Reading view

There are new articles available, click to refresh the page.

Spain arrests suspected hacker linked to Russian hacktivist campaign

Authorities arrested an alleged member of Cyber Army of Russia Reborn, a pro-Russian hacktivist group accused of committing multiple attacks against critical infrastructure providers in the United States and Europe. 

Spain’s national police announced the arrest Monday but said it occurred back in March. Officials did not name the man who was detained at his home in Palencia following an investigation triggered by a tip from the FBI in August 2025.

FBI agents in the Los Angeles field office coordinated with Spanish officials to capture the alleged cybercriminal, the agency’s cyber division said in a LinkedIn post Monday. The FBI said the arrest was part of Operation Riptide, an ongoing global campaign targeting cybercriminals and the infrastructure and financial networks they use to commit fraud.

“Together, we will continue to impose costs on cybercriminals wherever they operate,” the FBI said.

Spanish officials said the arrested man provided logistical support to a Ukrainian hacker linked to Cyber Army of Russia Reborn, also known as Z-Pentest, facilitating the Ukrainian’s escape to Russia via Poland and Belarus. 

The arrested man also “participated in actions attributed to the pro-Russian hacktivist group NoName057(16), whose operations were later claimed in specialized portals related to geopolitics, with the aim of spreading pro-Russian and anti-Western narratives,” Spanish authorities said.

Police investigators searched the suspect’s home and seized computers and cryptocurrency storage devices, later freezing a cryptocurrency wallet he allegedly used to receive payment for his alleged crimes. 

Officials said the nearly year-long investigation recently concluded but did not announce specific charges, other than accusing him of collaborating with a terrorist organization, glorifying terrorism and damaging computers.

Authorities have been targeting Cyber Army of Russia Reborn and its alleged members for years. The Russian state-sponsored group has been active since 2022, officials said. 

The Treasury Department sanctioned the pro-Russian hacktivist group’s alleged leader and primary hacker, Yuliya Vladimirovna Pankratova and Denis Olegovich Degtyarenko, in July 2024.

In December 2025, the Justice Department indicted Ukrainian national Victoria Eduardovna Dubranova, accusing her of participating in attacks against critical infrastructure and other victims in support of Russia’s geopolitical interests as part of Cyber Army of Russia Reborn and NoName057(16). Dubranova was extradited to the United States last year and pleaded guilty in two federal cases brought against her. 

The State Department since late 2025 has been offering potential rewards for up to $2 million for information on individuals associated with Cyber Army of Russia Reborn and up to $10 million for information on individuals associated with NoName. NoName057(16), also known as NoName, was established by Russian President Vladimir Putin in October 2018, according to the Justice Department.

Multiple federal agencies and international partners issued a joint cybersecurity advisory in December 2025 about threats posed by pro-Russian hacktivist groups, including Cyber Army of Russia Reborn and NoName.

The post Spain arrests suspected hacker linked to Russian hacktivist campaign appeared first on CyberScoop.

US Army websites defaced with pro-Kurdish sentiments, insults to Trump

Multiple U.S. Army internet subdomains were defaced in a 404 hijacking campaign, CyberScoop has confirmed.

As of Monday morning, error pages on two U.S. Army websites – oil.army.mil and ai2c.army.mil – displayed defacement messages visible to users. The messages denigrated President Donald Trump and United States Ambassador to Türkiye Tom Barrack, called to “FREE KURDISTAN,”  And included another line reading “Kurdish sr was here.”

One of the websites, oil.army.mil, belongs to the Army’s Open Innovation Lab, a test bed for software and cyber capabilities established in 2020. The other belongs to the Artificial Intelligence Integration Center, established in 2019 to integrate AI technologies into the Army and train personnel on emerging technologies.

Screenshot of 404 error pages for oil.army.mil, defaced with pro-Kurdistan comments and insults to President Donald Trump and White House advisor Tom Barrack. (Source: U.S. Army website)
Screenshot of 404 error pages for ai2c.army.mil, defaced with insults to President Donald Trump and White House advisor Tom Barrack and a sign off from “Kurdish sr.” (Source: U.S. Army website)

The defacements were initially discovered by independent cybersecurity researcher Ronald Lovelace, who notified U.S. Army officials and CyberScoop.

404 hijacking exploits a website’s error-handling system — often by compromising a plugin, content management system, or server configuration — to control what content gets displayed when a page isn’t found, rather than breaching the site’s core pages directly. This lets malicious users insert defacement messages, malicious redirects, or other unauthorized content that visitors see specifically on error pages, sometimes making the compromise harder to detect since the rest of the site appears untouched.

Lovelace said the affected sites run on WordPress and Microsoft cloud infrastructure. It’s not clear how long the subdomains have been compromised or whether other subdomains are affected. 

“It raises the severity a decent amount because it shows it’s a bit deeper than just one single path” that’s being corrupted, Lovelace said.

However, while the defacement’s presence across multiple subdomains suggests the potential for “broad reach,” it doesn’t appear to affect all Army websites, with many  still showing normal 404 error pages.

Also unclear at this time is how the hackers gained the ability to edit error pages for those websites, whether the breach originated internally if it was due to an internal or through a third party breach, and whether the intrusion extends beyond limited website defacement.

The websites were taken offline after CyberScoop reached out to the Army for comment. An Army spokesperson told CyberScoop that the pages were hosted on a legacy third-party platform that is not connected to the Army’s enterprise network and have since been removed.

The spokesperson said incident response by Army cyber investigators remains ongoing, and that it’s too early to say whether the third-party platform will be patched or discontinued. 

“We are aware of unauthorized defacements on the error pages of oil.army.mil and ai2c.army.mil, which are hosted on a legacy, non-authoritative platform,” said Army spokesperson Maj. Sean Minton in a statement. “Technical teams took immediate action to mitigate the issue, and the affected pages have been secured. The Army takes all cyber incidents seriously and is actively investigating this matter to enforce our strict cyber defense and network security standards.”

It’s not clear who is behind the defacement beyond  the references to Kurdistan— a geographic region spanning parts of  Turkey, Iraq, Iran and Syria that is home to more than 30 million Kurdish people. The Kurdish separatist movement has fought for decades to establish an independent nation, and defacing government websites has long been a popular tactic among Kurdish hacktivists.

Trump and Barrack drew the ire of Kurdish proponents earlier this year for seeming to back a Syrian government military campaign to reestablish federal control over Kurdish-majority lands.

It’s not the first time that Army websites have been seemingly compromised by foreign hackers. In 2015, Army officials had to temporarily shut down major websites, including the Army main home page and the Department of Defense’s U.S. Strategic Command, after hackers from the Syrian Electronic Army defaced them.

The post US Army websites defaced with pro-Kurdish sentiments, insults to Trump appeared first on CyberScoop.

❌