BulletProof Hosting Lives on: Stark's Rebrand and 4 Cyber Flashpoints episode artwork

EPISODE · Sep 15, 2025 · 24 MIN

BulletProof Hosting Lives on: Stark's Rebrand and 4 Cyber Flashpoints

from You've Already Been Hacked · host Professor CyberRisk

**Hosts:** - Professor CyberRisk - Cyber Cowboy **Live Cyber Maps & Resources** - Bitdefender Threat Map: https://threatmap.bitdefender.com/ - Checkpoint Live Cyber Threat Map: https://threatmap.checkpoint.com/ - Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ - Talos Intelligence – ebc_spam Map: https://talosintelligence.com/ebc_spam ---## Episode Information **Title:** Bulletproof Hosting Lives On: Stark’s Rebrand & 4 Cyber Flashpoints**Episode Number:** 3x23---### Overview In this episode we unpack the latest headline: European sanctions hit Stark Industries Solutions Ltd., yet the firm slipped into a new shell, keeping its “bullet‑proof” hosting services running. We dive into why that matters for defenders, and we explore four additional headlines: a supply‑chain attack on npm libraries, the fallout from Salesloft’s token breach, Microsoft’s critical Patch Tuesday, and a new Russian gambling‑scam network. Get the details on how to spot, block, and remediate each threat.---### Guest Information *None for this episode (solid 5‑story deep dive).*---### Topics Covered- How “bullet‑proof” hosting evades EU sanctions - 18 npm packages hijacked to steal crypto funds - Salesloft token breach exposes corporate data across Slack, Google Workspace & AWS - Microsoft Patch Tuesday – 80+ fixes (incl. remote code exec, SMB flaws) - Russian “Soulless” gambling‑scam affiliate network---## Top Stories **1. Bulletproof Host Stark Industries Evades EU Sanctions** *Summary:* The EU slapped sanctions on Stark Industries Solutions Ltd. in May 2025 for fueling Kremlin‑linked DDoS, malware, and disinformation campaigns. New research shows Stark swiftly rebranded to “thehosting”, moved assets to a Dutch shell (WorkTitans BV), and shifted IP space to a new Moldovan entity, PQ Hosting Plus SRL. The core infrastructure—IP ranges, servers and the notorious MIRhosting partner—remained operational, allowing Russian‑backed attacks to continue almost unchanged. *Why it Matters:* This is a textbook example of how “bullet‑proof” hosting providers dodge regulation by shifting names and ownership while keeping the same malicious traffic lanes open. It shows that sanctions alone are insufficient; attackers simply reorganize and keep the same services running, continuing to supply state‑level cyberwarfare. *What you should do:* Monitor the domain and IP space associated with Stark and its partners (thehosting.com, PQ Hosting Plus SRL, MIRhosting). Use threat‑intel feeds to detect changes in ownership or DNS records. Block traffic from these IP ranges at your perimeter firewalls, especially if you run a web‑services or cloud platform. Keep an eye on EU sanctions lists and immediately flag any new entities that appear in your infrastructure logs. ---## Additional Cybersecurity News – Titles & URLs | # | Title | URL ||---|-------|-----|| 2 | *18 Popular Code Packages Hacked, Rigged to Steal Crypto* | 3 | *The Ongoing Fallout from a Breach at AI Chatbot Maker Salesloft* | 4 | *Microsoft Patch Tuesday, September 2025 Edition* | | 5 | *Affiliates Flock to ‘Soulless’ Scam Gambling Machine* |---### Resources & Links *None this episode.*---## Call to Action- **Subscribe** – Stay updated on the latest cybersecurity threats. - **Leave a Review** – Let us know what you think. - **Join the Conversation** – Follow our community and ask questions.---### Sponsor *No sponsors this episode.*---## Podcast Socials & Website - **Website:** https://www.youvealreadybeenhacked.com - **X (Twitter):** @professorcyberrisk - **YouTube:** https://www.youtube.com/@YABHPodcast - **Discord/Community Forum:** https://discord.gg/cz3xdsrqAE

