a front for sanctioned hosting provider Stark Industries. After the EU sanctioned Stark Industries in May 2025, operators reportedly moved much of its infrastructure to a Dutch company controlled by a 57-year-old suspect. A second Dutch firm allegedly helped keep the servers connected to the internet.

“The FIOD tracks down individuals and entities attempting to circumvent these sanctions or failing to comply with them.” continues the press release. “According to the investigation team, the web hosting company provided support to actions by the Russian Federation that undermine democracy and security, including through information manipulation and disruption of public and economic systems.”

A report by De Volkskrant identifies the Dutch company WorkTitans B.V.

“A confidential technical overview, seen by de Volkskrant and Denmark’s public broadcaster DR, shows the networks most used in pro-Russian attacks on Danish government bodies.” states De Volkskrant. “Between 13 and 19 November 2025 this was the infrastructure of two companies: the Enschede-based WorkTitans, owned by organizational consultant Youssef Z., and Mirhosting of Almere, owned by concert pianist Andrey N.”

Stark was founded just before Russia’s 2022 invasion of Ukraine by Moldovan Ivan Neculiti from Transnistria, with his brother Iurie involved as director. Investigations by Correctiv and a 2024 intelligence report allege links between the brothers, their companies, and Russian intelligence, with Iurie described as a key link. They deny working for any security services and call the claims defamation.

Analysts say Stark’s infrastructure carried large volumes of pro-Russian cyberattack traffic, including NoName057(16) activity, and functioned as a proxy network obscuring attack origins. Mirhosting in the Netherlands allegedly helped route this traffic via EU infrastructure. EU sanctions in 2025 targeted Stark and the Neculiti brothers for facilitating Russian cyber operations.

“Nine days after the EU sanctions, one of Neculiti’s three internet companies, PQ Hosting, officially changed its name to THE.Hosting, the same name under which the Enschede-based WorkTitans operates its hosting activities. THE.Hosting was registered by a Russian network operator on behalf of the Neculiti brothers.” conlcudes the De Volkskrant.

“In addition, de Volkskrant found that specific IP addresses used by the hacker group NoName057(16) for attacks on European targets, including at least one Danish municipal website, were transferred from Stark to WorkTitans.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, disinformation)