Policy & Regulation

Cybersecurity news in this category

๐Ÿ‡ท๐Ÿ‡บAug 22

Why Legitimate Russian Websites Fail to Load With or Without VPN: TSPU RKN Blocking and MinTsifry Certificates Explained

Russian internet users are experiencing widespread access issues to legitimate domestic websites both when using VPNs and when connecting directly. The problems stem from TSPU devices installed by all ISPs under Roskomnadzor requirements and the transition to national MinTsifry certificates that foreign browsers do not trust. Three distinct error scenarios are documented: ERR_CONNECTION_TIMED_OUT when accessing Russian-IP sites over VPN, ERR_CERT_AUTHORITY_INVALID on major bank sites without VPN, and partial page loading failures caused by TSPU fingerprinting. Solutions for ordinary users include split-tunneling VPN clients, installing MinTsifry root certificates, or switching to Yandex Browser and Chromium-Gost. Website owners are advised to disable TLS 1.3, enable HTTP/2 support, and consider changing server IP addresses if SSH connections are also blocked. The article explicitly excludes any discussion of circumvention methods for prohibited content and focuses only on legal Russian resources as of August 2026.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 21

Smart Homes on Pause: Why Digital Systems in New Buildings Fail After Three Years

Modern residential complexes increasingly rely on digital infrastructure, yet many smart home systems stop functioning properly within three years of commissioning. The root causes lie in decisions made during the design phase rather than after handover. Marketing-driven features often lack any sustainable operational model, leading to disappearing services once the warranty period ends. A fragmented vendor landscape, missing documentation, and absent ownership further accelerate degradation. Cybersecurity risks grow when updates and monitoring are neglected, turning buildings into easy targets. The article outlines how to build resilient systems that remain functional for 10โ€“20 years by focusing on total cost of ownership, open standards, and clear responsibility frameworks.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 21

Rospotrebnadzor and FAS to Extend Oversight to Websites: Automating Foreign Word Replacement Using LLM

Russian compliance experts have developed a specialized microservice called Normograph that combines multi-stage filtering, OCR, and LLM processing to help organizations meet the requirements of Federal Law 168-FZ on protecting the Russian language. The system automatically identifies prohibited foreign borrowings and Latin script on websites, cross-references them against official dictionaries approved by the Russian Academy of Sciences, and suggests context-aware Russian replacements while preserving marketing meaning and grammatical agreement. It excludes registered trademarks, brand names, and terms without Russian equivalents using dynamic white lists and Rospatent data. The solution processes pages up to 20 times faster than manual review by filtering out already-compliant words before sending only problematic fragments to the language model. An OCR module based on Yandex Cloud Vision extends checks to images and banners. The service was built with GigaChat API but remains provider-agnostic and avoids sending full pages or confidential data to foreign AI services.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 21

T-Bank Masks New iOS Banking App as K8CHEN PRO to Bypass Sanctions

T-Bank has released a new version of its mobile banking application for iPhone users that appears in the App Store under the neutral name K8CHEN PRO. After installation and user authentication, the app automatically renames itself to 8PRO. The application is currently available for download in the Russian, Kazakh, Turkish, Georgian, and American App Store regions. T-Bank confirms the legitimacy of the release through a direct link published on its official website. The disguise is a direct response to repeated removals of official Russian financial apps from the App Store following the introduction of sanctions. Users are strongly advised to obtain the app exclusively via the official site link rather than searching the store, as fraudsters frequently clone banking applications to steal credentials.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 20

Separating Identity and Delivery Channels for Compliant Telegram Mini App Authentication

A developer shared a detailed case study on building legally compliant user identification for Telegram Mini Apps targeting Russian audiences. Instead of relying solely on Telegram initData verification, the project routes authentication through established Russian providers including VK ID, Yandex ID and MAX. Identity is handled separately from message delivery channels, with telegram_id used only for notifications after account creation. The implementation employs OAuth 2.1 with PKCE for VK, OAuth 2.0 for Yandex, and deep links for MAX while enforcing short-lived cryptographic state values and HttpOnly session cookies. Additional measures include consent checkboxes required by Russian law and polling-based result delivery to support browser, WebView and extension environments. The same architecture was reused for Home Assistant smart-home login, demonstrating reusable separation of identity and channel concerns.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 20

FSTEC Publishes 35-Point Network Perimeter Recommendations, Most Require No Spending

Russia's FSTEC released non-binding recommendations on protecting network perimeters on March 10, 2026, analyzing real-world intrusion vectors from external networks. The 35-point checklist spans eight sections covering device administration, DDoS resilience, segmentation, configuration backups, vulnerability management, authentication, logging, and incident response exercises. Only four items explicitly require purchasing new tools such as WAF, ZTNA, NAC, and SIEM, while five others depend on existing infrastructure. Twenty-six points can be addressed through policy, inventory, and configuration changes alone, including enforcing unique passwords, disabling legacy protocols like HTTP and SNMP v1/v2, and quarterly backup restoration tests. The document references Order 117 and earlier FSTEC methodologies on vulnerability handling, serving as a practical self-assessment questionnaire rather than a mandatory regulation. Analysts note that many organizations still fail to implement low-cost measures such as excluding remote administration interfaces from DMZ zones and verifying backup recoverability.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 19

Compliant Telegram Mini App Authentication via Russian ID Providers in My Anti-Social Network Project

The project 'My Anti-Social Network' demonstrates a production-grade approach to Telegram Mini App authorization that meets Russian identification requirements by separating user identity from delivery channels. Instead of relying solely on Telegram initData verification, the system routes authentication through VK ID, Yandex ID, and MAX using OAuth 2.0 / 2.1 flows with PKCE. Sensitive tokens never reach the browser; the client receives only short-lived one-time codes exchanged for HttpOnly session cookies. The architecture supports multiple front-ends including PWA, browser extensions, and Home Assistant integration while maintaining cryptographic protections around state parameters and code verifiers. The solution was implemented for an aggregator delivering personalized news feeds through Telegram, MAX, VK bots, and voice assistants.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 19

Asset Management as the Foundation of Vulnerability Management: Unknown Assets Cannot Be Protected

The article explains that asset management forms the essential base for any effective vulnerability management program, as organizations cannot protect systems they do not know exist. It details multiple data sources including SIEM, NTA/NDR, Active Directory, CMDB, virtualization platforms, and cloud APIs that must be combined to build a complete inventory. Key record fields such as asset criticality, responsible owner, and last successful scan date are highlighted as critical for prioritization and SLA compliance. The piece examines new Russian regulations including FSTEC Order No. 117 and Federal Law No. 58-FZ that mandate accurate asset inventories to meet monthly scanning and 24-hour critical patch requirements. International frameworks such as CIS Controls v8.1, NIST CSF 2.0, and ISO/IEC 27001:2022 are compared, emphasizing lifecycle management and reaction processes for unauthorized assets. Emerging asset types including cloud resources, SaaS services, AI systems, containers, and IoT devices are discussed as expanding the attack surface faster than organizations can track.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 17

Ozon Data Security Team Details Audit Framework to Eliminate Paper-Only Compliance

Alena, head of the Data Security group at Ozon, describes how the company built an internal audit process that focuses on actual risk reduction instead of producing lengthy formal reports. The team examines personal data, financial records, and other sensitive information across hundreds of microservices while checking role-based access, logging, encryption, and data flows. They analyzed more than 84,000 user-role pairs in one review and identified overly broad permissions on product tagging that could cause major financial losses. A notable case led to the removal of customer names, phones, and addresses from delivery boxes even though the practice was formally allowed under Federal Law 152-FZ. The group uses a scoring model based on data sensitivity, business importance, user count, and potential monetary impact to prioritize which systems to audit first. Additional criteria such as past incidents and critical information infrastructure status can be added to the model. The approach emphasizes real implementation of recommendations, cross-team communication, and hiring analysts who care deeply about practical security outcomes.

Habr
๐Ÿ‡ต๐Ÿ‡นAug 17

Microsoft to Make Passkeys Default Authentication in Entra ID Starting September 2026

Microsoft will transition Entra ID users to passkeys as the standard authentication method beginning September 1, 2026. The change aims to eliminate reliance on phishing-prone SMS and voice call codes. Existing SMS and voice users will be prompted to register passkeys during their next multifactor authentication. Passkeys rely on public-key cryptography and avoid shared secrets, blocking phishing, interception, credential reuse, and SIM swapping attacks. Support includes synced passkeys via iCloud Keychain and Google Password Manager, plus device-bound options like Microsoft Authenticator, Windows, and FIDO2 hardware keys. Native SMS and voice services will be fully retired on February 1, 2027, forcing affected tenants to adopt passkeys with no opt-out option.

