AntiMalwareJuly 20, 2026🇷🇺Translated from Russian

VK WorkSpace Adds Guest Access Without Accounts, Password Protection, Polls, and File Uploads Up to 30 MB

VK Tech has released an update to the cloud version of VK WorkSpace Board, introducing several new capabilities aimed at simplifying collaboration with external users while strengthening access controls.

External participants such as clients, contractors, and other guests can now be invited to boards without the need to create a VK WorkSpace account. To prevent unauthorized changes, board owners can protect access with a password and define precise permissions for each guest, including view-only mode, commenting rights, or full editing capabilities. Guests remain restricted from creating new boards or accessing version history.

Domain administrators gain the ability to enforce password protection as a mandatory requirement for all boards that allow guest access, reducing risks if links are shared incorrectly.

The update also adds built-in polls with automatic result tallying, enabling teams to collect input on ideas, set priorities, or conduct retrospectives without manual counting of votes.

Users can now upload files up to 30 MB in size; these files are automatically scanned by antivirus software before being made available for download by other participants.

For improved navigation on large projects, a mini-map feature has been introduced. Completed boards can be copied or exported in multiple formats including SVG, PNG, JPG, PDF, and CSV.

Additionally, VK WorkSpace now offers a full English-language interface. According to Petr Shcheglov, head of productivity services at VK Tech, working with clients, contractors, and candidates has become one of the primary collaboration scenarios, and the new guest access options make inviting external users significantly easier.

Related articles

HabrOther

Building a Minimalist UI Test Framework with Playwright and Pytest

Vladislav Timashenkov from InfoWatch presents a practical approach to constructing a concise UI automation testing framework using Playwright. The article focuses on leveraging native Playwright features instead of creating additional abstraction layers. It covers launching a Chromium browser once per session, handling authentication via API calls to obtain cookies, and managing isolated BrowserContext instances for test independence. Readers learn how to implement Page Object models that rely on Playwright's built-in locators and auto-waiting mechanisms. The tutorial includes real code examples for fixtures, context factories, and a sample test for tag management functionality. This method reduces maintenance overhead while ensuring tests remain scalable across different environments.

AntiMalwareOther

Russia Develops Domestic ERA-GLONASS System for Public Transport Tracking During GPS and GLONASS Disruptions

AO GLONASS has created a national system that maintains real-time monitoring of buses and trolleybuses even when satellite navigation signals are jammed or lost. The solution relies on the state-run ERA-GLONASS platform, placing autonomous markers at stops and identifiers on vehicles to record exact positions without depending on GPS or GLONASS. Data is transmitted over a protected ERA-GLONASS communication channel that remains available during mobile internet restrictions thanks to inclusion in official white lists. The first deployment begins in Kaluga on 1 September, covering three trolleybus routes with live tracking for passengers, dispatchers, carriers, and mapping services. The battery-powered markers are designed for five years of maintenance-free operation in any weather and are built entirely with Russian components and encryption algorithms. Future plans include extending the technology to municipal vehicles and emergency services fleets.

HabrOther

OSINT for the Lazy Part 16: Discovering Hidden Corporate Infrastructure Through Shodan

The article explains how Shodan differs from traditional search engines by indexing internet-connected devices such as servers, routers, cameras, databases, and admin panels rather than web pages. It provides ten practical search techniques including hostname queries, SSL certificate searches, ASN lookups, IP range scans, and targeted queries for development environments, admin panels, and databases. Examples demonstrate how forgotten dev.company.com or staging.company.com hosts, open Jenkins or Grafana dashboards, and exposed MongoDB or Redis instances can be located with simple filters. The piece walks through a five-step real-world workflow that combines domain, SSL, organization, and service-title searches to map a target company’s infrastructure. It emphasizes that Shodan only reveals services already exposed to the internet and does not perform any exploitation. Common root causes listed include forgotten test servers, rushed DevOps configurations, and misconfigured firewalls. The article concludes with a reminder that many organizations remain unaware their internal systems are visible to anyone using the same techniques.

AntiMalwareOther

Rostelecom Outage Triggers 29-Minute Mass Disruptions Across Russian Internet Services

A 29-minute failure in Rostelecom's data transmission network on August 6 caused widespread access problems to Russian online services. The operator quickly rerouted traffic to backup equipment, restoring normal operations without revealing the root cause. Users reported issues connecting to marketplaces, banks, social platforms, IT company services and other telecom providers. The majority of complaints originated from Rostelecom's own subscribers who experienced connection and service access failures. Although the incident remained brief and did not escalate into prolonged digital disruption, it highlighted the heavy reliance on a single major provider. The event demonstrated how even a short technical problem at a large operator can simultaneously affect access to stores, financial services and everyday online platforms.