.RU and .РФ Registries Stop Disclosing Legal Entity Domain Owners in WHOIS
The registries responsible for .RU and .РФ domains have stopped publishing information about legal-entity administrators in the public WHOIS service. Until recently the records included both the official name of the organization and its INN tax identification number; the same fields now contain only the single word Organization.
The modification was detected on 22 July by Habr contributor @ifap. One illustrative case is the domain formerly shown as belonging to Russia’s Federal Protective Service; the record now withholds any identifying details.
Because the change affects every legal-entity registration, investigators can no longer determine at a glance which company or state body controls a given domain. Locating the actual administrator therefore requires additional open-source research or formal requests.
Representatives of the Coordination Center stated that the data are temporarily unavailable for technical reasons. They declined to specify which component failed or how long the outage is expected to last, and they offered no assurance that the previous fields will reappear.
One hypothesis circulating among observers is that the registry is being re-engineered to comply with updated authentication rules for domain administrators. No official confirmation of this explanation has been issued.
Prior to the change, WHOIS queries provided a fast and reliable method for identifying the corporate or governmental entity behind any .RU or .РФ domain. The current format effectively reveals only that the registrant is an organization rather than an individual, leaving all further identification to external investigation.
Related articles
Advanced Windows Auditing Configuration Guide for Effective Incident Response in SOC Environments
The article provides a detailed walkthrough on configuring advanced audit policies in Windows 10 and Windows 11 to generate meaningful security events for incident investigation. It explains the role of the LSASS service in logging activities to the Security event log and contrasts basic auditing with the more granular advanced auditing that offers 53 subcategories. The guide covers enabling key subcategories such as Logon, Process Creation, and Account Management using auditpol commands, along with registry tweaks for PowerShell Script Block Logging and command-line auditing in process creation events. Practical tests demonstrate real-world events including successful and failed logons (Event IDs 4624 and 4625), process creation with arguments (Event ID 4688), and user account creation (Event IDs 4720 and 4732). All steps are performed on a VMware Workstation virtual machine running Windows 10 Pro 22H2 to avoid impacting production systems.
Russia's Supreme Court Bans Silent Crow and Cyberpartisans BY as Extremist Organizations
The Supreme Court of the Russian Federation has officially recognized the hacker groups Silent Crow and Cyberpartisans BY as extremist organizations and banned their activities in Russia. The closed-door ruling, issued at the request of the General Prosecutor's Office, accuses both groups of conducting joint cyberattacks against Russian and Belarusian critical information infrastructure with the aim of destabilizing the political situation and achieving an unconstitutional change of government. Cyberpartisans BY are described as part of the Belarusian association Supratsiv, which allegedly seeks a violent overthrow of the constitutional order, and are linked to the banned Polk named after Kastus Kalinouski as well as Ukrainian military information-psychological operations units. Silent Crow, previously known as CyberWar and Cyber LegionsUA, is portrayed as a pro-Ukrainian collective of politically motivated hacktivists whose primary objective is to damage Russian state bodies, companies, and critical infrastructure. Both groups are held responsible for attacks on Aeroflot IT systems, Rostelecom databases, Rosreestr servers, and the Belarusian Railway infrastructure. Participation in or support for these organizations now carries legal liability under Russian law.
How CISOs Can Speak to CEOs: Translating Cyber Risks into Business Impact and Financial Consequences
The July 2025 Aeroflot cyber incident, claimed by Silent Crow and Belarusian Cyber-Partisans, demonstrated how technical vulnerabilities quickly translate into canceled flights, regulatory investigations, stock market reactions, and direct executive accountability. The article examines the persistent communication gap between CISOs, who focus on metrics like EDR coverage and mean time to detect, and CEOs, who prioritize costs, operational disruptions, revenue loss, and personal liability. Research from EY and Splunk highlights differing perceptions of threats and success measures, while real-world cases such as Marks & Spencer, Jaguar Land Rover, Clorox, Change Healthcare, SolarWinds, and Uber show how contractor weaknesses, missing MFA, and delayed disclosures lead to hundreds of millions in damages and legal actions. Regulatory developments, including SEC charges against CISOs and Russia's 420-FZ with turnover-based fines, further force cybersecurity discussions into the boardroom. The piece provides a practical translation table showing how technical warnings should be reframed using concrete business scenarios and financial impacts. It concludes that both CISOs and CEOs must initiate conversations around unacceptable events, downtime costs, and risk reduction versus post-incident consequences.
EU Forces Google to Open Android Microphone, Camera and Screen Access for Rival AI Assistants
The European Union has ordered Google to provide competing AI assistants with the same level of access to sensitive Android resources that is currently reserved for Gemini. The ruling covers eleven system functions, including voice activation, home button integration, background execution, and on-device AI model access. Rival assistants will also gain real-time environmental data streams from the microphone, camera, screen, and speakers under identical consent and notification rules applied to Google services. Additional capabilities include cross-app interaction, messaging, scheduling, device settings control, and multi-step task automation. Screen automation will allow assistants to operate apps inside a virtual window while the user performs other activities. Most changes are scheduled for Android 18 by 1 August 2027, while simultaneous activation of multiple assistants by voice keyword will arrive in Android 19 no later than 1 August 2028. Access to the most sensitive functions may require objective security certification and explicit user authorization.