BoletimSec
๐Ÿ‡ท๐Ÿ‡บAug 17

Russian Ministry of Transport Unveils Draft Rules for Centralized Passenger Data with Unique Per-Trip IDs

The Russian Ministry of Transport has published a draft regulation expanding centralized databases of passenger and crew personal data. Each traveler and crew member will receive a unique identifier generated separately for every flight or trip that cannot be reused or reassigned. The rules add new mandatory data points including cancellations of boarding, online check-ins, and changes to group tickets. Data must be transmitted within 15 minutes for air and rail tickets and 30 minutes for other modes, with crew details submitted at least 24 hours before departure. Retention remains fixed at seven years. The order, if adopted, will replace the 2024 rules and is open for public comment until 29 August with an intended effective date of 1 March 2027.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 15

Multiple Ozon Apps Removed from Google Play Following Sanctions on Ozon Bank

Several Ozon applications have been removed from the Google Play store, affecting Android users who can no longer download the main Ozon client along with Ozon Fresh, Ozon Seller, Ozon Job and Ozon Travel. Ozon stated that the company did not violate Google Play rules, yet the exact reasons for the removals remain undisclosed. The action follows the earlier disappearance of the Ozon Bank app after the bank was placed under European Union sanctions, although no official connection has been confirmed. Apple users continue to access Ozon services through the App Store, while Android users are directed to alternative stores including RuStore, AppGallery and Galaxy Store. The company also warned against downloading APK files from unverified sources due to security risks. The removals come amid a broader wave of app store purges that also affected Yandex Pay on the App Store. Already installed applications generally continue to function, but users may face difficulties with future updates and reinstalls.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 14

Ruthenium: Custom Chromium Build for Android Adds Russian Trusted Root CA Support

A developer has released Ruthenium, a modified Chromium browser for Android that embeds the Russian Trusted Root CA certificate issued by the Ministry of Digital Development. The build restricts trust to .ru and .ั€ั„ domains only, avoiding changes to the system-wide Android certificate store. The project patches four Chromium source files to include the root with DNS constraints via CertWithConstraints, disables Google sign-in by default, and removes XR-related code for successful compilation. Ruthenium uses the official Chromium TLS verification logic without introducing a custom verifier. The APK is distributed with SHA-256 checksums, build metadata, and reproducible release tags tied to the exact Chromium revision and certificate digest. Users can install it alongside stock Chrome and use it selectively for Russian government and banking sites that rely on the state root.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 14

US Federal Judge Orders Google to Simplify Installation of Third-Party App Stores on Android

A federal judge has directed Google to remove extra warnings and confirmation steps when users install competing app stores through Google Play on Android devices. The ruling stems from the ongoing antitrust litigation between Epic Games and Google, where a jury previously found that Google illegally maintained a monopoly over Android app distribution and in-app payments. Judge James Donato criticized the current multi-screen process as an intentional barrier designed to discourage ordinary users from choosing alternatives. Google must implement the changes within one week, making the installation of third-party stores as straightforward as any other Android application. The decision acknowledges that while Android has long permitted sideloading, the layered security prompts and hidden permission toggles effectively steered most users back to Google Play. Aptoide has already appeared in the US Google Play store as the first third-party marketplace to benefit from the eased process. Google argued the warnings protect users from malware, but the court rejected the notion that security should serve as a shield for market dominance.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 14

Why Russia Needs Specialized Circumvention Tools Beyond Standard VPNs

The developers of Tunnel Kitten explain why another circumvention project is necessary despite the availability of numerous VPN services and solutions like AmneziaWG. A prolonged outage affected many long-term users, damaging trust and requiring ongoing fixes. Standard VPNs do not address the core issue: creating and maintaining tools to bypass internet blocks has been criminalized in Russia. This legal asymmetry makes public VPN services and self-hosted solutions risky or insufficient for users facing state-level censorship. Tunnel Kitten positions itself as a project focused on a different task that accounts for these legal realities. The team emphasizes that the problem is not merely technical but tied to the criminalization of circumvention efforts.

Habr
๐Ÿ‡ต๐Ÿ‡นAug 13

US Presidential Memo Authorizes Selected Private Companies to Join Federal Cyber Operations Against Foreign Criminal Groups

The United States government has established a formal program allowing vetted private-sector companies to participate in offensive cyber operations targeting foreign criminal organizations. Signed by President Donald Trump on August 12, 2026, the presidential memorandum places the initiative under the National Coordination Center with joint oversight from the Department of Justice and the Department of Homeland Security. Participating firms will operate exclusively under government contracts, direction, and supervision, with strict requirements including technical evaluations, financial guarantees of at least one million dollars, and pre-approval for every operation. The program focuses on disrupting ransomware, phishing, financial fraud, and other schemes affecting American citizens while imposing clear limits to prevent unintended harm to US persons or escalation to prohibited levels of force. In contrast to Brazilโ€™s ongoing policy discussions, the US move formally recognizes that advanced offensive capabilities now reside primarily in the private sector and creates a regulated mechanism to access them. Operational rules must be published within 60 days, marking a significant shift in how governments integrate private expertise into state-directed cyber actions.

BoletimSec
๐Ÿ‡ท๐Ÿ‡บAug 13

Russia to Require Independent Lab Testing of Sovereign AI Models for Legal and Traditional Values Compliance

The Russian Ministry of Digital Development is discussing a certification scheme under which developers can submit large generative AI models to accredited independent laboratories. These labs will verify compliance with Russian legislation and traditional spiritual-moral values defined in presidential decree No. 809. Only models seeking official national or sovereign status, which unlocks state support, data access and priority procurement, will undergo the process. Developers must first conduct self-testing according to a risk-oriented methodology and supply architecture details, filtering mechanisms and other documentation. Accredited laboratories will then run benchmarks, attempt prompt-injection attacks and produce evaluation reports, while the final decision remains with MinTsifry. Separate security assessments for government systems will be performed by the FSB and FSTEC Russia. Experts have called for transparent, reproducible tests and periodic re-certification after model updates.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 12

Why Separate Corporate and Personal Email Accounts: Risks of Mixing Work and Private Communications

Mixing corporate and personal email accounts creates serious security, compliance, and operational risks for both employees and organizations. When employees forward contracts or client data to personal mailboxes to bypass size limits or convenience, copies proliferate beyond company control in phones, backups, and cloud services. After termination, the employer loses any ability to revoke access or audit the data, while personal accounts often lack multi-factor authentication and strong password practices. Russian legislation including Federal Law No. 152-FZ on personal data, the Labor Code, and Federal Law No. 98-FZ on trade secrets requires proper protection of sensitive information. Using work email for shopping, banking, or password recovery exposes the corporate domain to phishing and leaks, while the reverse creates dependency on private accounts for business continuity. The recommended practice is strict separation with unique passwords, MFA on both accounts, and approved corporate channels for file transfer.

Securitylab
๐Ÿ‡ท๐Ÿ‡บAug 12

Yandex Pay App Permanently Removed from App Store Across All Regions Due to Sanctions

The Yandex Pay application has been fully removed from the App Store in every region worldwide. Existing installations continue to operate normally, and the company has confirmed that all client funds remain secure. However, users can no longer download the app or receive updates, prompting Apple device owners to avoid deleting the application. Yandex recommends disabling automatic app updates through iOS settings to prevent any potential loss of functionality. If the app is accidentally removed, the service remains accessible through the web version at pay.yandex.ru, which can be added to the home screen via Safari. The removal occurs amid broader sanctions and information-related restrictions affecting Russian technology services.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 11

NSPK Warns of Potential Online Payment Disruptions for Visa and Mastercard Holders Due to Russian Certificate Transition

The National System of Payment Cards (NSPK) has issued a warning that holders of Russian-issued Visa and Mastercard cards may encounter difficulties when making online purchases. The issues stem from NSPK's ongoing transition to Russian security certificates required for authenticating internet resources and establishing secure connections. NSPK recommends that users proactively replace their existing cards with Mir-branded alternatives to avoid payment failures at critical moments. The move aligns with broader efforts toward import substitution and ensuring stable access to payment services amid international sanctions imposed on Russia since 2022. Mir cards will remain fully functional for both in-store and online transactions without any changes. Foreign browsers may display security warnings when encountering the new Russian certificates, though NSPK stresses that these alerts do not indicate compromised resources or data leaks. The transition is described as standard practice among Russian organizations and will not affect payment security, data protection, or overall service operations.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 11