**Hosts:** - Professor CyberRisk - Cyber Cowboy **Live Cyber Maps & Resources** - Bitdefender Threat Map: https://threatmap.bitdefender.com/ - Checkpoint Live Cyber Threat Map: https://threatmap.checkpoint.com/ - Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ - Talos Intelligence – ebc_spam Map: https://talosintelligence.com/ebc_spam ---## Episode Information **Title:** Bulletproof Hosting Lives On: Stark’s Rebrand & 4 Cyber Flashpoints**Episode Number:** 3x23---### Overview In this episode we unpack the latest headline: European sanctions hit Stark Industries Solutions Ltd., yet the firm slipped into a new shell, keeping its “bullet‑proof” hosting services running. We dive into why that matters for defenders, and we explore four additional headlines: a supply‑chain attack on npm libraries, the fallout from Salesloft’s token breach, Microsoft’s critical Patch Tuesday, and a new Russian gambling‑scam network. Get the details on how to spot, block, and remediate each threat.---### Guest Information *None for this episode (solid 5‑story deep dive).*---### Topics Covered- How “bullet‑proof” hosting evades EU sanctions - 18 npm packages hijacked to steal crypto funds - Salesloft token breach exposes corporate data across Slack, Google Workspace & AWS - Microsoft Patch Tuesday – 80+ fixes (incl. remote code exec, SMB flaws) - Russian “Soulless” gambling‑scam affiliate network---## Top Stories **1. Bulletproof Host Stark Industries Evades EU Sanctions** *Summary:* The EU slapped sanctions on Stark Industries Solutions Ltd. in May 2025 for fueling Kremlin‑linked DDoS, malware, and disinformation campaigns. New research shows Stark swiftly rebranded to “thehosting”, moved assets to a Dutch shell (WorkTitans BV), and shifted IP space to a new Moldovan entity, PQ Hosting Plus SRL. The core infrastructure—IP ranges, servers and the notorious MIRhosting partner—remained operational, allowing Russian‑backed attacks to continue almost unchanged. *Why it Matters:* This is a textbook example of how “bullet‑proof” hosting providers dodge regulation by shifting names and ownership while keeping the same malicious traffic lanes open. It shows that sanctions alone are insufficient; attackers simply reorganize and keep the same services running, continuing to supply state‑level cyberwarfare. *What you should do:* Monitor the domain and IP space associated with Stark and its partners (thehosting.com, PQ Hosting Plus SRL, MIRhosting). Use threat‑intel feeds to detect changes in ownership or DNS records. Block traffic from these IP ranges at your perimeter firewalls, especially if you run a web‑services or cloud platform. Keep an eye on EU sanctions lists and immediately flag any new entities that appear in your infrastructure logs. ---## Additional Cybersecurity News – Titles & URLs | # | Title | URL ||---|-------|-----|| 2 | *18 Popular Code Packages Hacked, Rigged to Steal Crypto* | 3 | *The Ongoing Fallout from a Breach at AI Chatbot Maker Salesloft* | 4 | *Microsoft Patch Tuesday, September 2025 Edition* | | 5 | *Affiliates Flock to ‘Soulless’ Scam Gambling Machine* |---### Resources & Links *None this episode.*---## Call to Action- **Subscribe** – Stay updated on the latest cybersecurity threats. - **Leave a Review** – Let us know what you think. - **Join the Conversation** – Follow our community and ask questions.---### Sponsor *No sponsors this episode.*---## Podcast Socials & Website - **Website:** https://www.youvealreadybeenhacked.com - **X (Twitter):** @professorcyberrisk - **YouTube:** https://www.youtube.com/@YABHPodcast - **Discord/Community Forum:** https://discord.gg/cz3xdsrqAE

NOW PLAYING

BulletProof Hosting Lives on: Stark's Rebrand and 4 Cyber Flashpoints

0:00 24:25

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Eat to Live Jenna Fuhrman, Dr. Fuhrman Our health is our most precious gift and smart nutrition can change your life. Each month, join Dr. Fuhrman and his daughter, Jenna Fuhrman as they discuss important topics in the world of nutrition. Eat to Live will change the way you eat and think about food. French Your Way Jessica: Native French teacher founder of French Your Way Boost your French listening skills and test your comprehension with this one of a kind series of podcasts. Get the chance to listen to a real conversation between native speakers talking at normal speed AND customise your learning experience through carefully designed sets of questions (2 levels of difficulty) available for download at www.frenchvoicespodcast.com. All interviews also come with the transcript. French teacher Jessica interviews native speakers of French from around the world who share a bit of their life and passion. Where else would you meet in one same place a French yoga teacher based in Melbourne, a soap manufacturer from Provence, or a couple cycling around the world? HOMELAND HOMELAND The Church is a body not a building. It's the bride of Jesus Christ! Jesus is coming back for a mature bride. That means it's time for the church of Jesus Christ to move from milk to meat. This is the hour of maturity!HOMELAND is an announcement that the church is being set free. Only the church has the ability to transform the world. The kingdom's of this world will become the kingdoms of our Lord and Savior!All of creation has been waiting for this moment! Sons and daughters of God are rising up and taking their seat! DIOSA. Carolina Sanper This podcast is a sacred space created by Carolina Sanper where you connect with your inner wisdom and embody your magnetic feminine power.It is the realization that the mystical realm is where you plant the seeds of your desired reality.It is a portal to your true essence: awareness, presence, and receiving with ease. Welcome home, DIOSA. 🖤

Frequently Asked Questions

How long is this episode of You've Already Been Hacked?

This episode is 24 minutes long.

When was this You've Already Been Hacked episode published?

This episode was published on September 15, 2025.

What is this episode about?

**Hosts:** - Professor CyberRisk - Cyber Cowboy **Live Cyber Maps & Resources** - Bitdefender Threat Map: https://threatmap.bitdefender.com/ - Checkpoint Live Cyber Threat Map: https://threatmap.checkpoint.com/ - Kaspersky Cyber Threat Map:...

Can I download this You've Already Been Hacked episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!