Feeds.Feedburner U.S. Army Websites Defaced in Pro-Kurdish Hacktivist Attack
Article Content
- •Two U.S. Army websites were defaced with pro-Kurdish messages and insults to Trump.
- •The attack utilized a 404 hijacking method, exploiting vulnerabilities in WordPress plugins.
- •The Army has removed the affected pages and is currently investigating the incident.
On July 6, 2026, multiple U.S. Army subdomains, including oil.army.mil and ai2c.army.mil, were defaced in a 404 hijacking campaign. The attack displayed messages denouncing President Donald Trump and supporting Kurdish independence. Cybersecurity researcher Ronald Lovelace discovered the defacement, which exploited vulnerabilities in the websites' error-handling systems, likely due to compromised WordPress plugins. The Army's affected sites belong to the Open Innovation Lab and the AI Integration Center. Following the incident, the Army took the pages offline and initiated an investigation. The attack raises concerns about the security of government websites and the potential for broader vulnerabilities. As of now, it remains unclear how the hackers gained access to modify the error pages. No data breach has been confirmed, and the investigation is ongoing.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Syrian Electronic Army and AI Integration Center in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…