Astra Cloud Launches Attested Secure Cloud to Accelerate FSTEC Compliance for Russian Government Systems

Astra Cloud, part of the Astra Group, has introduced a new "Protected Attested Cloud" service designed for hosting state information systems, personal data systems, medical platforms, and other sensitive environments. The infrastructure has received official attestation under FSTEC Russia Order No. 117 for protection class K1 and Order No. 21 for protection level UZ-1. Customers can leverage the pre-certified platform to speed up their own system attestation procedures by three to five times, although each organization's information system must still undergo separate certification. The service includes certified security tools such as firewalls, antivirus solutions, intrusion detection and prevention systems, trusted boot mechanisms, and SIEM, with all connections required through certified cryptographic channels. The cloud is hosted in a Tier IV data center built on domestic hardware and targets organizations that must meet FSTEC requirements without building their own protected infrastructure. From March 2026, Order No. 117 replaces Order No. 17 and extends obligations to subordinate institutions and companies interacting with the state segment, including 24-hour remediation of critical vulnerabilities.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 10

Russia's Ministry of Digital Development to Bind M2M SIM Cards to Devices and Restrict Unauthorized Calls Starting 2027

The Russian Ministry of Digital Development has proposed new regulations requiring companies and individual entrepreneurs to register M2M SIM cards and associated equipment in the ESIA system. The rules, scheduled for launch on September 1, 2027, aim to combat fraud by preventing the misuse of these cards for anonymous calls and mass messaging. Each M2M SIM card will be strictly tied to a specific device, with changes to identifiers allowed only once per month except in cases of loss or damage. Operators will gain access to a unified platform for managing SIM cards, including activation, deactivation, status checks, location tracking via base stations, and service suspension for discrepancies. All relevant data such as owner INN, operator details, equipment type, identifier, and installation address must be submitted through Gosuslugi or operator platforms. Voice calls will be limited to one minute, white lists for contacts can be updated monthly, and mass SMS or auto-dialing will be banned except for authorized senders.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 10

Russia Simplifies State Support Access for National AI Model Developers

Russian authorities have decided to shorten and clarify the path to government support for developers of large AI models. Following the entry into force of the law on artificial intelligence development, obtaining the status of a national or sovereign model will become easier, with decisions verified through a single set of test tasks. The reference test is planned to be published in open access and updated regularly, allowing developers to know in advance the exact criteria the state will use to evaluate their neural networks. Companies such as MWS AI and T-Bank will be able to apply for the new statuses and associated support measures. Expertise will be entrusted to several organizations that have passed state verification, with the main criterion being Russian company control over the entire model lifecycle rather than the origin of every line of code. The use of foreign components under open licenses will be permitted if the developer can independently modify, develop, and maintain the solution. Bureaucratic procedures will be reduced, missing documents can be submitted after the application, and computing infrastructure must be located in Russia but can be rented. The first areas of mandatory application of domestic models will be education and public services, with key provisions of the law taking effect on September 1, 2026, and requirements for sovereign models on March 1, 2027.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 10

EU Extends Chat Control 1.0 Regulation to 2028 Despite Privacy Concerns and Parliamentary Opposition

The EU Council has extended Regulation (EU) 2021/1232, known as Chat Control 1.0, allowing voluntary scanning of unencrypted messages by providers such as Discord and Gmail until 2028. The measure targets detection of child sexual abuse material but has drawn criticism for its impact on encryption and privacy. A proposed Chat Control 2.0 version under COM(2022) 209 would mandate scanning of encrypted communications, which critics argue undermines end-to-end encryption. The extension passed after a July 2026 European Parliament vote failed to reach the required majority due to absent lawmakers. Investigations revealed lobbying ties between Commissioner Ilva Johansson's office and organizations including Thorn and WeProtect Global Alliance. The European Data Protection Supervisor found that targeted advertising supporting the regulation violated EU data rules.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 10

NIST Bans Periodic Password Rotation While Russia's FSTEC Mandates 90-Day Changes for Government Systems

In July 2025, NIST released the final version of SP 800-63B, explicitly prohibiting periodic password changes with the requirement that verifiers and CSPs shall not require subscribers to change passwords periodically. Eight months later, in April 2026, FSTEC approved a methodological document requiring passwords in state information systems and critical information infrastructure to be changed at least every 90 days, with mobile devices limited to 30 days and no reuse of the last 12 passwords. The requirements originate from Order No. 117, which itself contains no mention of passwords, but delegates details to lower-level methodological documents including the April 2026 guide that defines measure IAF.3. Compliance is enforced through the KZI protected indicator calculation submitted to FSTEC twice a year, with penalties including zeroing of the 0.25 weight group for repeated failures and immediate zeroing during penetration testing. The policy applies to government bodies, state unitary enterprises, institutions, and CII subjects, while commercial organizations outside this scope retain flexibility to set their own policies based on threat models. NIST and FSTEC requirements align closely on minimum length, failed attempt limits, MFA for privileged accounts, and prohibition of default passwords, differing primarily on the rotation mandate.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 7

Web Certificate Trust Chains and State Access Risks Explained Amid Russian Banking Sanctions

The article explains the hierarchical structure of web certificates used for site authentication and traffic encryption, starting from highly protected root certificates stored in air-gapped facilities with Shamir's secret sharing for key protection. Intermediate certificates extend the chain of trust down to leaf certificates deployed on websites. Russian banks have turned to certificates issued under the MinTsifry root after Western and Chinese CAs refused service due to sanctions. The piece highlights that any nation-state with access to a root private key, whether FSB, NSA, or others, could theoretically issue fraudulent certificates for any domain. It notes the limitations of the X.509 standard, which lacks native support for multi-CA signatures, and suggests that separate browsing environments or PGP-style web-of-trust models could mitigate risks. The author concludes that security is already reduced by reliance on any state-controlled CA and that the choice is ultimately which intelligence agency one prefers to trust.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 7

MAX Messenger to Open Source Code and Launch Developer Program for Alternative Clients

The Russian messenger MAX is preparing to open its platform to third-party developers by launching a dedicated developer program and providing API access. Approved participants will receive the official client's source code, design system, technical documentation, and access tokens to integrate with the platform infrastructure. The initiative targets IT companies from Russia and friendly countries that demonstrate experience with large-scale projects and adherence to strict security standards. All selected developers must implement secure development practices, robust encryption mechanisms, and undergo code audits to protect user data. The program supplies ready-made user registration and anti-fraud tools, while alternative clients remain bound by API usage terms focused on security compliance. Applications will be accepted via the official developer portal, although exact launch dates have not yet been disclosed.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 6

InfoWatch Details ARMA Wall NGFW Development for Industrial Systems Under Russian Import Substitution Rules

InfoWatch has published the second part of its interview series describing the ongoing development of the ARMA Wall next-generation firewall for industrial control systems. The product prioritizes on-premise processing without cloud agents to meet strict customer security policies and certification requirements. Engineers combine proprietary detection feeds with external sources, including indicators from NKCKI, while maintaining hundreds of thousands of signatures without disabling legacy rules for older Siemens controllers. Migration support relies on manual pre-project audits rather than automated tools, and the company works closely with domestic SCADA vendors to embed NGFW capabilities inside long-lifecycle OT environments. ARMA Wall is positioned as a more flexible and cost-effective alternative to data diodes because it allows granular command-level filtering and can emulate one-way traffic when required. The solution is already deployed at Roscosmos subsidiary RKK Energia after full certification and categorization.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 6

WhatsApp Developing AI Content Labeling Feature for Channel Admins to Meet EU Transparency Rules

WhatsApp, owned by Meta, is rolling out a new function that allows channel administrators to mark posts containing AI-generated or AI-edited media. The feature appears in the latest Android beta and stems directly from European Union requirements for transparency around artificial intelligence content. Administrators can long-press a message after publication and select an option to add an AI content label, which then displays a visible tag informing subscribers that the material was created or modified by neural network tools. The requirement applies specifically to images, videos, and other media files, while generated text remains exempt from mandatory labeling. WABetaInfo researchers spotted the change, noting that the label may become permanent once applied and that the rollout could initially target only jurisdictions with relevant legislation. Broader availability for iOS users and global deployment remain under consideration.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 5

Developer Builds Decentralized Messenger to Navigate Russian Laws 149-FZ and 152-FZ

