Avanpost SmartPAM Adds 60 MITRE ATT&CK Signatures for Privileged Session Threat Detection
Avanpost has expanded its SmartPAM solution with a new library of 60 signatures aligned to the MITRE ATT&CK matrix. The update, available in version 1.4, enables the Privileged Access Management platform to inspect activities inside privileged sessions instead of limiting itself to access control at the entry point.
The signatures address key stages of attacker behavior after initial compromise, including credential access, persistence mechanisms, lateral movement, and defense evasion techniques. Specific examples include attempts to disable operating system auditing, antivirus software, or firewalls, as well as clearing system logs or obfuscating executed commands.
Session data is processed by an integrated signature analysis engine that normalizes events, correlates them with known attack patterns, and initiates predefined responses. Available actions include blocking individual commands, terminating user sessions, or forwarding alerts to a SIEM platform.
Organizations can extend the supplied rule set with their own custom signatures and tailor detection policies to the specifics of their infrastructure and security requirements. The signature library is distributed via subscription, with free access guaranteed by Avanpost through the end of 2026 and regular updates promised thereafter.
According to the vendor, SmartPAM is the first PAM product to deliver a detection library structured according to the MITRE ATT&CK framework. The enhancement transforms the solution from a simple gateway for privileged accounts into a continuous monitoring system that evaluates every action performed after authentication, addressing the reality that stolen or misused administrator credentials often appear legitimate to basic access controls.
Related articles
Bureau 1440 Unveils Satellite Internet Terminals Reaching 700 Mbps for Industrial and Rail Use
Bureau 1440 presented three satellite terminal models at the Digital Solutions forum in Russia. The 1440 ULTRA model supports data speeds up to 700 Mbps and is designed for remote industrial sites and infrastructure, operating both stationary and in motion. The company reduced the terminal's weight by 30 percent while maintaining 600 by 600 mm dimensions and adding IP67 dust and water protection. The 1440 ZEMLYA variant is already undergoing tests on Russian Railways trains, including Lastochka and Sapsan services, and is rated for operation at speeds up to 400 km/h. A compact 1440 MINI concept aims for around 100 Mbps in a 300 by 300 mm portable form factor intended for rescue teams and expeditions. All models are being developed alongside the company's low-orbit satellite constellation, with test connections already active on rail lines and in remote settlements. Sales have not yet begun, and the company will announce availability separately while noting that maximum speeds are not guaranteed in every environment.
GTA V Unofficial Browser Port Runs Locally via WebAssembly Using Leaked Rockstar Sources
Enthusiasts created an unofficial port of GTA V that executes the game directly in the browser through WebAssembly without any cloud streaming. The project compiled the original RAGE engine to wasm64 and built a compatibility layer translating DirectX 11 calls to WebGPU. Game assets were served over HTTP while JavaScript handled input and saves, and AudioWorklet managed audio. The port retained Euphoria physics and Scaleform interfaces but removed Bink video playback. Requirements ranged from 3 to 16 GB of RAM, supporting both story mode and free roam. The site was taken offline shortly after launch, first displaying a thank-you message and later redirecting to adult content. Analysis of the build confirmed debug symbols and developer file paths consistent with leaked Rockstar source code.
PKI Storm: Managing 100,000 Simultaneous Certificate Requests in Kubernetes Recovery Scenarios
A large organization's PKI infrastructure faced a critical bottleneck when a data center outage triggered simultaneous startup of tens of thousands of Kubernetes pods, each requiring mTLS certificates. The existing setup using ESAUS and Citadel routed all requests through external certificate authorities that could only sustain 50-70 RPS against an incoming burst of 100,000 requests. Average daily load of 10-11 RPS had masked the thundering herd risk during mass recovery. Scaling the CA 15x was rejected due to cost and the fundamental dependency on real-time signing. The team introduced pre-issuance of certificates stored in a dedicated Unified Secret Storage (ЕХС) layer that supports 14,000 RPS reads while the CA continues normal operation. This architectural separation of issuance and consumption reduced recovery time from nearly 24 minutes to seconds while shifting focus to secure secret lifecycle management including KRA key protection.
MinTsifry Considers Annual 10 Billion Rubles Support Package for Russian AI Development
Russia's Ministry of Digital Development is discussing a state support package worth up to 10 billion rubles per year aimed at local AI developers. The proposed funding would cover technology development, pilot launches, and compensation for computing resources. According to Kommersant, 8 billion rubles are planned for development and implementation while 2 billion would offset computational costs. Mechanisms under consideration include subsidized loans through authorized banks and grants covering up to 80 percent of pilot project costs in priority sectors. The initiative remains in discussion with no final parameters or launch timelines confirmed yet. Industry experts note that clear selection criteria and transparent reporting will be essential to prevent intermediaries and ensure fair access for independent teams.