AntiMalwareAugust 5, 2026🇷🇺Translated from Russian

Yandex Cloud Partners with Sogaz and Ingosstrakh to Automate Cyber Risk Assessment for Business Insurance

Yandex Cloud has partnered with major Russian insurers Sogaz and Ingosstrakh to launch new cyber insurance programs for businesses. Under the arrangement, the insurers provide financial protection while Yandex Cloud evaluates the client’s cloud infrastructure to determine appropriate policy conditions.

The assessment is performed using the Yandex Security Deck service. This tool automatically scans cloud resources, applications, and stored data for open internal information, excessive user access rights, data leak risks, and potential infrastructure compromise vectors. Findings are aggregated into a single interface and ranked by priority.

Clients receive the full report and may forward it directly to the insurer, which uses the data to calculate policy terms. When serious vulnerabilities are detected, Yandex Cloud offers specific remediation steps. The automated approach is intended to replace traditional paper questionnaires that often contain incomplete or outdated information.

According to Sogaz, the total volume of requested cyber-risk coverage more than doubled year-over-year during the first half of 2026, exceeding 12 billion rubles. The new model combines infrastructure diagnostics, technical protection measures, and financial compensation in the event of an incident.

Insurers gain a more accurate, real-time view of client risks, while businesses receive an opportunity to address cloud misconfigurations before they are exploited by attackers.

Related articles

AntiMalwarePolicy & Regulation

FAS Case Against Apple Will Not Brick iPhones for Russian Users

The Russian Federal Antimonopoly Service (FAS) has opened a case against Apple for failing to pre-install a national messenger and a Russian app store on iOS devices, yet officials have confirmed that no technical measures will disable or restrict existing iPhones. Deputy Chairman of the State Duma Committee on Information Policy Andrey Svintsov stated that the actions of FAS, Roskomnadzor and other agencies are limited to recording violations and collecting fines. Apple had already implemented the option to select a domestic search engine but did not meet the remaining pre-installation requirements. Svintsov emphasized that any court decisions will remain in force until Apple decides to return to the Russian market and settles accumulated penalties. The approach is designed to replenish the state budget through fines once the company resumes legal operations. Russian iPhone owners can continue using their devices without any risk of remote blocking or forced conversion into expensive paperweights.

AntiMalwarePolicy & Regulation

Over 20 VPN Services Hit by Outages After Russian Regulators Block Hosting Provider Subnets

Users of multiple VPN services reported widespread connection problems throughout the day as IP addresses belonging to several large hosting providers were placed under restrictions. The blocks targeted infrastructure used by VPNs to reroute traffic around content filters, causing entire ranges of servers to become inaccessible when whole subnets were affected. The Telegram channel Exploit reported that more than 20 VPN services of varying sizes experienced disruptions, though Roskomnadzor has not issued an official statement on the scope or origin of the measures. The affected providers indicated they are shifting customers to backup servers, noting that the restrictions appear selective yet still force frequent address changes during the day. The incidents coincide with ongoing discussions of new rules that would require hosting providers to independently detect and report masked VPN IP addresses to regulators. Similar large-scale subnet blocks occurred in late May, impacting numerous MTProto-based proxies and VPNs simultaneously.

安全客Policy & Regulation

HackerOne Ends Anonymous Era for Bug Bounty Hunters with Mandatory ID Verification

HackerOne has introduced compulsory identity verification for all researchers submitting reports to paid bug bounty programs, effective August 1. The policy requires users to complete KYC checks through Estonian firm Veriff by uploading government-issued ID and performing a live selfie, with annual renewals. Vulnerability Disclosure Programs remain open to anonymous participants, but any researcher seeking monetary rewards must now reveal their identity. The move follows similar steps by Bugcrowd and Intigriti and is driven by anti-money laundering and cross-border payment regulations. Researchers in high-surveillance regions and newcomers face new barriers, while the platform argues the change improves report quality and enterprise trust. H1 Clear adds an extra criminal background check layer for elite participants.

AntiMalwarePolicy & Regulation

Telegram Briefly Removed from App Store After Apple Detects Child Sexual Abuse Material

Telegram was temporarily pulled from the App Store in multiple countries after Apple moderators identified content linked to child sexual abuse. The removal lasted roughly 20 minutes before the app was reinstated following Telegram's quick removal of the prohibited material and blocking of the responsible user. Apple cited strict App Store rules as the reason for the action. During the outage, already-installed copies continued to function normally while the app remained available via the Mac App Store and Google Play. Telegram responded on X with the quote “Rumors of my death have been greatly exaggerated” before Apple issued its official explanation. This marks at least the third documented instance of Telegram facing App Store removal, including a 2018 incident over unacceptable content and a 2024 removal from the Chinese store at the request of local regulators.