A solo developer has created a lightweight messenger called Gram using the $mol framework and HyperBaza technology, designed to operate without collecting personal data or requiring logins. The project specifically examines compliance with Russian Federal Laws 149-FZ and 152-FZ, which regulate instant messaging services and personal data processing. The application supports encrypted peer-to-peer messaging, group chats via registries, and proof-of-work spam protection, while running primarily offline with optional decentralized nodes. Because messages remain encrypted on servers and no user identification occurs, the developer argues that obligations under the laws do not apply to private or home use. Public nodes must be shut down to avoid legal requirements such as phone-based identification and six-month message storage. The full source code is available on GitHub, and the service can be forked for deployment outside Russian jurisdiction.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 5

FAS Case Against Apple Will Not Brick iPhones for Russian Users

The Russian Federal Antimonopoly Service (FAS) has opened a case against Apple for failing to pre-install a national messenger and a Russian app store on iOS devices, yet officials have confirmed that no technical measures will disable or restrict existing iPhones. Deputy Chairman of the State Duma Committee on Information Policy Andrey Svintsov stated that the actions of FAS, Roskomnadzor and other agencies are limited to recording violations and collecting fines. Apple had already implemented the option to select a domestic search engine but did not meet the remaining pre-installation requirements. Svintsov emphasized that any court decisions will remain in force until Apple decides to return to the Russian market and settles accumulated penalties. The approach is designed to replenish the state budget through fines once the company resumes legal operations. Russian iPhone owners can continue using their devices without any risk of remote blocking or forced conversion into expensive paperweights.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 5

Yandex Cloud Partners with Sogaz and Ingosstrakh to Automate Cyber Risk Assessment for Business Insurance

Yandex Cloud, through its Yandex B2B Tech division, has launched joint cyber insurance programs with Russian insurers Sogaz and Ingosstrakh. The initiative replaces traditional manual questionnaires with automated infrastructure scanning via the Yandex Security Deck service. The tool examines cloud resources, applications, and data to identify open internal information, excessive user privileges, leak risks, and potential compromise vectors. Detected issues are consolidated in a single prioritized interface and shared with insurers to refine policy terms. If critical gaps are found, Yandex Cloud also provides remediation recommendations. The move comes as demand for cyber insurance grows rapidly, with Sogaz reporting that requested coverage volume doubled year-over-year to exceed 12 billion rubles in the first half of 2026.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 4

Over 20 VPN Services Hit by Outages After Russian Regulators Block Hosting Provider Subnets

Users of multiple VPN services reported widespread connection problems throughout the day as IP addresses belonging to several large hosting providers were placed under restrictions. The blocks targeted infrastructure used by VPNs to reroute traffic around content filters, causing entire ranges of servers to become inaccessible when whole subnets were affected. The Telegram channel Exploit reported that more than 20 VPN services of varying sizes experienced disruptions, though Roskomnadzor has not issued an official statement on the scope or origin of the measures. The affected providers indicated they are shifting customers to backup servers, noting that the restrictions appear selective yet still force frequent address changes during the day. The incidents coincide with ongoing discussions of new rules that would require hosting providers to independently detect and report masked VPN IP addresses to regulators. Similar large-scale subnet blocks occurred in late May, impacting numerous MTProto-based proxies and VPNs simultaneously.

AntiMalware
๐Ÿ‡จ๐Ÿ‡ณAug 4

HackerOne Ends Anonymous Era for Bug Bounty Hunters with Mandatory ID Verification

HackerOne has introduced compulsory identity verification for all researchers submitting reports to paid bug bounty programs, effective August 1. The policy requires users to complete KYC checks through Estonian firm Veriff by uploading government-issued ID and performing a live selfie, with annual renewals. Vulnerability Disclosure Programs remain open to anonymous participants, but any researcher seeking monetary rewards must now reveal their identity. The move follows similar steps by Bugcrowd and Intigriti and is driven by anti-money laundering and cross-border payment regulations. Researchers in high-surveillance regions and newcomers face new barriers, while the platform argues the change improves report quality and enterprise trust. H1 Clear adds an extra criminal background check layer for elite participants.

ๅฎ‰ๅ…จๅฎข
๐Ÿ‡ท๐Ÿ‡บAug 4

Telegram Briefly Removed from App Store After Apple Detects Child Sexual Abuse Material

Telegram was temporarily pulled from the App Store in multiple countries after Apple moderators identified content linked to child sexual abuse. The removal lasted roughly 20 minutes before the app was reinstated following Telegram's quick removal of the prohibited material and blocking of the responsible user. Apple cited strict App Store rules as the reason for the action. During the outage, already-installed copies continued to function normally while the app remained available via the Mac App Store and Google Play. Telegram responded on X with the quote โ€œRumors of my death have been greatly exaggeratedโ€ before Apple issued its official explanation. This marks at least the third documented instance of Telegram facing App Store removal, including a 2018 incident over unacceptable content and a 2024 removal from the Chinese store at the request of local regulators.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 4

Russia's MinTsifry Proposes Hosting Providers Detect and Report Disguised VPN Services

The Russian Ministry of Digital Development is discussing measures to strengthen oversight of VPN services that mask themselves as legitimate websites and hide their IP addresses from official blocklists. Hosting providers would be required to independently identify suspicious IP addresses and report them to regulators for potential blocking. The proposal also introduces a tiered trust system for hosting clients based on the strength of their identity verification. Users authenticated only via phone or bank card could have services terminated within 30 minutes upon violations, while those verified through Gosuslugi or biometric systems would receive more time to resolve issues. Non-compliant hosting providers risk being labeled as unreliable, resulting in restrictions that limit client access to a narrow whitelist of approved resources such as government portals, banks, and marketplaces. Industry participants warn that these restrictions could worsen IPv4 address shortages and drive legitimate businesses toward foreign hosting providers.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 3

Why Sending an MDM Command Does Not Mean It Has Been Executed

MDM operations such as policy assignment and device lock appear synchronous in the console but actually trigger complex asynchronous delivery chains involving backends, queues, vendor infrastructure, and device agents. The article explains that request acceptance, queue storage, external API confirmation, and actual device execution represent four distinct states that must be tracked separately. Aitera MDM implements an Outbox pattern to ensure transactional consistency between policy changes and command delivery while supporting at-least-once semantics with idempotency. Android Enterprise relies on the Android Management API and Google-controlled synchronization through Android Device Policy, whereas iOS uses APNs only for wake-up and pull-based command retrieval with statuses including Acknowledged, Error, and NotNow. The system maintains separate desired, delivery, and observed states to avoid misleading applied flags and provides detailed command history for administrators. Metrics focus on policy confirmation rates, queue age, and divergence between intended and actual device configurations rather than simple device counts.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 3

Russia's FAS Opens Antitrust Case Against Apple for Failing to Pre-Install Domestic Software on iOS Devices

Russia's Federal Antimonopoly Service has initiated proceedings against Apple after the company failed to comply with a prior warning to pre-install Russian software on iPhones and iPads. The case stems from requirements under Russian law to offer domestic alternatives for search engines, messengers, and app stores. Apple had added support for a Russian search engine in a software update, but this did not satisfy regulators who also demanded the national messenger and domestic app store. Non-compliance could result in a fine reaching up to 4 billion rubles under the Code of Administrative Offenses. The government has already approved a mandatory list of Russian applications that must be pre-installed on smartphones and tablets starting January 1, 2027. The list includes RuStore, Max, Yandex Browser, Alice AI, VKontakte, Gosuslugi, Mir Pay, Mail.ru, and 2GIS among others.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 3

Russia Drafts Rules Letting Users Choose AI Assistant at Smartphone First Boot

The Russian Ministry of Digital Development has published a draft government resolution that would replace the existing voice assistant pre-installation requirement with a broader category called system assistant. The new rules would allow users to select a domestic, foreign, or no AI assistant when first powering on a smartphone. The system assistant is defined as an AI program capable of controlling the device, operating system, and applications through voice, text, and visual commands. Manufacturers would be required to give the chosen assistant equal treatment regarding updates, settings, and interface visibility, and the pre-installed version must remain free and persist after factory resets. Search services could also incorporate AI technologies under the updated list. The ministry states the changes aim to increase competition between Russian and foreign platforms while preserving user access to modern AI services even if certain foreign products face restrictions.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บAug 3

Password Rotation Policies Under Scrutiny: NIST Guidelines, Historical Origins, and Logical Flaws

The article examines the long-standing practice of mandatory password rotation every 90 days, contrasting it with modern recommendations from NIST that advocate changing passwords only upon confirmed compromise rather than on a fixed schedule. It dissects common arguments in favor of periodic rotation, such as limiting offline hash cracking time and terminating unknown sessions, and demonstrates how these rely on reverse logic that starts from the control rather than from actual threats. Historical analysis traces the 90-day rule back to the 1985 DoD Green Book (CSC-STD-002-85), revealing that its own calculations showed password lifetime has minimal impact on security when proper rate limiting is in place. The piece distinguishes between data leakage and credential compromise, emphasizing that internal organizational signals provide far better indicators for targeted password changes than public breach databases. It concludes that scheduled rotation only makes sense as a substitute for mature detection capabilities, a trade-off explicitly recognized in PCI DSS v4.0.

