Russia's Rassvet LEO Satellite System Enters Real-World Testing Phase
Russia's low-orbit satellite system Rassvet has exited the laboratory and entered real-world operations. Bureau 1440, a subsidiary of IKS Holding, has started testing its satellite internet service with actual consumers in various regions of the country.
The first user terminal has already been installed on a long-distance train operated by Russian Railways. Alexey Shelobkov, CEO of IKS Holding and head of Bureau 1440, announced the milestone at the Eastern Economic Forum.
According to Shelobkov, the project transitioned from research to service validation in 2026, ahead of the original timeline. The company will now evaluate how the satellite connection performs across vast territories and while in motion. Testing on the Russian Railways train is scheduled to begin within days or weeks.
Rassvet is being developed as a domestic low-Earth orbit constellation designed for high-speed data transmission. Its goals include connecting remote regions, narrowing the digital divide, and establishing a sovereign Russian hybrid communications infrastructure.
Shelobkov stressed that the project should not be viewed solely as a counterpart to Starlink. Satellite internet is becoming a core technology and future communications standard, making independent Russian infrastructure essential to avoid reliance on foreign satellites, terminals, and external policy decisions.
In parallel, Roscosmos plans to expand cooperation with private companies in the space sector. Space has evolved from a domain of symbolic launches into routine business infrastructure, Shelobkov noted.
Related articles
Secure Custom Domain Setup for Client Status Pages Using CNAME, Certbot and Go Instead of ACME On-Demand
A detailed case study describes how a monitoring service implemented white-label status pages on customer domains without relying on ACME on-demand certificate issuance. The approach uses pre-validated domains stored in a database, background DNS checks via CNAME or A-record matching, and a root helper script running on a systemd timer to handle certbot issuance and nginx configuration. Key design choices separate privileges so the Go application never touches certificates or nginx directly, while loopback endpoints are protected against proxy header spoofing. The solution explicitly addresses risks such as DoS through malicious Host headers exhausting Let's Encrypt rate limits, private key exposure, and first-visitor latency during TLS handshakes. Hysteresis in DNS status prevents temporary resolution glitches from disabling active customer pages. The entire implementation stays under a few hundred lines of code and runs reliably on a single server with nginx in front of the Go application.
Durev VPN Accused of Plagiarizing Independent Researchers' Articles for Commercial YouTube Promotion
Independent Russian cybersecurity researcher zarazaexe has publicly accused the commercial VPN service Durev VPN of systematically copying technical articles about Russian internet censorship systems, messenger analysis, and government-issued certificates. The team behind Durev VPN allegedly rewrote the original research into YouTube video scripts, replaced first-person statements with references to their own specialists, and removed all attribution to the source author or project. One video titled СРОЧНО УДАЛИ СЕРТИФИКАТ МИНЦИФРЫ reportedly gained 795,000 views in two days, while the service's Telegram bot shows 260,000 users and charges a minimum subscription of 313 rubles per month. Specific copied elements include scanning results of 46 million Russian IP addresses that yielded 63,000 entries in TSPU whitelists, architectural descriptions of default-deny and fail-closed policies, ECH handling by DPI systems, and detailed reverse-engineering findings from the MAX messenger client. The researcher documented the reuse of his earlier errors about UDP blocking inside whitelists and identical analogies comparing root certificates to apartment keys. When confronted, the Durev VPN representative initially demanded patents, invoked fair use, and later claimed the matter would be reviewed by their lawyer within a week. The researcher published the full chat logs and removed the disputed segment from one video after the complaint.
Putin Calls Rumors of Russian Bank Deposit Freeze 'Stupid Fakes'
Russian President Vladimir Putin dismissed rumors about a possible freeze on citizens' bank deposits, describing them as rather stupid fakes during a plenary session at the Eastern Economic Forum on September 3. He stated that there are no grounds for such concerns and recalled the events of 2022 when citizens rushed to withdraw funds amid anxious sentiments. The financial system handled the situation without closing cash desks, allowing all requested amounts to be disbursed calmly. Putin emphasized that Russians continue to keep money in the financial system and are increasingly directing it to the stock market. According to the Central Bank of Russia, net inflows to private investors' brokerage accounts in the second quarter of 2026 exceeded 1 trillion rubles, marking a 19% increase from the previous quarter and a record since observations began in 2021.
Building a Cybersecurity News Aggregator: Story Clustering, Seven Importance Signals and Strict Filtering Thresholds
The idea for an information security news aggregator emerged years ago with the goal of delivering only the most relevant stories while eliminating noise. Early versions relied on the rut5_base_sum_gazeta summarization model and TextRank for importance scoring, but performance remained unsatisfactory. The current system processes roughly one thousand items daily from more than 200 sources and publishes only about 0.5 percent of them. A hybrid approach now combines a transparent seven-feature formula that scores story importance with an LLM that removes irrelevant content and generates concise summaries. The formula incorporates signals such as confirmation count, CVSS severity, exploitation status from KEV, source tier, proximity to Russian readers, depth of analysis, and publication speed. Penalties are applied for vendor self-promotion, webinars, and job postings. Stories are clustered using CVE identifiers, shared trigrams, and named entities to avoid duplicate posts while preserving original reporting.