AntiMalware•September 28, 2026•🇷🇺Translated from Russian

Russians Offered Unofficial 5G Activation on iPhone for 399 Rubles with No Guarantees

Russian iPhone users who want to use 5G networks can now pay a service called 5G First to bypass Apple's current restrictions for 399 rubles. The tool requires only a computer connection and does not involve jailbreaking the device.

According to analysis by iPhones.ru, the program most likely alters the carrier profile stored on the iPhone. These profiles define which network capabilities are allowed for a particular SIM card. The software keeps the original Russian operator parameters while adding the 5G-related options that Apple has disabled in Russia.

The service is explicitly labeled experimental by its developers. It does not support every model, including the iPhone Air and devices that use only eSIM. Compatibility also varies with the version of iOS, the mobile operator and the specific SIM card in use.

A free alternative called CarrierSIM has appeared for iOS 17. The script instructs the system to load the built-in Vodafone Hungary carrier profile, which already permits 5G access. Changes are written using the AirLift mechanism that exploits access outside the Apple Books synchronization directory.

Neither solution provides transparency about exactly which system files are modified or what data is processed. It remains unknown whether the changes will persist after the next iOS update. Apple could close both workarounds with a future software release.

Even if the 5G toggle appears in the settings menu, users will only benefit where Russian operators have actually deployed fifth-generation networks. Current 5G coverage in Russia remains limited and does not always deliver noticeable improvements over LTE.

The Ministry of Digital Development has begun talks with Apple about enabling 5G officially on iPhones sold in Russia.

Related articles

Habr•Other

Klark and Klara Launch Self-Hosted Corporate Messenger and Task Manager for On-Premise Data Control

Klark and Klara are two integrated products designed to keep corporate communication and task management entirely within company infrastructure. Klark functions as a Telegram-like messenger with personal chats, supergroups, channels, voice messages, file sharing, and video calls powered by LiveKit. Klara serves as a streamlined task and knowledge base system replacing complex setups like Jira and Confluence. Both run via Docker Compose on customer servers using PostgreSQL, Redis, FastAPI, and React, with built-in antivirus scanning via ClamAV. Key security measures include mandatory TOTP two-factor authentication, LDAP integration, content security policies, and automatic session invalidation on token reuse. The combination allows direct task creation from chat messages and displays tasks alongside conversations in a unified interface.

AntiMalware•Other

Russia's Taxi Market Overrun by Illegal Drivers Using Fake Accounts and Gray Intermediaries

Russian taxi aggregators are increasingly relying on complex chains of intermediaries that allow drivers without proper licenses, experience, or even Russian permits to operate. These gray schemes involve dispatch services, car fleets, individual entrepreneurs, and so-called podklyuchashki that sell ready-made accounts for 3-7 thousand rubles after minimal verification. A high-profile incident in Odintsovo exposed how a driver refusing service to a disabled veteran of the special military operation was later deported, revealing a corporate maze where the vehicle, the connecting IP, and the driver had no direct link to the aggregator. Official data shows over 900,000 vehicles registered in the FGIS Taxi system, yet more than 1.5 million drivers may be operating outside legal requirements. With Russians taking around 10 million taxi trips daily, the lack of accountability has contributed to over 3,100 accidents involving taxis in 2025, resulting in 143 deaths and more than 3,800 injuries. Courts remain inconsistent in assigning liability across aggregators, fleets, and individual drivers. Experts are calling for aggregators to be designated as carriers with mandatory checks and joint liability.

Habr•Other

CryptoLab: Interactive Educational Platform Turns Cryptographic Protocols Course into Hands-On Alice, Bob and Mallory Experiments

A university instructor developed CryptoLab, an educational testbed that lets students run live cryptographic protocol experiments with active attackers instead of simple encrypt-decrypt exercises. The platform models the classic Alice-Mallory-Bob scenario where each participant runs as a separate application mode, allowing inspection, modification, dropping, and replay of packets. The first lab focuses on AES-GCM, AEAD properties, nonce reuse, replay protection, weak RNGs, key rotation, and metadata leakage. Students can operate in interactive mode to manually attack traffic or execute automated scenarios that verify expected security outcomes. Experiments demonstrate that modifying ciphertext triggers authentication failure and that a valid authentication tag does not guarantee message freshness without additional replay defenses. The tool also includes Python 3.10 assignments for correctly using cryptographic primitives rather than implementing algorithms from scratch. CryptoLab currently supports Windows x64 and macOS Apple Silicon builds and serves as the foundation for upcoming labs on symmetric encryption modes, asymmetric cryptography, key exchange, and TLS.

Habr•Other

From Scanner Overload to Manual Insight: A Bug Bounty Hunter's Journey

A young researcher recounts his transition from automated scanning to thoughtful manual analysis in Bug Bounty programs. After completing a broad information security course covering cryptography, networks, Docker, databases, and OWASP Top 10, he initially approached real-world targets with the same scanner-heavy mindset used in labs. Months of fruitless results led to burnout and a six-month break working in construction. Returning with a new focus, he studied hundreds of public HackerOne reports to understand researcher reasoning and anomaly detection. This shift enabled his first valid, unreported finding and fundamentally changed his methodology. Today the 18-year-old university student balances Bug Bounty with reconnaissance, machine learning, and personal projects while emphasizing deep application understanding over tool volume.