Habr
๐Ÿ‡ท๐Ÿ‡บAug 3

Yandex Alice AI Replaces VK Marusya in Russia's Mandatory Preinstalled Apps List for 2027

Russian authorities have approved the official list of software that device manufacturers and sellers must preinstall on smartphones, tablets, and computers starting in 2027. The updated requirements maintain most of the previous selections without major disruption. The only notable change involves voice assistants, where Yandex Alice AI will now take the place previously held by VK Marusya. This adjustment reflects ongoing government efforts to promote domestic software through mandatory preinstallation policies. The regulation continues to focus on ensuring Russian-developed applications receive prominent placement on new devices sold in the country.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 31

FSB Russia Certifies Rutoken Chip 3127 with Five-Year Cryptographic Key Validity

Aktiv has received an FSB Russia certificate for the embedded Rutoken Chip 3127 microcontroller under security classes KS1 and KS2. The certification followed additional research that extended the validity period of the device's private cryptographic keys to five years. The chip belongs to the Rutoken ECP 3.0 3127 product line and targets long-term cryptographic protection in servers, ATMs, workstations, tablets, biometric systems, industrial equipment, and IoT devices. It stores keys in non-extractable form, performs user and device authentication, verifies component integrity, and supports trusted boot processes by controlling executable code at each stage. Additional capabilities include data encryption, derivation of session keys, secure software updates, and protected TLS and VPN connections using the CRISP protocol that complies with GOST R 71252-2024. The chip incorporates hardware-level defenses such as voltage monitoring, protective layer detection, and dummy branch execution to counter physical tampering and side-channel attacks. Pilot deployments have already occurred, including integration into the OVISION biometric access control systems, paving the way for serial use in critical infrastructure.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 30

Durov's Addition to Terrorist List Triggers Russian Account Blocks but Does Not Automatically Ban Telegram or Classify Transfers as Terrorism Financing

Russian financial institutions must suspend operations on Pavel Durov's domestic accounts following his inclusion in the Rosfinmonitoring terrorist and extremist list on July 30. The restrictions primarily target his personal finances and property inside Russia, as confirmed by attorney Dmitry Roshchin. Telegram itself remains unaffected as a platform because the messenger and its founder are legally distinct entities. Transfers to Durov do not automatically constitute terrorism financing; criminal liability requires proof that the funds were specifically intended for terrorist activities. The FSB has accused Durov of aiding terrorism by failing to remove channels allegedly used by Ukrainian services for sabotage planning, yet he has not been convicted by a court. Media outlets RIA Novosti and Izvestia reported these clarifications on compliance with Russian anti-terrorism legislation.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 30

Russian Ministry Proposes Mandatory Phone-Number Authentication for Foreign Websites and Apps

The Russian Ministry of Digital Development has drafted new rules requiring foreign websites and applications to authenticate users in Russia exclusively through phone numbers. The measure forms part of the third anti-fraud package known as Antifraud 3.0 and would eliminate email, social-media logins and other traditional methods. Foreign service operators would also be obliged to retain registration, login and account-deletion records for three years and to hand them over to Russian law-enforcement agencies upon request. Amendments are planned for Article 8 of the law On Information, with submission to the State Duma scheduled for autumn 2026. Experts warn that many international companies may refuse to build separate authentication flows for the Russian market, potentially leading some services to exit Russia entirely. The proposal also raises enforcement questions for already-blocked platforms such as Facebook and Instagram owned by Meta.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 30

Google's Android Developer Verification Rollout: Implications for Russian Devices and MDM-Managed Phones

Google is introducing mandatory Android Developer Verification on certified devices starting in select countries in September 2026, requiring developers to register and sign apps with verified identities. The policy aims to curb fraudulent and malicious applications by linking package names to registered developer signatures checked via the new Android Developer Verifier system component. Devices without Google services, including many Russian and Chinese firmware builds as well as AOSP variants, remain completely unaffected since the verification mechanism relies on Google Play services. Russia is explicitly excluded from the initial rollout and subsequent waves due to sanctions, allowing continued distribution of in-house and third-party applications. Corporate MDM deployments are also exempt because administrators are considered to have already vetted the apps for safety. Google plans to offer both full registration requiring D-U-N-S numbers for organizations and a limited option for hobbyists capped at 20 devices. The company has already registered SafeMobile as a verified developer, ensuring seamless installation of its client on supported devices.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 29

Building Information Security Culture: How Welcome Training Turned Rules into Engaging Dialogue

A large software development company transformed its approach to information security awareness by replacing formal policy sign-offs and portal documents with an interactive Welcome Training program. The 45-minute in-person sessions target developers, analysts, testers, product managers, and designers, focusing on real-world context, attack mechanics, and personal relevance rather than prohibitions. Training covers global and local threat landscapes, password policies, corporate email usage, sensitive data storage with VeraCrypt, secure credential sharing via pbin, file verification with VirusTotal, and social engineering defense. It also highlights existing corporate tools including Kaspersky Endpoint Security, Kaspersky Secure Mail Gateway, and SIEM systems to emphasize layered protection. The format has increased engagement, improved retention of guidelines, fostered conscious compliance, and noticeably reduced incidents stemming from human error. The company stresses that technology alone fails without employee understanding of why rules matter.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 28

Russian Ministry Clarifies No Plans to Disable Apple iPhones Despite New Device Registry

The Russian Ministry of Digital Development has officially stated that no government body or telecom operator has the authority to remotely disable iPhones or other devices from specific manufacturers. The clarification was issued in response to an inquiry from deputy Vladimir Plyakin regarding rumors of potential restrictions if Apple fails to comply with Russian legislation. Current laws do not permit turning user devices into non-functional bricks through any centralized mechanism. However, amendments to the law On Communications will introduce a national registry of user equipment identifiers starting March 1, 2027. The ministry is still developing the regulatory framework for this database, including what data will be collected and which agencies will have access. Officials emphasized that the existence of the registry does not imply any capability for mass device deactivation at this stage.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 28

Russia's Top Investigator Proposes AI, VPN and Other Technologies as Aggravating Circumstances in Criminal Code

Alexander Bastrykin, head of Russia's Investigative Committee, has put forward a bill that would treat the use of artificial intelligence, VPN services and other information technologies as an aggravating factor when sentencing offenders. The proposal aims to address the growing role of digital tools in crimes ranging from fraud and data trafficking to terrorism, murder and sexual offences. Current Russian law lacks a universal provision allowing courts to factor in the deployment of such technologies during punishment decisions. Bastrykin argued that embedding specific technologies into dozens of Criminal Code articles would be inefficient because the IT landscape evolves too rapidly for static legal language. Instead, the committee advocates a systemic approach that recognises technology as a distinct aggravating circumstance when it serves as the primary instrument of the crime or significantly amplifies the harm caused. The measure would not criminalise the mere possession or activation of a VPN, smartphone or AI model; it would apply only when these tools materially enable or scale criminal activity. The bill has already been prepared by the Investigative Committee and was outlined in an interview with Interfax.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 28

Bank of Russia Publishes Methodological Recommendations No. 3-MR on AI Security for Financial Market Participants

The Bank of Russia has released methodological recommendations No. 3-MR dated 16 June 2026, providing detailed guidance on ensuring information security during the development and use of artificial intelligence systems in the financial sector. The document builds on the earlier Code of Ethics for AI in finance and integrates with existing risk management, operational resilience, and data protection frameworks already familiar to credit institutions and other market participants. It introduces standardized terminology for AI-specific threats such as hallucinations, data drift, and poisoned datasets while outlining six risk categories and a four-stage AI system lifecycle model. Organizations are advised to apply threat modeling based on FSTEC methodology, implement proportional controls across data preparation, development, training, and operation phases, and maintain human oversight for high-risk automated processes. Special attention is given to supply chain risks involving third-party vendors and open-source components, requiring due diligence, provenance tracking, and contractual safeguards aligned with existing outsourcing standards. The recommendations remain non-binding yet signal clear regulatory expectations that are likely to influence future compliance checks and audits.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 28

