LIVE · cybersecurity feed
Live wire
security

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the Euro

zeroday.news · 68d ago

Authorities in the Netherlands have arrested two individuals suspected of facilitating Russian cyberattacks and disinformation campaigns by providing essential IT infrastructure. The arrests, which occurred on May 18, are linked to the operations of hosting companies that allegedly supported entities sanctioned by the European Union for engaging in malicious cyber activities.

The Dutch financial crime agency, FIOD, apprehended a 57-year-old man from Amsterdam and a 39-year-old man from The Hague. They are charged with violating sanctions law by making economic resources available to sanctioned entities. The investigation centers on Stark Industries Solutions, a hosting provider that emerged shortly before Russia's invasion of Ukraine and has been identified as a significant source of distributed denial-of-service (DDoS) attacks against European targets. Stark has also been a key supplier of proxy and anonymity services used by Russian-backed hacking groups.

Previously, the EU sanctioned Moldovan brothers Ivan and Yuri Neculiti and their company PQHosting in May 2025 for their role in supporting Russia's hybrid warfare efforts. PQHosting was one of Stark Industries' primary conduits to the internet. However, Stark maintained another connection through a Dutch Internet service provider named MIRhosting, operated by Andrey Nesterenko, a Russian national residing in the Netherlands.

Following the sanctions against PQHosting, Stark Industries' network assets were reportedly transferred to a new entity, the[.]hosting, under the control of the Dutch company WorkTitans BV. Investigations indicated that WorkTitans was controlled by Nesterenko and Youssef Zinad, a 57-year-old Dutch resident. Notably, WorkTitans relied solely on MIRhosting for its internet connectivity, and Zinad had a prior work history with MIRhosting.

During the May 18 operation, Dutch investigators seized laptops, telephones, and over 800 servers belonging to the targeted businesses. A message sent to customers of the[.]hosting informed them that data stored on the seized servers had been lost and could not be recovered.

Reports suggest that WorkTitans and MIRhosting were extensively used in pro-Russian cyberattacks targeting Danish government bodies during the week of Denmark's municipal elections in November 2025. Prior to his arrest, Nesterenko reportedly denied knowledge of his servers being misused by pro-Russian cybercriminals, stating he had ceased services with the Neculiti brothers upon the imposition of EU sanctions. MIRhosting issued a statement indicating it had initiated an internal investigation and temporarily paused services to WorkTitans as a precautionary measure, asserting that preliminary findings showed no indication of their services being used to influence the Danish elections.

Andrey Nesterenko, who founded MIRhosting's parent company, Innovation IT Solutions Corp., has a history linked to hosting a hacktivist website used to organize cyberattacks against Georgia during the 2008 conflict. Nesterenko stated that MIRhosting does not support cybercrime or illegal activities and that the arrest has been detrimental to him and his company, asserting that the transfer to the.hosting was not an attempt to evade sanctions.

Information regarding Youssef Zinad is less public. He reportedly maintained a low profile, with limited online presence and a lack of response to communications. While Nesterenko described Zinad as a business associate providing services to MIRhosting, previous communications indicated Zinad was part of the company's legal team. Official records list Zinad as a contact for MIRhosting's offices in Almere. Zinad has not responded to requests for comment.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.