AntiMalwareAugust 26, 2026🇷🇺Translated from Russian

Aeroflot to Accept Digital Rubles for Ticket Purchases Starting September 2026

Aeroflot will begin accepting digital rubles for the purchase of airline tickets starting 1 September 2026. The new payment option will be available both on the carrier’s website and at its own sales offices across Russia.

When buying a ticket online, passengers will be offered the choice “Digital ruble”. The site will then generate a QR code that must be scanned inside a bank application supporting the new form of currency. After confirmation, funds are debited from the digital wallet on the Bank of Russia platform and the ticket is issued with an electronic receipt sent to the customer’s email.

The process closely resembles payments made through the Fast Payments System (SBP) and does not require passengers to carry any physical form of digital cash to the airport. At Aeroflot ticket offices the same QR-code mechanism will appear on the cashier terminal for the customer to scan and authorise.

To use the service travellers must open a digital wallet with a bank already connected to the Bank of Russia digital-ruble platform. Existing bank cards and other payment methods will continue to be accepted without change.

On the same date MTS will begin accepting digital rubles for services linked to MTS Pay. Rostelecom and Megafon have also confirmed they are preparing their systems for the new currency. Authorities have reiterated that the digital ruble is not a cryptocurrency but the third official form of the Russian national currency alongside cash and non-cash money.

Related articles

AntiMalwareOther

Russia Permits 5G Deployment on Existing 4G Infrastructure and Frequencies

The Russian Ministry of Digital Development has prepared a draft decision for the State Radio Frequency Commission that introduces technological neutrality for mobile networks. Major operators including Beeline, Megafon, MTS and Tele2 will be allowed to launch 5G services on spectrum and base stations already allocated for LTE. The measure covers foreign equipment installed before September 2026 and aims to accelerate commercial 5G rollout without waiting for entirely new infrastructure. Additional spectrum in the 4.63-4.99 GHz band will be allocated for high-capacity use cases, although these frequencies offer limited coverage. Commercial 5G services must appear in cities with over one million residents by the end of 2027, with gradual expansion through 2031. Domestic base stations are scheduled to replace foreign equipment between 2027 and 2031.

SecuritylabOther

Grep_Tribe Blue Team Shares SOC Defense Lessons from Standoff 17 Cyber Battle

The Grep_Tribe team participated in Standoff 17 for the third time, defending the RetailSTF Group infrastructure in a simulated State F environment against continuous red team attacks. They handled 37 confirmed incidents, 22 detected incidents, five investigated critical events, and maintained 88 percent average infrastructure availability. The team used familiar Positive Technologies tools alongside the new R-Vision SOAR platform to automate routine responses such as IP blocking and file sandboxing. Work was organized through a tribal system with role-based preparation and dynamic small-group investigations for complex attack chains. Participants highlighted how the event tested prioritization, Threat Intelligence attribution, and automation under high-intensity conditions unlike daily SOC operations. The experience reinforced plans to expand SOAR playbooks for repetitive tasks in their real internal SOC environment.

HabrOther

Password Reset Fails to Evict Attackers: What Persists in Compromised Email Accounts

Even after users change passwords and enable two-factor authentication, attackers often retain access through active sessions, application tokens, and forwarding rules. The original password serves only as an entry point, while already-issued session cookies, refresh tokens, and app passwords continue functioning independently. Services like Google, Microsoft, and Yandex provide specific pages to review devices, permissions, and app passwords, yet many users overlook the critical "sign out all devices" option. In corporate environments, Microsoft Entra ID commands can revoke sessions, but access tokens may still remain valid for up to an hour afterward. Attackers frequently replace recovery details and set up mail delegation or hidden forwarding rules to maintain long-term control. The recommended sequence prioritizes session revocation first, followed by password change, MFA review, and recovery data verification to prevent re-entry via forgotten-password flows.

AntiMalwareOther

86% of Large Russian Companies Use or Pilot LLMs While Autonomous AI Agents Remain Rare in Production

A joint study by Infosystems Jet and Smart Ranking reveals that 86% of major Russian organizations are already deploying or testing large language models, with 53% having moved generative AI solutions into full production. Adoption drops sharply for more autonomous systems: only 15% run semi-autonomous AI agents in production, while fully autonomous and multi-agent setups reach just 8% each. The primary barriers are not model availability but insufficient process maturity, data infrastructure readiness, and integration complexity, cited by 44% of respondents. Additional obstacles include server costs (58%), legal risks (56%), budget limits (42%), and talent shortages (40%). Nearly half of surveyed companies report no measurable financial return from AI projects so far, highlighting the gap between pilot success and scalable value. The research covered 52 large firms employing roughly 450,000 people in total.