Aladdin Obtains New FSB Certificate for CryptoFlash Encrypted USB Drive Valid Until 2029

Aladdin has received a new FSB Russia certificate for its Aladdin CryptoFlash hardware-encrypted USB drive. The certificate number ะกะค/124-5574 confirms compliance with cryptographic protection requirements for classes KS1 and KS2 and remains valid until 16 July 2029. The device now supports additional Russian Linux distributions including RED OS 7.3 and 8, Alt 8 SP Workstation, Alt Workstation 10, and the OS of the Moscow Electronic School. Read and write speeds have been increased to 11 MB/s while the graphical interface received improvements. The product uses the Magma encryption algorithm in hardware and operates as a clientless solution that requires no additional drivers or software. The previous certificate remains active until December 2028, allowing both versions of the device to be used in parallel for storing and transferring official and confidential information marked DSP.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 27

Microsoft Tightens Corporate Windows Activation with TPM-Bound KMS Servers

Microsoft is strengthening its corporate Windows licensing controls by introducing new requirements for KMS servers used in volume activation. The changes will bind KMS hosts to TPM hardware attestation, preventing cloned or fake servers from issuing licenses to unlicensed devices. Warnings will begin appearing in Windows Server 2025 in August 2026, with mandatory enforcement planned for the next LTSC release. Existing KMS systems will continue operating normally until the new rules take effect. The update targets enterprise environments with on-premises KMS infrastructure and does not affect individual consumer devices or common non-KMS activation bypass methods. Administrators can already verify TPM support on physical servers using the Get-TpmSupportedFeature command.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 25

Russia's Article 10.1 on Personal Data Dissemination: Apparent and Real Contradictions in Federal Law 152-FZ

Part II of the analysis examines how the rushed redrafting of Article 10.1 between the first and second readings created serious interpretive problems in Federal Law 152-FZ. The core issues include undefined terms such as 'disclosure', conflicting definitions of 'access', 'provision' and 'dissemination' between 152-FZ and 149-FZ, and the removal of the legal basis for processing publicly available data while retaining the consent mechanism that was meant to control it. Courts have consistently held that mere openness of data does not constitute a valid processing ground, forcing subsequent operators to find their own basis under Article 6. The article highlights that the mechanism for subjects to set conditions and prohibitions was preserved, yet the underlying legal foundation that would make those rules effective was eliminated. Two possible readings of the special consent are explored, with judicial practice leaning toward the narrower interpretation that leaves conditions and prohibitions as mere additional restrictions rather than a source of authorization.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 25

Why Deep Packet Inspection Overestimates Its Reach in Encrypted Networks

Modern encryption has fundamentally limited the effectiveness of Deep Packet Inspection systems, leaving network monitors with only metadata and behavioral patterns rather than actual content. DPI tools can still classify traffic types and apply policies based on visible flow characteristics, but they cannot read messages, files, or credentials inside properly encrypted sessions without explicit TLS inspection. The article details how TLS 1.3, Encrypted Client Hello, and QUIC further reduce passive visibility while corporate inspection remains possible only when endpoint devices trust an organizational certificate. Russian regulatory requirements around TSPU systems are discussed separately from corporate DPI use, with emphasis on the need for technical confirmation rather than assumptions. The piece also clarifies distinctions between DPI, IDS, IPS, and DLP, and explains why machine learning cannot convert metadata into decrypted payloads. Overall, the analysis shows that DPI remains useful for traffic management and known-threat detection where visibility exists, but it cannot serve as a complete security foundation.

Securitylab
๐Ÿ‡ท๐Ÿ‡บJul 25

How Russia's Article 10.1 on Personal Data Dissemination Emerged: Legislative History and Reform Flaws

The article examines the origins of Article 10.1 in Federal Law 152-FZ, introduced via bill 1057337-7 by deputy Anton Gorelk in in November 2020. It traces how the reform aimed to separate publication, access, extraction, and reuse of personal data but retained outdated definitions from the original law and added exceptions that created contradictions. The piece details pre-reform court rulings, including Supreme Court decisions confirming that open internet profiles do not automatically qualify as publicly available data under Article 8. It highlights the committee's own admission that the bill failed to meet its stated goals and the Legal Department's warning about inconsistent terminology around 'access' and 'transfer'. The resulting 519-FZ law is described as an imprecise attempt to solve real control problems with unsuitable conceptual tools, leaving operators unable to apply the rules consistently.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 24

EU Imposes 21st Sanctions Package Targeting 94 Russian Banks Including Ozon Bank, Yandex Bank and WB Bank

The European Union has adopted its 21st sanctions package against Russia, placing restrictions on 94 banks, the Moscow Exchange, and several payment organizations. The measures, effective from 23 July, directly affect Rosselkhozbank, Dom.rf, MTS Bank, Ak Bars, Uralsib, Zenit, Absolut Bank, WB Bank, Ozon Bank, Tochka, Yandex Bank, and Post Bank. Personal sanctions were also imposed on Bank of Russia Deputy Chairman Sergey Belov, Russian Railways head Oleg Belozerov, and other individuals. In addition to finance, the package covers energy, trade, and cryptocurrency sectors. Russian financial institutions have stated that operations continue normally, though the Golden Crown payment system has already suspended transfers to Georgia and several other countries. Moscow Exchange and affected banks including Ozon Bank and Tochka confirmed that trading, settlements, and client services remain unchanged.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 24

Sberbank to Terminate Currency and Multicurrency Visa Cards from September 2026 Despite Prior Extensions to 2030

Sberbank announced it will cease servicing currency and multicurrency Visa cards starting September 1, 2026, including those whose validity was previously extended until 2030. The bank notified customers via SMS and advised them to close affected cards in advance through the Sberbank Online app or at a branch to avoid access issues with their funds. This decision aligns with ongoing sanctions against Russia, import substitution policies, and the gradual removal of Visa and Mastercard from the Russian market. Central Bank officials, including Elvira Nabiullina and Alla Bakina, have confirmed that international payment systems must exit Russia, with the share of Visa and Mastercard already reduced to less than 17 percent. The National System of Payment Cards continues to incur costs supporting legacy cards while promoting domestic alternatives such as Mir. Customers are encouraged to transfer remaining balances to other accounts to maintain uninterrupted access to their money.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 23

.RU and .ะ ะค Registries Stop Disclosing Legal Entity Domain Owners in WHOIS

The domain registries for .RU and .ะ ะค have ceased displaying detailed information about administrators that are legal entities. Previously the WHOIS service revealed the full name of the organization along with its INN tax identification number, but the records now show only the generic term Organization. The change was first noticed on 22 July by Habr user @ifap, who observed that domains previously linked to government bodies such as the Federal Protective Service no longer reveal the actual administrator. Support staff at the Coordination Center attributed the disappearance of data to unspecified technical issues and described the outage as temporary, without providing any timeline or details on the root cause. Observers note that the reduced transparency turns routine owner identification into a lengthy investigation, especially for less prominent domains. One unconfirmed theory suggests the registry is being reconfigured to meet new authentication requirements for domain administrators. It remains unclear whether the previous level of disclosure will be restored or whether the current limited view will become permanent.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 21

Advanced Windows Auditing Configuration Guide for Effective Incident Response in SOC Environments

The article provides a detailed walkthrough on configuring advanced audit policies in Windows 10 and Windows 11 to generate meaningful security events for incident investigation. It explains the role of the LSASS service in logging activities to the Security event log and contrasts basic auditing with the more granular advanced auditing that offers 53 subcategories. The guide covers enabling key subcategories such as Logon, Process Creation, and Account Management using auditpol commands, along with registry tweaks for PowerShell Script Block Logging and command-line auditing in process creation events. Practical tests demonstrate real-world events including successful and failed logons (Event IDs 4624 and 4625), process creation with arguments (Event ID 4688), and user account creation (Event IDs 4720 and 4732). All steps are performed on a VMware Workstation virtual machine running Windows 10 Pro 22H2 to avoid impacting production systems.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 21

Russia's Supreme Court Bans Silent Crow and Cyberpartisans BY as Extremist Organizations

