MEPhI Opens 2026 Admissions for Online Cybersecurity Master's Program with Yandex Practicum
The National Research Nuclear University MEPhI (NIYAU MIFI) has announced that less than one month remains until the end of the admission campaign for its online master's program in Cybersecurity for the 2026 academic year. Offered in partnership with Yandex Practicum, the program is designed for working professionals and delivers two diplomas upon completion: a state master's degree in direction 10.04.01 Information Security and a professional retraining diploma in Cybersecurity from Yandex Practicum.
Program Tracks and Curriculum
The curriculum is structured around four educational tracks, each focusing on distinct areas of information security:
- AppSec Engineer – covers application security, vulnerability protection, secure coding in Python and Go, cryptography, database security, SIEM monitoring, penetration testing, and tools such as SAST, DAST, AES, RSA, and GDPR compliance.
- DevSecOps Engineer – emphasizes secure CI/CD pipelines, infrastructure as code, Kubernetes security, shift-left practices, and integration of security into DevOps workflows using tools like GitOps and Security as Code.
- Network Security Engineer – focuses on corporate network protection, traffic monitoring, incident response, Zero Trust architecture, OT/SCADA security, and frameworks including MITRE ATT&CK and the Cyber Kill Chain.
- AI Security Engineer – addresses threats to ML and LLM models, prompt engineering, secure development of AI systems, and protection of data interfaces using technologies such as OWASP Top 10 and cloud infrastructure security.
The program is updated annually by experts from Yandex and MEPhI faculty to reflect current market demands and emerging threats.
Admission Process for 2026
Applications must be submitted online. After leaving a request, an assigned curator assists with requirements, document preparation, and enrollment steps. Documents are uploaded through Gosuslugi, requiring a higher education diploma. Candidates then complete entrance examinations consisting of an information security test and a motivation letter, needing a minimum of 80 points to enter the competitive list. Successful applicants sign a contract and may pay via an educational loan with state support at a preferential 3% interest rate.
Learning Format and Benefits
Training lasts two years and is conducted entirely online with classes scheduled in the evenings and on weekends, requiring approximately 25 hours per week. Students receive full MEPhI student status, including access to discounts, a student ID, and potential military deferment. Previously completed relevant courses may be credited on an individual basis. Additional support includes academic supervisors, project feedback, and tax deduction options for tuition fees.
Those interested in the 2026 intake are encouraged to submit an application promptly to secure a place before the campaign closes.
Related articles
Inside the Fortress: Why Perimeter Security Tools Fall Short and How Microsegmentation Protects Networks Internally
Companies invest heavily in perimeter defenses such as firewalls and intrusion detection systems, yet these measures no longer guarantee safety as attackers increasingly operate from within networks. Traditional L2 domains leave virtual machines unisolated, enabling traffic interception, lateral movement, and malware spread similar to an apartment building with poor soundproofing. Microsegmentation powered by SDN divides VLANs into isolated microsegments down to individual VM ports, enforcing granular policies based on ports, IP addresses, and protocols. This approach implements Zero Trust by placing virtual packet filters directly at VM network interfaces on the hypervisor, independent of guest OS actions. Performance remains high because filtering runs on powerful virtualization servers, and scaling occurs naturally as additional hypervisors absorb new workloads without extra configuration. A real-world case from the oil and gas sector shows one customer creating up to 5,000 new microsegmentation rules per week via open REST API. The technology complements rather than replaces perimeter firewalls, delivering both strict internal controls and operational agility.
Good Bear 1.0 Released: Firefox-Based Browser with Isolated Russian PKI Trust Container
Good Bear 1.0 is a Russian-language browser built on Firefox 156.0 that provides an isolated container for handling Russian PKI certificates without mixing trust contexts or user data with the standard browsing session. The release includes .deb packages for Ubuntu 24.04 LTS amd64 and Windows x64 installers, using Mozilla Public License 2.0 and reproducible build processes from pinned Firefox sources. Instead of globally importing root certificates, the browser performs secondary chain validation only inside a dedicated userContextId container with strict OriginAttributes isolation for caches, storage, and connections. Password autofill and sensitive session data are disabled in the container when separation cannot be guaranteed, and POST requests trigger explicit user choice before reopening in the isolated context. The interface shows both a persistent container marker and a separate RU indicator only when Russian PKI is actively used, along with detailed security panels explaining the trust source. Updates, crash reporting, and automatic MAR mechanisms are intentionally omitted to avoid creating unverified trust chains for the distribution itself.
Survey of 254 Russian Domains Shows 89% DMARC Adoption but Highlights Gaps in Reporting and Subdomain Policies
A manual review of public DNS records across 254 prominent Russian domains from 17 sectors found strong baseline adoption of email authentication mechanisms. MX records appeared in 96.1% of domains, SPF in 93.7%, DMARC in 89.0%, and DKIM records via common selectors in 62.2%. Among domains with DMARC, 40.7% published a reject policy and 42.9% used quarantine, while 16.4% remained at none. Notably, 19% of DMARC-enabled domains lacked any rua address for aggregate reports, including 33 domains enforcing reject or quarantine. The study also identified cases of inconsistent policies between parent domains and subdomains, as well as SPF records ending in ~all paired with strict DMARC settings. Researchers emphasized that DNS data alone cannot confirm actual mail flow alignment or report consumption.
Server Outage Halts Vehicle Registration Across Smolensk Region
A technical failure on a unified server has temporarily suspended vehicle registration services in the Smolensk region of Russia. The outage affects the interdistrict traffic police department No.1 located on Lavochkina street, preventing new registrations from being processed. Regional UMVD officials confirmed that the problem impacts the single server used for the entire oblast's registration system. According to department head Maxim Zykov, the disruption is considered temporary, though no precise restoration timeline was provided. Applicants who submitted requests through the Gosuslugi portal will receive services in the first working days after the system is restored. The UMVD plans to issue an additional announcement once operations resume.