Russian TSPU Systems Redirect DNS Queries to Google and Cloudflare Servers Toward National Domain Name System
Since the evening of August 26, Russian TSPU (technical means of countering threats) have started redirecting open DNS queries addressed to Google and Cloudflare public DNS servers toward the National System of Domain Names (NSDI). The change affects users of multiple Russian internet providers and coincides with ongoing implementation of content filtering systems required by Russian legislation.
When a standard UDP DNS query is sent to addresses such as 8.8.8.8 or 1.1.1.1 for domains including YouTube and RuTracker, the response returned is NXDOMAIN, indicating that the domain does not exist. In contrast, identical queries sent over TCP successfully reach the original servers and obtain genuine IP addresses.
Further traffic analysis by Habr user angry_agent showed that packets with a deliberately low TTL value elicited ICMP TTL Exceeded messages containing the IP address 195.208.5.1, which belongs to NSDI. The same behavior was not observed with arbitrary UDP packets, confirming that the system specifically inspects DNS traffic.
According to the researcher, TSPU devices recognize open DNS queries and perform a directed DNAT operation, transparently altering the destination address so that the packet is delivered to an NSDI server. The national resolver then decides what response to return to the user. From the perspective of the network operator, the query appears to have been sent directly to NSDI rather than to a foreign resolver.
The mechanism is not flawless. When several identical queries are transmitted rapidly, the first request receives an NXDOMAIN response while subsequent requests reach Google and return correct addresses. Redirection also does not occur for every public DNS server tested.
No official statement confirming the new redirection technique has been issued by Russian authorities or network operators. The conclusions are based solely on the experiments of a single researcher. The development follows reports from users of several Russian providers who experienced difficulties accessing protected DNS services operated by Google and Cloudflare.
Related articles
pg_anon Open-Source Tool Receives Major Updates for PostgreSQL Data Masking and Partial Database Operations
Tantor Labs has released version 1.11.0 of pg_anon, an open-source utility designed to mask personal data in PostgreSQL databases while preserving structure and relationships. The update introduces packaging as a standard Python package, support for partial dumps and restores using whitelist and blacklist dictionaries, and improved handling of complex schema elements such as partitioned tables, generated columns, and custom types. Performance improvements include switching the dump engine to asyncio, single-query metadata collection, and on-the-fly gzip compression to reduce memory usage on large databases. New CLI options allow clean or drop operations on target databases, privilege ignoring, and passthrough of pg_dump and pg_restore flags. A REST API was added to enable integration into CI/CD pipelines and automated self-service systems for nightly masked database refreshes. The tool helps organizations comply with data protection requirements by creating pseudonymized copies suitable for development, testing, and contractor environments.
Pegasus Spyware Returns in Serbian Surveillance Campaign via Zero-Click iMessage Exploit
A Serbian student activist's iPhone was infected with the Pegasus spyware through a zero-click exploit in iMessage, allowing silent installation without any user interaction. The infection, confirmed by Citizen Lab in collaboration with the SHARE Foundation, showed indicators of compromise between December 2025 and January 2026. Apple later sent the target a notification warning of a mercenary spyware attack attempt. The exploit granted full access to photos, messages, files, and enabled covert microphone and camera activation. The vulnerability was addressed in the iOS 18.4.1 update released on April 16, 2025. The incident forms part of a wider surveillance wave in Serbia, with at least 14 individuals including students, activists, a parliament member, and a local political representative receiving similar Apple alerts. Additional targets were hit with Android spyware variants linked to NoviSpy.
Mozilla Adds Built-in Ad Blocker to Firefox for iOS Devices
Mozilla has integrated a native ad-blocking feature directly into its Firefox browser for iOS. The update allows iPhone and iPad users to block third-party advertisements and associated trackers before web pages load, eliminating the need for separate extensions. Apple’s App Store policies have long restricted the use of third-party content blockers on iOS compared to desktop and Android platforms. The new functionality targets intrusive elements such as pop-up windows, content-overlapping banners, and other advertising formats. By handling blocking at the browser level, Firefox for iOS improves user privacy and reduces exposure to tracking mechanisms without requiring additional software installation.
De-Clouding IoT Devices: Local Control for Midea Air Conditioners and Tuya-Based Cat Feeders
A security researcher detailed a methodical approach to eliminating vendor cloud dependency for Wi-Fi IoT devices in a smart home setup. After acquiring a cat, the author was forced to integrate several Tuya-based appliances that only worked through proprietary cloud apps. Using hardware analysis tools including UART adapters, multimeters, and soldering equipment, the devices were disassembled and their controllers identified. The Midea air conditioner controller based on TYWE3S ESP8266 was reflashed with ESPHome to enable direct Home Assistant integration. For the Tuya WBR3-powered cat feeder running on an RTL8720CF chip, OpenBeken firmware was installed after extracting the original firmware with ltchiptool. Detailed UART communication analysis between the Wi-Fi module and MCU allowed full recreation of scheduling and control functions locally via MQTT.