HabrSeptember 4, 2026🇷🇺Translated from Russian

OTUS Publishes September Digest of Free Lessons on Linux Administration, PostgreSQL, CI/CD and Infrastructure Security

OTUS has published its September digest of free lessons for engineers responsible for infrastructure, covering Linux, databases, CI/CD and security topics.

The company offers practicing specialists an opportunity to attend online sessions led by current instructors who demonstrate technologies on real production cases.

Administration of Linux and servers

  • 7 September 20:00 – Linux for Windows administrators in 60 minutes
  • 17 September 20:00 – Where Linux stores settings and logs: practical analysis of the file system structure
  • 21 September 20:00 – Typical tasks with RAID arrays: creation, operation, data migration and recovery
  • 22 September 20:00 – Top GPO policies that will help you
  • 24 September 19:00 – Can AI fix a Linux server: where hints end and engineering diagnostics begin

Performance, databases and high availability

  • 8 September 20:00 – Fighting locks in PostgreSQL: achieving high concurrency under heavy load
  • 8 September 20:00 – LVM without downtime: volume expansion, data migration and emergency rollback via snapshot
  • 23 September 20:00 – Using Patroni to manage highly available PostgreSQL clusters
  • 23 September 20:00 – eBPF: X-ray vision for production

Infrastructure automation and DevOps

  • 10 September 20:00 – Setting up GitLab Runners
  • 17 September 20:00 – Release management in 1C: GitFlow, code review and CI/CD in practice (pre-recorded webinar)
  • 9 September 20:00 – Go profiling: how to find and fix bottlenecks in production

Infrastructure security

  • 22 September 20:00 – Automating traffic management with mitmproxy
  • 22 September 20:00 – Can AI-generated code be trusted: finding hallucinations, vulnerabilities and outdated solutions

AI in the work of an engineer

  • 8 September 20:00 – AI versus bugs: how to analyze an incident in a Python project from logs to fix
  • 21 September 20:00 – One working day with AI: from emails and tables to a ready presentation for management

Related topics for engineer growth

  • 8 September 20:00 – From technical leader to CTO: how to start making business-level decisions
  • 9 September 20:00 – How a team lead can distribute responsibility without becoming a bottleneck

Related articles

AntiMalwareOther

Top LLMs Misidentify Poisonous Mushrooms in Every Ninth Case, Benchmark Shows

Polish developer Piotr Migdal evaluated leading large language models on their ability to identify mushrooms from photographs, using a dataset of 1040 images covering 55 species common in Poland. The images came from the FungiTastic dataset derived from the Atlas of Danish Fungi, with expert labels and partial DNA confirmation. Models were asked to return the five most likely species names in Latin without additional training or tools. Gemini 3.8 Flash performed best with 65 percent top-1 accuracy and 85 percent top-5 accuracy, followed closely by other Gemini variants. However, safety-critical errors remained high: Gemini models labeled poisonous mushrooms as edible in roughly 11 percent of cases, while GPT-5.6 Sol reached 24 percent, Claude Opus 5 reached 29 percent, and Qwen 3.8 27B reached 36 percent. The study did not ask models directly whether a mushroom was edible; species identifications were later cross-checked against toxicity tables.

SecuritylabOther

September 2026 AI Model Rankings: Fable 5.1 Tops Intelligence Index as Competition Tightens Across GPT-5.6 Sol, Grok 4.6 and Muse Spark 1.3

The beginning of September 2026 marked a rare moment when the list of top language models had to be almost entirely rewritten. Anthropic released Fable 5.1 and the limited Mythos 5.1, while Meta updated Muse Spark to version 1.3, Google introduced Gemini 3.8 Flash, and Alibaba refreshed Qwen3.8-Max. Existing models including GPT-5.6 Sol, Grok 4.6, Kimi K3, GLM-5.3 and DeepSeek V4 Pro remain competitive. Traditional rankings from smartest to least capable have become difficult because modern models operate in multiple reasoning-depth modes where low, high and max settings can differ by ten or more points on the same test. The market is better viewed as several overlapping races where Fable 5.1 leads in complex reasoning quality, GPT-5.6 Sol and Grok 4.6 deliver near-top performance at lower cost, and Muse Spark 1.3 excels in price-performance. Independent Artificial Analysis Intelligence Index scores, context windows, API pricing and tool-use capabilities now determine practical choices more than raw benchmark numbers.

AntiMalwareOther

InfoWatch Acquires Web Control DC Team and Rebrands sPACE PAM as InfoWatch Privilege Control

InfoWatch has expanded its product portfolio by incorporating the Web Control DC development team and rebranding its flagship sPACE PAM solution. The new product, InfoWatch Privilege Control, is designed to manage and monitor privileged accounts belonging to system administrators, contractors, external specialists, and business users. These accounts provide access to servers, databases, network equipment, and critical applications, making them high-value targets for attackers. According to InfoWatch data, approximately 40% of critical information security incidents in Russia in 2025 were linked to the leakage or misuse of privileged credentials, while another 30% of confirmed cyberattacks occurred through compromised IT contractors. The solution enables time-limited privilege issuance, connection management, and detailed activity logging to prevent unauthorized actions. The original sPACE PAM product remains listed in the Russian software registry and holds FSTEC Russia certification at the fourth trust level, with compatibility for Astra Linux, Alt, and RED OS operating systems.

HabrOther

Secure Custom Domain Setup for Client Status Pages Using CNAME, Certbot and Go Instead of ACME On-Demand

A detailed case study describes how a monitoring service implemented white-label status pages on customer domains without relying on ACME on-demand certificate issuance. The approach uses pre-validated domains stored in a database, background DNS checks via CNAME or A-record matching, and a root helper script running on a systemd timer to handle certbot issuance and nginx configuration. Key design choices separate privileges so the Go application never touches certificates or nginx directly, while loopback endpoints are protected against proxy header spoofing. The solution explicitly addresses risks such as DoS through malicious Host headers exhausting Let's Encrypt rate limits, private key exposure, and first-visitor latency during TLS handshakes. Hysteresis in DNS status prevents temporary resolution glitches from disabling active customer pages. The entire implementation stays under a few hundred lines of code and runs reliably on a single server with nginx in front of the Go application.