AntiMalware•October 8, 2026•🇷🇺Translated from Russian

Russian Internet Services Hit by Outages After Drone Attack on Yandex Data Center in Sasovo

On October 8, numerous Russian websites and online services began experiencing widespread outages and performance issues. Users reported difficulties accessing pages of media outlets, transportation resources, and marketplaces, while a substantial portion of the problems affected internal corporate systems and specialized professional tools.

According to reports from Kod.ru, the disruptions extended beyond Yandex. Cian confirmed that its website and mobile application stopped functioning, attributing the failure to an incident involving an infrastructure partner. Sites belonging to developers A101, Granel, and Brusnika also became temporarily inaccessible.

T-Bank recorded interruptions in its corporate messenger and email distribution systems. Internal system problems were additionally noted at Ozon, Wildberries, and HSE. Astral issued a warning about possible temporary disruptions in electronic reporting, electronic document management, and services for electronic transportation documents.

In connection with these events, Yandex confirmed a fire that occurred after a drone attack on its data center in Sasovo, Ryazan region. The company stated that no individuals were injured, the facility was completely shut down, and specialists are working to address the consequences. Some services may have been unavailable as a result. However, attributing every user complaint to this single incident remains premature, as the scale of problems varies significantly across affected organizations.

Related articles

Habr•Other

macOS User Investigates Claude Regional Block via Logs and Restores Work Site Access with Targeted WireGuard Routes

A detailed case study describes how a macOS user analyzed Claude application logs after experiencing regional unavailability errors while using WireGuard VPN. The investigation covered ~/Library/Logs/Claude/ files containing markers like app-unavailable-in-region and region_unavailable, cross-referenced with tunnel activity dates from August to October 2026. No direct evidence linked the VPN to the account block, as tunnel logs were overwritten and system journals returned Operation not permitted errors. The user then addressed a secondary issue where WireGuard blocked access to work services including amoCRM, TGBooster, and Geekjob. Custom host routes were added via route add commands to direct specific IPv4 addresses through the local gateway while keeping Claude traffic in the tunnel. A launchd-based PF kill switch was tested for tunnel failure protection but caused a full internet outage on October 5 due to anchor and hook conflicts, leading to its rollback. By October 8, work sites functioned under VPN with verified routes, though persistent kill switch protection remained unresolved.

Habr•Other

Publishing Internal APIs from DMZ Without Direct LAN Connections: Five Tested Architectures

When an API gateway resides in the DMZ but security policies forbid outbound connections into the LAN, organizations must adopt alternative patterns to expose internal services synchronously. The article examines five production-ready approaches built on the NEOMSA APIM platform, ranging from custom request-reply logic over Kafka to zero-code solutions using ActiveMQ Artemis and experimental reverse HTTP in HAProxy. Each pattern is evaluated against criteria such as the need for DMZ-to-LAN firewall rules, volume of custom code, support for streaming responses, and measured performance. Load tests on the Artemis-based bridge reached 50 requests per second with a 95th percentile latency of approximately 100 ms, while the Kafka implementation required roughly 2,500 lines of Java to emulate missing reply semantics. The analysis highlights trade-offs in operational complexity, vendor support implications, and security posture, particularly the benefit of preventing any outbound initiation from the DMZ.

AntiMalware•Other

FSB in Chelyabinsk Region Proposes QR-Code Passports for Tracking Construction Materials to Combat Theft

The regional branch of Russia's Federal Security Service in Chelyabinsk has suggested introducing an electronic tracking system for construction materials using unique QR codes assigned to each batch. The initiative aims to reduce theft and fraud during the construction of social facilities by creating a verifiable digital record of material movement from supplier to site. According to official representative Tatyana Sosnina, the system would allow real-time comparison between ordered quantities, project documentation, and actual usage on site. This approach is expected to help customers and oversight bodies quickly identify discrepancies between procurement records and physical consumption. The proposal does not yet include any announced timelines or estimated implementation costs. Experts note that the effectiveness of such QR-based tracking will ultimately depend on the accuracy of data entry at every stage of the supply chain rather than on the codes themselves.

Habr•Other

Tools Alone Won't Suffice: Building Systemic Kubernetes Security Across Hundreds of Clusters at Alfa-Bank

Alexander, lead of the K8S and cloud security department at Alfa-Bank, explains how the bank moved from fragmented tools and ad-hoc practices to a comprehensive process-driven security function covering more than 500 Kubernetes clusters. The approach centers on a threat lifecycle model that includes threat modeling, requirements definition, project expertise, auditing, risk assessment, platform operations, and SOC integration. A RACI matrix formalizes responsibilities across security, DevOps, AppSec Business Partners, and IT teams to ensure consistent execution at scale. Four specialized roles—an architect, analyst-engineer, auditor, and platform DevOps engineer—handle the workload that no single individual could manage. The bank emphasizes that commercial scanners and policies deliver value only when embedded in repeatable processes tied to a living threat model and clear accountability.