Habr•September 29, 2026•🇷🇺Translated from Russian

K2 Cloud Adds Native OVN Traffic Mirroring for NTA/NDR Deployment in Public Cloud

K2 Cloud has become the first Russian public cloud to support native traffic mirroring from virtual-machine interfaces for NTA/NDR systems. The implementation was achieved by extending OVN overlay-network capabilities and contributing the changes upstream, where the patch was accepted into the main code base.

Why cloud traffic visibility was missing

Until this development, no Russian public cloud offered the ability to mirror VM traffic. PT Network Attack Discovery (PT NAD) from Positive Technologies and similar tools require an exact copy of network packets to perform signature analysis, indicator-of-compromise checks, sandbox integration, and behavioral anomaly detection. Without this copy the systems cannot function.

How the mirroring works

Mirroring is performed after the packet has passed the load balancer and cloud firewall for inbound traffic, and immediately after the VM for outbound traffic. The original packet continues to its destination while an identical copy is sent to the designated PT NAD sensor. The feature operates across any project networks, including different VPCs, and mirrors exactly the same traffic that would be seen by tcpdump inside the VM.

Filters solve duplicate, one-sided, and elephant-flow problems

  • Inbound filter rules drop traffic originating from other VMs inside the same VPC to prevent duplicate packets from reaching the sensor.
  • Outbound rules explicitly allow traffic to the default gateway so that DNS and DHCP sessions remain complete.
  • Heavy but legitimate flows such as backups can be excluded by IP, port, and protocol to reduce sensor load.

Filters are applied only to the cloned packets and have no effect on the original traffic.

Operational constraints and performance

Mirroring is limited to a single availability zone; each additional zone requires its own PT NAD instance. Load testing conducted jointly with Positive Technologies demonstrated more than 3 Gbit/s of mirrored HTTP traffic, roughly 400 000 packets per second, and 30 000 HTTP transactions per second with negligible packet loss. The official PT NAD rating is 2 Gbit/s; higher rates are achievable with multiqueue configuration on the capture interface.

Deployment notes

Administrators must remove the automatically assigned IP address from the capture interface by uninstalling the c2-ec2-netutils package, otherwise the DPDK-based sensor will not start. Disk IOPS should be monitored when raw traffic storage is enabled. All resources—sources, destinations, sessions, and filters—can be managed through the web console, the EC2-compatible API, or the K2 Cloud Terraform provider.

Related articles

Securitylab•Other

Neuromorphic Processors Deliver Reflex-Like Responses for Robots, Drones and Edge Sensors

Neuromorphic chips are optimized for sparse, event-driven data rather than dense matrix operations, making them ideal for always-on peripheral devices that must react instantly while conserving power. The technology pairs naturally with event cameras and temporal sensors in robotics, drones, automotive systems, medical wearables, industrial monitoring and space applications. Platforms such as Intel Loihi 2, BrainChip Akida, SynSense Speck and SpiNNaker2 already demonstrate working prototypes that activate only on meaningful changes in the input stream. Researchers at TU Delft have flown autonomous drones using spiking networks on Loihi, while NASA has tested radiation-tolerant neuromorphic designs for onboard decision making. The approach complements rather than replaces GPUs and NPUs, creating hybrid systems where the neuromorphic layer handles fast reflexes and conventional accelerators manage complex models.

Securitylab•Other

Bitrix24 Introduces Cowork/Code AI Agent for Corporate Task Automation and App Building

Bitrix24 has launched Cowork/Code, an AI application that combines file management, company data access, and application development inside a controlled corporate environment. The tool features an AI agent capable of executing multi-step workflows such as locating records, comparing documents, generating tables, and saving results to shared folders. It operates in two modes: Cowork for one-time tasks like overdue task reports or client preparation, and Code for creating reusable tools such as dashboards or notification bots. A memory technology called Radiant stores context from chats, tasks, meetings, and employee data to deliver more accurate, personalized responses over time. The platform addresses common risks of vibe coding by keeping code, data access, and distribution within the Bitrix24 ecosystem hosted on Russian infrastructure. A free tier provides limited usage, with paid plans required for sustained team operation.

Habr•Other

Klark and Klara Launch Self-Hosted Corporate Messenger and Task Manager for On-Premise Data Control

Klark and Klara are two integrated products designed to keep corporate communication and task management entirely within company infrastructure. Klark functions as a Telegram-like messenger with personal chats, supergroups, channels, voice messages, file sharing, and video calls powered by LiveKit. Klara serves as a streamlined task and knowledge base system replacing complex setups like Jira and Confluence. Both run via Docker Compose on customer servers using PostgreSQL, Redis, FastAPI, and React, with built-in antivirus scanning via ClamAV. Key security measures include mandatory TOTP two-factor authentication, LDAP integration, content security policies, and automatic session invalidation on token reuse. The combination allows direct task creation from chat messages and displays tasks alongside conversations in a unified interface.

AntiMalware•Other

Russia's Taxi Market Overrun by Illegal Drivers Using Fake Accounts and Gray Intermediaries

Russian taxi aggregators are increasingly relying on complex chains of intermediaries that allow drivers without proper licenses, experience, or even Russian permits to operate. These gray schemes involve dispatch services, car fleets, individual entrepreneurs, and so-called podklyuchashki that sell ready-made accounts for 3-7 thousand rubles after minimal verification. A high-profile incident in Odintsovo exposed how a driver refusing service to a disabled veteran of the special military operation was later deported, revealing a corporate maze where the vehicle, the connecting IP, and the driver had no direct link to the aggregator. Official data shows over 900,000 vehicles registered in the FGIS Taxi system, yet more than 1.5 million drivers may be operating outside legal requirements. With Russians taking around 10 million taxi trips daily, the lack of accountability has contributed to over 3,100 accidents involving taxis in 2025, resulting in 143 deaths and more than 3,800 injuries. Courts remain inconsistent in assigning liability across aggregators, fleets, and individual drivers. Experts are calling for aggregators to be designated as carriers with mandatory checks and joint liability.