Habr•August 20, 2026•🇷🇺Translated from Russian

Positive Technologies Wraps Up Third Positive Hack Camp with 81 Students from 20 Countries

Positive Technologies has concluded the third edition of Positive Hack Camp, its annual international cybersecurity and white hacking camp held in Moscow. More than 80 beginning specialists from 20 countries participated in the two-week intensive program organized by Positive Education with support from the Ministry of Digital Development of Russia.

Selection and Participants

Applications opened in February, attracting over 800 submissions from students worldwide. After interviews assessing skills and motivation, 81 participants from countries including Egypt, India, Indonesia, China, Malaysia, and other nations across Southeast Asia, the Middle East, Africa, and Latin America received invitations. All participants covered their own travel costs.

Program Goals

The camp seeks to train professionals who can strengthen cyber resilience and digital sovereignty in their home countries. It also aims to unite the international white hacker community. Success stories from prior years include three 2025 participants from Algeria who joined Deeptech Innovation Hub at the national research center CERIST and now contribute to Algeria’s cybersecurity initiatives.

Training Curriculum

Classes ran from early morning until evening throughout late July. Topics included modeling attacks on IT infrastructure, analyzing network traffic protection, privilege escalation techniques in web applications, operating system security fundamentals, and reverse engineering of complex devices. Experts such as Alexander Popov, Egor Tishin, Dmitry Sokolov, and Ksenia Naumova led sessions, alongside Lebanese white hackers Hussein Daher and Mohammed Daher, who have collectively discovered over 2,000 vulnerabilities on major bug bounty platforms.

In total, instructors delivered 30 practical sessions based on real attack scenarios. Students completed a final examination to consolidate their skills.

Cultural Activities

Evenings and weekends featured a screening of the film “How to Get Access to Everything: Reverse Engineering,” a master class on making pelmeni, a nighttime cruise on the Moscow River, and a Counter-Strike tournament.

Results

On August 7, all participants successfully passed the exam and received diplomas. Organizers expressed confidence that the training will support the students’ future careers in protecting digital infrastructure worldwide.

Related articles

Securitylab•Other

Pivoting in Legacy Hell: Navigating MIPS Servers, BusyBox, and 2014 Kernels During Internal Network Assessments

The article details a complete methodology for pivoting from an initial SSH compromise on an old Debian MIPS server to reach a hidden web admin panel inside a segmented network. It covers environment enumeration with commands like uname -a and ip route, followed by setting up a Chisel-based SOCKS5 proxy when standard SSH dynamic forwarding is disabled by server configuration. Scanning proceeds via proxychains with nmap using -sT, -Pn, and -n flags or by deploying static MIPS binaries directly on the host. Traffic is then routed through Burp Suite chained to the SOCKS proxy for password guessing against the web interface. The piece emphasizes practical constraints such as BusyBox limitations, kernel version incompatibilities with modern binaries, and the need for careful subnet identification. Readers are directed to replicate the full chain in the Forgotten Server task from the free White Hacker Profession course.

Securitylab•Other

Neuromorphic Processors Deliver Reflex-Like Responses for Robots, Drones and Edge Sensors

Neuromorphic chips are optimized for sparse, event-driven data rather than dense matrix operations, making them ideal for always-on peripheral devices that must react instantly while conserving power. The technology pairs naturally with event cameras and temporal sensors in robotics, drones, automotive systems, medical wearables, industrial monitoring and space applications. Platforms such as Intel Loihi 2, BrainChip Akida, SynSense Speck and SpiNNaker2 already demonstrate working prototypes that activate only on meaningful changes in the input stream. Researchers at TU Delft have flown autonomous drones using spiking networks on Loihi, while NASA has tested radiation-tolerant neuromorphic designs for onboard decision making. The approach complements rather than replaces GPUs and NPUs, creating hybrid systems where the neuromorphic layer handles fast reflexes and conventional accelerators manage complex models.

Habr•Other

K2 Cloud Adds Native OVN Traffic Mirroring for NTA/NDR Deployment in Public Cloud

K2 Cloud has implemented traffic mirroring for virtual machine interfaces inside overlay networks built on OVN, solving a long-standing gap that prevented NTA/NDR systems from operating in Russian public clouds. The company contributed the feature upstream, and the patch was accepted into the main OVN codebase. The solution supports source, destination, and mirroring session objects together with optional match/action filters that eliminate duplicate packets, reduce load on sensors, and allow traffic distribution across multiple analyzers. Testing with Positive Technologies PT NAD showed sustained throughput above 3 Gbit/s with approximately 400 000 packets per second and minimal packet loss. The feature works inside a single availability zone; multi-AZ deployments require one PT NAD sensor per zone. Management is available through the web console, an EC2-compatible API, and the official Terraform provider.

Securitylab•Other

Bitrix24 Introduces Cowork/Code AI Agent for Corporate Task Automation and App Building

Bitrix24 has launched Cowork/Code, an AI application that combines file management, company data access, and application development inside a controlled corporate environment. The tool features an AI agent capable of executing multi-step workflows such as locating records, comparing documents, generating tables, and saving results to shared folders. It operates in two modes: Cowork for one-time tasks like overdue task reports or client preparation, and Code for creating reusable tools such as dashboards or notification bots. A memory technology called Radiant stores context from chats, tasks, meetings, and employee data to deliver more accurate, personalized responses over time. The platform addresses common risks of vibe coding by keeping code, data access, and distribution within the Bitrix24 ecosystem hosted on Russian infrastructure. A free tier provides limited usage, with paid plans required for sustained team operation.