Habr•October 2, 2026•🇷🇺Translated from Russian

Enterprise-Grade Web Protection on a Budget: How Cloud WAF Lowers Barriers for SMBs

Reg.cloud has published a detailed guide explaining how cloud WAF solutions make enterprise-grade web application protection accessible to small and medium-sized businesses that lack dedicated security infrastructure.

According to data from Positive Technologies, 82% of Russian SMBs encountered cyber incidents over the past year, and 75% of successful web application attacks in 2025 resulted in operational disruption. Traditional WAF deployments require purchasing hardware or allocating servers, obtaining licenses, and maintaining the installation, creating high barriers for smaller teams.

Cloud WAF shifts these responsibilities to the provider. Organizations pay only for the service itself, either through subscription or usage-based pricing, while the provider handles infrastructure, updates, and scaling. Seven ready-made protection profiles are available for popular CMS platforms, API services, e-commerce flows, and media sites, allowing teams to start with baseline rules rather than building policies from scratch.

The article stresses that a dedicated security specialist is not always required. Tasks can be distributed between DevOps engineers and developers across three phases: preparation (gathering DNS records, origin server details, and rollback plans), connection (DNS redirection with initial audit mode to baseline legitimate traffic), and ongoing maintenance (reviewing logs, adding exceptions for false positives, and updating policies after application changes).

Key features include dual audit and blocking modes, detailed event logging with IP, payload, and rule information, rate limiting, bot filtering, and support for HTTP/HTTPS traffic inspection against SQL injection, XSS, and API abuse. A free testing tier currently allows protection of up to three applications at 50 requests per second.

The five-step onboarding process covers service activation, application registration, backend configuration, profile selection, and final DNS A-record change to route traffic through the cloud scrubbing center. The publication notes that WAF is not a complete solution and must be paired with vulnerability patching, access management, and separate defenses against volumetric DDoS or sophisticated bots.

Related articles

AntiMalware•Other

Yandex B2B Tech Integrates Hybrid Full-Text and Vector Search in Single YDB Query

Yandex B2B Tech has added hybrid search to its YDB database, allowing full-text and vector approaches to run together inside one SQL query. The update helps small and medium businesses as well as large corporations locate exact document identifiers while also matching semantic meaning in descriptions, even when wording differs. Full-text search handles precise elements such as policy numbers, codes, and names, whereas vector search identifies conceptual similarity. Results from both methods are merged and ranked within the same transaction, keeping all data inside a single database instance. This removes the need to maintain a separate search engine and vector store or to reconcile information between them. The technology is aimed at chatbots, recommendation systems, and AI assistants that process technical content where both exact codes and human-readable problem descriptions matter equally. Hybrid search is now available in the on-premises YDB 26.3 release and in the cloud-based Managed Service for YDB.

AntiMalware•Other

Google Developing Voice-Activated Emergency SOS Feature for Android Devices

Google is working on a voice-activated Emergency SOS function for Android that would allow users to summon help without touching their smartphone. The feature, discovered in the Personal Safety app code by Android Authority, appears to trigger after the user says the word 'Help' three times in sequence. Once activated, the system would automatically determine location, begin emergency video recording, and place a call to emergency services. The current method requires pressing the power button five times, which can be impractical in certain situations. Additional code strings suggest optional voice confirmation with phrases such as 'Say yes to continue' and 'Say cancel to dismiss Emergency SOS'. The function is not yet available to users and may eventually reach non-Pixel devices running the Personal Safety app, though supported languages and models remain undisclosed.

Habr•Other

How the Lorenz SZ 42 Teleprinter Cipher Machine Worked: Nazi High Command Encryption and Its 1941 Breakthrough

The Lorenz SZ 42 was a teleprinter attachment used by the German high command for encrypting top-secret communications during World War II, operating on the Vernam cipher principle with twelve wheels generating a keystream. Unlike the portable Enigma, Lorenz integrated directly between teletypes for automatic five-bit ITA2 encryption. British interceptors at Knockholt first encountered its signals in 1940, later named Tunny. A critical operator error on 30 August 1941 allowed cryptanalysts at Bletchley Park to deduce the machine's structure. This led to the development of the Colossus computer in 1944 for automated decryption. The article details the χ, ψ, and μ wheel groups, the stuttering psi mechanism, and Python implementations of ITA2 encoding and XOR operations.

Securitylab•Other

Inside the Fortress: Why Perimeter Security Tools Fall Short and How Microsegmentation Protects Networks Internally

Companies invest heavily in perimeter defenses such as firewalls and intrusion detection systems, yet these measures no longer guarantee safety as attackers increasingly operate from within networks. Traditional L2 domains leave virtual machines unisolated, enabling traffic interception, lateral movement, and malware spread similar to an apartment building with poor soundproofing. Microsegmentation powered by SDN divides VLANs into isolated microsegments down to individual VM ports, enforcing granular policies based on ports, IP addresses, and protocols. This approach implements Zero Trust by placing virtual packet filters directly at VM network interfaces on the hypervisor, independent of guest OS actions. Performance remains high because filtering runs on powerful virtualization servers, and scaling occurs naturally as additional hypervisors absorb new workloads without extra configuration. A real-world case from the oil and gas sector shows one customer creating up to 5,000 new microsegmentation rules per week via open REST API. The technology complements rather than replaces perimeter firewalls, delivering both strict internal controls and operational agility.