securitylab_n•July 12, 2026•🇷🇺Translated from Russian

Universe Proves Ordinary After All: High-Profile DESI Study Claiming Giant Aligned Cosmic Structures Collapses Following Data Correction

A high-profile paper published in the journal Nature that claimed to detect giant, directionally aligned filaments in the cosmic web has been effectively invalidated after independent researchers identified fundamental errors in the data analysis.

The original study examined observations from the Dark Energy Spectroscopic Instrument (DESI), which has produced one of the largest three-dimensional maps of the universe to date. The dataset included 47 million galaxies and quasars covering more than 11 billion years of cosmic history within the 13.8-billion-year lifespan of the universe.

According to the authors, the filaments of the cosmic web appeared significantly longer than predicted by existing models and, more strikingly, showed a preferred orientation rather than random alignment. Such a finding would have challenged the cosmological principle, the foundational assumption that the universe is statistically homogeneous and isotropic on sufficiently large scales, with no preferred directions.

An independent cosmologist who re-examined the work discovered that the team had used luminosity distance instead of the conventional comoving distance when measuring large-scale structure. These two distance measures serve different purposes and are not interchangeable for studies of cosmic-web geometry. In addition, the analysis did not incorporate the fact that distances between distant objects change over time due to the ongoing expansion of the universe.

After substituting the correct distance metric and applying the necessary expansion correction, the apparent giant aligned structures disappeared. The revised results showed a cosmic web that remains inhomogeneous on moderate scales but exhibits no mysterious preferred direction, fully consistent with the cosmological principle.

One of the original authors has disputed the critique, arguing that the re-analysis focused on the distribution of structures rather than their orientation. The independent reviewer maintains that the identified errors affect both types of measurements and are independent of the chosen analytical approach.

The controversy has raised broader questions about the peer-review process at leading journals. Although Nature typically requires papers to present results capable of significantly advancing a field, reviewers cannot realistically verify every line of code or calculation. The authors of the disputed study also bypassed the common practice of posting a preprint on the arXiv server, depriving the community of an opportunity for early scrutiny. Scientific embargoes imposed by journals further limited pre-publication discussion, highlighting ongoing tensions between the desire for high-impact announcements and the need for thorough, open verification.

Related articles

Securitylab•Other

Inside the Fortress: Why Perimeter Security Tools Fall Short and How Microsegmentation Protects Networks Internally

Companies invest heavily in perimeter defenses such as firewalls and intrusion detection systems, yet these measures no longer guarantee safety as attackers increasingly operate from within networks. Traditional L2 domains leave virtual machines unisolated, enabling traffic interception, lateral movement, and malware spread similar to an apartment building with poor soundproofing. Microsegmentation powered by SDN divides VLANs into isolated microsegments down to individual VM ports, enforcing granular policies based on ports, IP addresses, and protocols. This approach implements Zero Trust by placing virtual packet filters directly at VM network interfaces on the hypervisor, independent of guest OS actions. Performance remains high because filtering runs on powerful virtualization servers, and scaling occurs naturally as additional hypervisors absorb new workloads without extra configuration. A real-world case from the oil and gas sector shows one customer creating up to 5,000 new microsegmentation rules per week via open REST API. The technology complements rather than replaces perimeter firewalls, delivering both strict internal controls and operational agility.

Habr•Other

Good Bear 1.0 Released: Firefox-Based Browser with Isolated Russian PKI Trust Container

Good Bear 1.0 is a Russian-language browser built on Firefox 156.0 that provides an isolated container for handling Russian PKI certificates without mixing trust contexts or user data with the standard browsing session. The release includes .deb packages for Ubuntu 24.04 LTS amd64 and Windows x64 installers, using Mozilla Public License 2.0 and reproducible build processes from pinned Firefox sources. Instead of globally importing root certificates, the browser performs secondary chain validation only inside a dedicated userContextId container with strict OriginAttributes isolation for caches, storage, and connections. Password autofill and sensitive session data are disabled in the container when separation cannot be guaranteed, and POST requests trigger explicit user choice before reopening in the isolated context. The interface shows both a persistent container marker and a separate RU indicator only when Russian PKI is actively used, along with detailed security panels explaining the trust source. Updates, crash reporting, and automatic MAR mechanisms are intentionally omitted to avoid creating unverified trust chains for the distribution itself.

Habr•Other

Survey of 254 Russian Domains Shows 89% DMARC Adoption but Highlights Gaps in Reporting and Subdomain Policies

A manual review of public DNS records across 254 prominent Russian domains from 17 sectors found strong baseline adoption of email authentication mechanisms. MX records appeared in 96.1% of domains, SPF in 93.7%, DMARC in 89.0%, and DKIM records via common selectors in 62.2%. Among domains with DMARC, 40.7% published a reject policy and 42.9% used quarantine, while 16.4% remained at none. Notably, 19% of DMARC-enabled domains lacked any rua address for aggregate reports, including 33 domains enforcing reject or quarantine. The study also identified cases of inconsistent policies between parent domains and subdomains, as well as SPF records ending in ~all paired with strict DMARC settings. Researchers emphasized that DNS data alone cannot confirm actual mail flow alignment or report consumption.

AntiMalware•Other

Server Outage Halts Vehicle Registration Across Smolensk Region

A technical failure on a unified server has temporarily suspended vehicle registration services in the Smolensk region of Russia. The outage affects the interdistrict traffic police department No.1 located on Lavochkina street, preventing new registrations from being processed. Regional UMVD officials confirmed that the problem impacts the single server used for the entire oblast's registration system. According to department head Maxim Zykov, the disruption is considered temporary, though no precise restoration timeline was provided. Applicants who submitted requests through the Gosuslugi portal will receive services in the first working days after the system is restored. The UMVD plans to issue an additional announcement once operations resume.