The Supreme Court of the Russian Federation has officially recognized the hacker groups Silent Crow and Cyberpartisans BY as extremist organizations and banned their activities in Russia. The closed-door ruling, issued at the request of the General Prosecutor's Office, accuses both groups of conducting joint cyberattacks against Russian and Belarusian critical information infrastructure with the aim of destabilizing the political situation and achieving an unconstitutional change of government. Cyberpartisans BY are described as part of the Belarusian association Supratsiv, which allegedly seeks a violent overthrow of the constitutional order, and are linked to the banned Polk named after Kastus Kalinouski as well as Ukrainian military information-psychological operations units. Silent Crow, previously known as CyberWar and Cyber LegionsUA, is portrayed as a pro-Ukrainian collective of politically motivated hacktivists whose primary objective is to damage Russian state bodies, companies, and critical infrastructure. Both groups are held responsible for attacks on Aeroflot IT systems, Rostelecom databases, Rosreestr servers, and the Belarusian Railway infrastructure. Participation in or support for these organizations now carries legal liability under Russian law.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 21

How CISOs Can Speak to CEOs: Translating Cyber Risks into Business Impact and Financial Consequences

The July 2025 Aeroflot cyber incident, claimed by Silent Crow and Belarusian Cyber-Partisans, demonstrated how technical vulnerabilities quickly translate into canceled flights, regulatory investigations, stock market reactions, and direct executive accountability. The article examines the persistent communication gap between CISOs, who focus on metrics like EDR coverage and mean time to detect, and CEOs, who prioritize costs, operational disruptions, revenue loss, and personal liability. Research from EY and Splunk highlights differing perceptions of threats and success measures, while real-world cases such as Marks & Spencer, Jaguar Land Rover, Clorox, Change Healthcare, SolarWinds, and Uber show how contractor weaknesses, missing MFA, and delayed disclosures lead to hundreds of millions in damages and legal actions. Regulatory developments, including SEC charges against CISOs and Russia's 420-FZ with turnover-based fines, further force cybersecurity discussions into the boardroom. The piece provides a practical translation table showing how technical warnings should be reframed using concrete business scenarios and financial impacts. It concludes that both CISOs and CEOs must initiate conversations around unacceptable events, downtime costs, and risk reduction versus post-incident consequences.

Securitylab
๐Ÿ‡ต๐Ÿ‡นJul 21

EU Forces Google to Open Android Microphone, Camera and Screen Access for Rival AI Assistants

The European Union has ordered Google to provide competing AI assistants with the same level of access to sensitive Android resources that is currently reserved for Gemini. The ruling covers eleven system functions, including voice activation, home button integration, background execution, and on-device AI model access. Rival assistants will also gain real-time environmental data streams from the microphone, camera, screen, and speakers under identical consent and notification rules applied to Google services. Additional capabilities include cross-app interaction, messaging, scheduling, device settings control, and multi-step task automation. Screen automation will allow assistants to operate apps inside a virtual window while the user performs other activities. Most changes are scheduled for Android 18 by 1 August 2027, while simultaneous activation of multiple assistants by voice keyword will arrive in Android 19 no later than 1 August 2028. Access to the most sensitive functions may require objective security certification and explicit user authorization.

BoletimSec
๐Ÿ‡ท๐Ÿ‡บJul 20

Walk In, You've Been Recognized: The Evolution of Identification Technologies in Modern Access Control Systems

PERCo has expanded its PERCo-Web access control system with new BLE-enabled readers, companion mobile apps, and a joint facial recognition solution developed with the CRะข group. The update provides an opportunity to examine how identification methods in physical access control have developed without any single technology fully displacing the others. Traditional proximity and MIFARE cards remain the foundation, while QR codes, NFC, BLE, and biometrics each occupy specific niches based on convenience, security, and regulatory requirements. Russian Federal Law 572-FZ has fundamentally changed facial biometrics deployment by mandating use of the Unified Biometric System (EBS) or accredited commercial systems (KBS) for authentication. The article explains the technical workflow from reader to controller, the cryptographic protections of modern cards, the contactless advantages of BLE, and the privacy and compliance considerations that now make facial recognition a 'technology of trust' rather than simple convenience.

Habr
๐Ÿ‡ท๐Ÿ‡บJul 20

Russian Users Report Widespread App Store Outages as Roskomnadzor Denies Any Role in Restricting Access

Russian users began experiencing technical problems with the App Store starting early in the day, with the monitoring service Sboy.rf receiving 251 complaints about instability and failed downloads. The majority of reports originated from Moscow, accounting for 20 percent of cases, followed by Saint Petersburg at 13 percent and several other regions including Udmurtia, Kursk, Rostov, Bryansk oblasts and Stavropol Krai each contributing 5 percent. Affected users described inconsistent behavior of the App Store application itself along with difficulties downloading games and other software, where the Get button would appear but actual downloads would succeed only sporadically. In response to the growing number of reports, Roskomnadzor quickly issued a brief statement clarifying that it is not imposing any restrictions on access to the App Store. The exact cause of the disruptions remains unknown, Apple has not provided any official comment, and the scale of the incident is considered limited since only several hundred users have reported issues and not everyone is affected. Standard troubleshooting steps such as verifying internet connectivity, restarting the App Store application, and waiting for service restoration have been recommended to users.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 17

VK Apps Remain Downloadable in US Google Play Despite Removal in Russia and Turkey Amid Sanctions

The removal of VK services from Google Play has proven to be less global than initially reported, with applications still accessible to users whose Google accounts are registered in the United States region. Testing revealed a clear geographic pattern: the apps are unavailable in Russian and Turkish storefronts but remain fully visible and installable under the American region. The services disappeared from the store on July 16, prompting VK to confirm that already installed applications will continue functioning without restrictions and directing users to alternative stores such as RuStore. The exact cause of the regional discrepancy remains unclear and may relate to Google Play configuration settings, ongoing sanctions against Russia, distribution policies, or simple catalog synchronization delays. In a related development, VK users have begun receiving notifications urging them to switch to the vk.ru domain, which the company states offers superior speed and reliability and will now serve as the primary address.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 16

VK and MAX Apps Removed from Google Play Store Amid EU Sanctions on Russian Company

VK and its national messenger MAX have been removed from the Google Play Store following the European Union's decision to add the parent company to its sanctions list. The company confirmed that the apps are no longer available for new downloads or updates through Google, but existing installations continue to function normally with full access to messaging, calls, events, and push notifications. Users can obtain updates and new installations through alternative Android stores including RuStore, Huawei AppGallery, Samsung Galaxy Store, and Xiaomi GetApps, or receive in-app update prompts when new versions become available. The removal comes shortly after similar apps such as Dzen and VK Video disappeared from the Apple App Store last month. Although the exact reasons were not disclosed in VK's statement, the sanctions were triggered specifically by the development of the MAX messenger as a national platform. This development highlights how regulatory actions are reshaping app distribution channels for Russian digital services, positioning RuStore as a primary rather than backup marketplace.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 16

Russian Players Report Mass Launch Failures in Diablo IV, Marvel Rivals and Other Online Games Amid Suspected Regional Restrictions

Russian gamers are experiencing widespread problems launching popular online titles including Diablo IV, Marvel Rivals, and Neverness to Everness, with games either failing to start or disconnecting at the server connection stage. Reports on Steam highlight the recurring Server Connection Failed error in Marvel Rivals, where standard troubleshooting steps such as client restarts, file verification, and account re-logins provide no relief for many users. The issues coincide with mentions of content web filtering systems and follow a partial Steam outage on July 14 that already disrupted platform sections and page loading. Players are divided between theories of deliberate regional blocks or ordinary technical faults, yet neither game developers nor Russian authorities have issued any official statements. Steam itself remains accessible, allowing users to reach their libraries and the Play button, but actual gameplay connections have turned into an unpredictable lottery. Without confirmed explanations, affected players can only continue testing connections and hoping for successful launches.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 16

Google to Allow Competing Android App Stores Directly Inside Play Store After Epic Games Court Ruling

Google is preparing to open its official Google Play store to rival Android app marketplaces starting July 22, following a court order issued in the long-running antitrust lawsuit with Epic Games. The ruling stems from the 2020 Fortnite dispute over Googleโ€™s 30% commission and direct in-app purchases that bypassed the platformโ€™s billing system. A federal judge determined that Google had unlawfully prevented device makers from promoting or pre-installing alternative app stores, thereby reinforcing Google Playโ€™s monopoly position. As a result, approved third-party stores will now be distributed directly through Google Play, receive default access to its app catalog, and be subject to an annual $5,000 verification fee. Developers retain the right to block distribution of their apps on specific stores, while participating marketplaces must meet strict security, copyright, and update obligations or risk removal if suspicious installations exceed 1%. Although the changes are expected to apply primarily in the United States, the decision marks a fundamental shift in how Google must accommodate competitors within its own ecosystem.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 15

