Bridging Manual and Automated Testing: InfoWatch Engineer Outlines Unified Quality Process
InfoWatch senior test engineer Mikhail Shalepo has shared a comprehensive internal regulation that connects manual and automated testing into one coherent quality process. The article uses the metaphor of an “orange” to describe the overlapping area of functional verification where the two testing approaches must deliver a single, reliable signal about product state.
Shalepo notes that when automation volume, environments, and mandatory runs remain small, teams often rely on shared context. As the product grows, this implicit understanding disappears, creating the need for explicit rules on selecting automation candidates, validating new tests, defining mandatory regression sets, classifying failures, and recording manual compensation.
Core Principles of the Regulation
The document distinguishes between process rules—who decides, what result is recorded, and who owns the next step—and specific engineering decisions for individual features. It establishes that manual testers review the purpose of an automated scenario rather than its code, and that every failure must receive an owner and follow-up action before a run is considered resolved.
The regulation is split into two blocks: development and verification of new functionality, and full regression testing before release. Both blocks follow the same three-stage structure—preparation, execution, and completion—producing clear artifacts at each step.
Feature Development Block
Before a sprint, manual testers and automation engineers meet to discuss scenarios worth automating. Decisions are turned into backlog tasks instead of remaining informal promises. During the sprint, the manual testing team acts as the customer of automation meaning, while smoke tests must pass before any build reaches manual verification. At sprint end, coverage status is recorded directly in TMS Scale to keep the single source of truth up to date.
Pre-Release Regression Block
Before regression begins, teams align on the full scope of checks, supported configurations, and exit criteria. During execution, automated results are triaged jointly with developers; every failure is classified, assigned an owner, and linked to a task or defect. Manual compensation is documented only when an automated signal cannot be restored quickly. At the end of regression, the team produces a connected set of artifacts that allow full reconstruction of the release decision without relying on chat history.
Shalepo emphasizes that the regulation does not guarantee zero defects or automatically shorten regression time. Its value lies in making the basis for release decisions observable and repeatable across the team.
Related articles
Pivoting in Legacy Hell: Navigating MIPS Servers, BusyBox, and 2014 Kernels During Internal Network Assessments
The article details a complete methodology for pivoting from an initial SSH compromise on an old Debian MIPS server to reach a hidden web admin panel inside a segmented network. It covers environment enumeration with commands like uname -a and ip route, followed by setting up a Chisel-based SOCKS5 proxy when standard SSH dynamic forwarding is disabled by server configuration. Scanning proceeds via proxychains with nmap using -sT, -Pn, and -n flags or by deploying static MIPS binaries directly on the host. Traffic is then routed through Burp Suite chained to the SOCKS proxy for password guessing against the web interface. The piece emphasizes practical constraints such as BusyBox limitations, kernel version incompatibilities with modern binaries, and the need for careful subnet identification. Readers are directed to replicate the full chain in the Forgotten Server task from the free White Hacker Profession course.
Neuromorphic Processors Deliver Reflex-Like Responses for Robots, Drones and Edge Sensors
Neuromorphic chips are optimized for sparse, event-driven data rather than dense matrix operations, making them ideal for always-on peripheral devices that must react instantly while conserving power. The technology pairs naturally with event cameras and temporal sensors in robotics, drones, automotive systems, medical wearables, industrial monitoring and space applications. Platforms such as Intel Loihi 2, BrainChip Akida, SynSense Speck and SpiNNaker2 already demonstrate working prototypes that activate only on meaningful changes in the input stream. Researchers at TU Delft have flown autonomous drones using spiking networks on Loihi, while NASA has tested radiation-tolerant neuromorphic designs for onboard decision making. The approach complements rather than replaces GPUs and NPUs, creating hybrid systems where the neuromorphic layer handles fast reflexes and conventional accelerators manage complex models.
K2 Cloud Adds Native OVN Traffic Mirroring for NTA/NDR Deployment in Public Cloud
K2 Cloud has implemented traffic mirroring for virtual machine interfaces inside overlay networks built on OVN, solving a long-standing gap that prevented NTA/NDR systems from operating in Russian public clouds. The company contributed the feature upstream, and the patch was accepted into the main OVN codebase. The solution supports source, destination, and mirroring session objects together with optional match/action filters that eliminate duplicate packets, reduce load on sensors, and allow traffic distribution across multiple analyzers. Testing with Positive Technologies PT NAD showed sustained throughput above 3 Gbit/s with approximately 400 000 packets per second and minimal packet loss. The feature works inside a single availability zone; multi-AZ deployments require one PT NAD sensor per zone. Management is available through the web console, an EC2-compatible API, and the official Terraform provider.
Bitrix24 Introduces Cowork/Code AI Agent for Corporate Task Automation and App Building
Bitrix24 has launched Cowork/Code, an AI application that combines file management, company data access, and application development inside a controlled corporate environment. The tool features an AI agent capable of executing multi-step workflows such as locating records, comparing documents, generating tables, and saving results to shared folders. It operates in two modes: Cowork for one-time tasks like overdue task reports or client preparation, and Code for creating reusable tools such as dashboards or notification bots. A memory technology called Radiant stores context from chats, tasks, meetings, and employee data to deliver more accurate, personalized responses over time. The platform addresses common risks of vibe coding by keeping code, data access, and distribution within the Bitrix24 ecosystem hosted on Russian infrastructure. A free tier provides limited usage, with paid plans required for sustained team operation.