UK Plans Nighttime Social Media Curfew and Addictive Feature Restrictions for Teens from 2027

The United Kingdom has announced plans to restrict social media access for teenagers aged 16-17, introducing a nightly curfew from midnight to 6 a.m. starting in spring 2027. In addition to the time-based ban, platforms will be required to disable addictive features such as infinite personalized feeds, autoplay videos, Reels, and TikTok-style content by default for this age group. The measures are designed as a transitional step ahead of a complete social media ban for children under 16, which will also take effect in spring 2027. Government officials cite a pilot study involving 300 participants that demonstrated improved sleep quality and concentration after implementing similar nighttime restrictions. The policy also targets AI chatbots, mandating mandatory breaks for minors and potentially banning services that provide dangerous or unverified mental health advice. Schools will incorporate new digital literacy modules covering safe AI usage, detection of deepfakes, disinformation, and harmful content such as violent or misogynistic material.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 15

US Prepares for Free Chinese AI Models Distributed Like Torrents, Weighs Policy Shift on Open-Source Systems

The Trump administration is actively discussing uniform capability requirements for American open-source AI models, using advanced Chinese systems as the benchmark. Chinese developers are expected to release powerful Mythos-class models within the next 6โ€“12 months that anyone can freely download, run locally, fine-tune, and integrate without developer oversight. This development creates a policy dilemma for Washington, as overly strict controls risk slowing domestic innovation while failing to prevent the spread of foreign technology. China is deliberately promoting open AI releases to expand the global reach of its developers, especially after restrictions limited the availability of leading U.S. models. At the same time, the industry is exploring superconducting cables and optical interconnects to curb the rapid growth in data-center electricity consumption, which already accounts for 1.5% of global power usage. The Washington Post notes that long-term energy forecasts may be overstated if these efficiency technologies are adopted at scale.

securitylab_n
๐Ÿ‡ท๐Ÿ‡บJul 15

Google Urges European Commission to Stop Mass Blocking of IP Addresses, DNS Services and VPNs in Piracy Fight

Google has called on the European Commission to abandon the widespread practice of blocking IP addresses, DNS services and VPNs as a means of combating pirate sites, describing the approach as both ineffective and risky. The company explained that such blocks fail to remove illegal content permanently and allow users to quickly switch to alternative DNS providers, VPNs or new addresses, enabling piracy to continue uninterrupted. Blocking entire IP ranges is particularly problematic because a single address or range is often shared by multiple unrelated legitimate websites and cloud services, leading to collateral damage for lawful users. Google cited the December 2019 incident in Portugal, where ISP blocks on virtual IP addresses disrupted important Google services and affected Google Cloud customers sharing the same infrastructure. A similar outcome followed the blocking of The Pirate Bay in the United Kingdom, after which lists of proxy servers rapidly appeared online to restore access. The search giant stressed that these measures only create temporary obstacles rather than eliminating the source of pirated material and increase the chance of accidentally disabling legitimate online resources.

securitylab_n
๐Ÿ‡ท๐Ÿ‡บJul 14

Kremlin Spokesperson Peskov Labels EU Sanctions Against MAX Messenger as Manifestation of Repressive Policy

Dmitry Peskov, the press secretary to the Russian president, has strongly condemned the European Union's decision to impose sanctions on the Russian messenger MAX, describing the move as absolutely absurd and a clear demonstration of the repressive character of European sanctions policy. The EU added the parent company VK and its subsidiary LLC Communication Platform, the developer and operator of MAX, to its sanctions list due to their connection with Russia's national messenger. This action follows the removal of the VK and MAX applications from the Apple App Store in June, although already installed versions continue to function without the ability to receive updates through the store. VK has stated that the sanctions have not impacted the messenger's operations and that MAX along with other services remain fully available to users in normal mode. The situation raises questions about whether further barriers will emerge around MAX beyond the current sanctions listings and App Store restrictions, with political rhetoric currently outweighing any significant technical consequences.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 14

RZD Trunk Quantum Network Obtains FSTEC Attestation and Enters External Commercial Market

Russiaโ€™s state-owned railway operator RZD has successfully passed certification by the Federal Service for Technical and Export Control (FSTEC), confirming that its trunk quantum network meets the requirements for information systems of the second protection class. The attestation enables RZD to begin offering quantum-secured communication services to external organizations, including banks, industrial enterprises, medical institutions, and transport companies. Quantum key distribution technology allows any interception attempt to be detected because interference with the quantum channel alters the state of transmitted particles, providing a level of security far beyond conventional encryption methods. The network is already being tested by the Bank of Russia, the Federal Treasury, the Financial University, and several major banks, with potential clients also identified in the oil-and-gas, industrial, healthcare, and transportation sectors. The Ministry of Digital Development considers the technology sufficiently mature and has included further expansion of the quantum network through 2030 in the national โ€œData Economyโ€ project roadmap. As a result, RZD is gradually transforming from a traditional carrier of passengers and cargo into an operator of protected digital highways.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 14

Telegram Loses Global Short Links as t.me Domain Disabled Worldwide by .me Registry

On July 13, users worldwide discovered that Telegramโ€™s short links in the t.me format stopped opening in web browsers, although the messenger itself continued to function normally. The issue was first reported by the Russian publication Kode Durova and affects only external browser access, while links remain fully operational inside the Telegram desktop client and mobile applications. According to preliminary findings, the domain was effectively removed from the DNS system at the registry level of the .me top-level domain, which belongs to Montenegro and is operated by the company doMEn. The exact reason for the deactivation remains unknown, with possible explanations including a legal dispute, routine verification, government requests, or a violation of the domain zoneโ€™s rules. Notably, the t.me domain is registered to Telegram until 2035, ruling out simple expiration or administrative oversight. As a result, users are currently advised to open t.me links directly through the Telegram app while waiting for the domain to be restored in the global DNS.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 13

EU Adds Russian Tech Giant VK to Sanctions List Over Development of National Messenger MAX

The European Union has included VK in its sanctions regime, targeting the parent company of Russiaโ€™s largest social media platforms including VKontakte and Odnoklassniki. The move was triggered by VKโ€™s ownership of the developer behind the national messenger application MAX, which Russian authorities have been promoting as a domestic digital platform. According to the Council of the EU, VK serves as the parent structure for LLC Communication Platform, the entity directly responsible for creating and operating MAX. The sanctions decision was formally published on 13 July in the Official Journal of the European Union, marking the first time Brussels has directly sanctioned a major Russian IT holding in connection with a consumer messaging service. While the exact operational and commercial consequences for VK, its subsidiaries, and international partners remain unspecified in the official notice, the action extends EU restrictive measures beyond traditional sectors such as banking, energy, and manufacturing into the Russian technology industry. VKโ€™s press service stated that the sanctions do not affect the functioning of VK or MAX and that all applications and services remain available to users without disruption.

AntiMalware
๐Ÿ‡ท๐Ÿ‡บJul 13

Russia to Mandate Gosuslugi Authentication for Hosting Providers, Further Reducing Anonymity in Runet

The Russian Ministry of Digital Development (MinTsifry) is advancing plans to require all hosting providers to identify clients exclusively through the Gosuslugi portal and the ESIA system. The measure aims to ensure that every allocated IP address is linked to a verified individual, going beyond current methods such as email or bank card verification. This approach mirrors the identification rules already enforced since September for .ru, .ั€ั„, and .su domain registrations and renewals. Industry reactions are divided: while some providers like Turbo Cloud support the initiative for combating fraud, others warn of high implementation costs and significant client losses. Smaller users, including students and independent developers, may migrate to foreign hosting services, and foreigners could face restricted access without alternative verification options.

AntiMalware
๐Ÿ‡จ๐Ÿ‡ณJul 12

Phase II of National 100-City FDE Frontier Deployment Engineer Onboarding Program Officially Launches

The second phase of the nationwide "Hundred Cities On-the-Job Plan" for FDE Frontier Deployment Engineers has been announced, expanding opportunities across China. The initiative targets experienced engineers specializing in advanced deployment technologies and aims to place professionals in key urban centers. Building on the success of the first phase, this new round seeks to strengthen technical capabilities in critical infrastructure and cybersecurity domains. Participants will receive structured onboarding, training, and direct placement support in multiple cities. The program underscores growing demand for specialized deployment expertise amid rapid digital transformation.

ๅฎ‰ๅ…จๅฎข