Durev VPN Accused of Plagiarizing Independent Researchers' Articles for Commercial YouTube Promotion
Independent researcher zarazaexe has accused the commercial VPN service Durev VPN of repurposing multiple technical articles for YouTube advertising without attribution or permission.
The original publications covered reverse engineering of the MAX messenger, analysis of Russian TSPU whitelist mechanisms, examination of MinTsifry root certificates, and a detailed review of the Teleга client. Durev VPN converted these texts into video scripts, changed first-person statements to references to their own specialists, and removed any mention of the source author or project name.
One video titled СРОЧНО УДАЛИ СЕРТИФИКАТ МИНЦИФРЫ accumulated 795,000 views within two days. The service's Telegram bot lists 260,000 users, and the cheapest subscription costs 313 rubles per month. Rough calculations suggest that even modest conversion rates could generate several million rubles in recurring revenue from the viewed content.
Direct textual overlaps include the claim that specialists scanned 46 million Russian IP addresses and found 63,000 entries in permitted whitelists, identical descriptions of default-deny and fail-closed architectures, and matching explanations of ECH behavior under DPI inspection. The video also repeated an earlier factual error from the source article regarding total UDP blocking inside whitelists.
Additional videos reused findings from the MAX messenger analysis, including the behavior of class com.my.tracker.core.o.f, MediaDrm Widevine UUID handling in TEE, and the network_security_config.xml flag that permits cleartext traffic. Some material was also drawn from articles published by runetfreedom.
When contacted, the Durev VPN representative demanded proof of patents, suggested the research was generated by Claude, and later invoked fair use while refusing to add attribution. After receiving a DMCA warning, the representative stated the issue would be reviewed by their lawyer within one week. The researcher published the complete conversation and noted that the disputed segment referencing the 46-million-address scan was later edited out of the published video.
The service itself is registered in Kazakhstan. Its client uses the Happ application on non-Android platforms and offers test access for 17 rubles. Measured performance on the test profile showed 494 ms latency with 20 Mbit/s download and 46 Mbit/s upload speeds.
Related articles
Incident Reconstruction Fails When Logs Lack Time Zone Offsets and Proper Synchronization
Reconstructing security incidents from multiple log sources often collapses when timestamps lack time zone information or consistent synchronization. Events from web servers, load balancers, applications, and mail gateways can appear in physically impossible order, such as responses preceding requests or sessions closing before they open. The root causes include clock drift without NTP, mismatched reference points like UTC versus local time, and timestamps recorded at message processing rather than event occurrence. Classic BSD syslog (RFC 3164) omits both year and offset, forcing investigators to consult potentially unavailable source systems. Modern RFC 5424 provides full timestamps with offsets, making normalization possible without external context. Organizations must enforce offset-inclusive formats at ingestion, monitor actual synchronization status rather than service uptime, and document external sources whose timestamps cannot be controlled.
HTTP Methods Explained: GET, POST, PUT, PATCH, DELETE and the New QUERY Standard
HTTP methods define the actions a client requests from a server regarding a resource. The core semantics are outlined in RFC 9110, with extensions for specialized protocols. A new standardized method called QUERY was introduced in June 2026 via RFC 10008 to handle complex queries that include a request body while remaining safe and idempotent. The article details safe and idempotent properties, compares each method including GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, TRACE, CONNECT, and QUERY, and explains their correct usage to avoid breaking caches, proxies, and infrastructure expectations. It also covers WebDAV extensions and other registered methods in the IANA registry.
From Web Perimeter Breaches to Domain Takeover: How Standoff Hackbase Trains Pentesters on Real Corporate Infrastructure
wr3dmast3r, a senior pentester and BSCP certification guide author, rose to first place on the Standoff Hackbase ranking by shifting focus from initial perimeter access to full internal infrastructure compromise. The platform replicates large-scale corporate networks from various industries, forcing participants to map service relationships, harvest credentials, escalate privileges, and chain pivots across segments. Unlike CTF challenges that end with a single flag, Hackbase tasks require building complete attack paths that can lead to data theft, process disruption, or cross-domain movement. The interview highlights practical techniques such as time-boxing hypotheses, manually modeling infrastructure after automated scans, and using AI only as an information accelerator rather than an autonomous operator. wr3dmast3r also details a memorable chain that began with a bot, moved through VPN and Outlook access, leveraged SCCM tokens for privilege escalation, and ended with compromise of a second domain containing the target system.
OTUS Publishes September Digest of Free Lessons on Linux Administration, PostgreSQL, CI/CD and Infrastructure Security
OTUS has released a new digest listing free September webinars aimed at infrastructure engineers, DevOps specialists and system administrators. The program covers practical topics including Linux server configuration, PostgreSQL 18 performance tuning, high-availability clusters with Patroni, CI/CD pipelines in GitLab, eBPF observability and infrastructure security practices. All sessions are delivered by practicing OTUS instructors who share real-world production experience. Separate tracks address RAID and LVM management, GPO policies, release management in 1C environments, Go profiling, mitmproxy traffic analysis and responsible use of AI tools for incident investigation and code review. The webinars run throughout September at 19:00 or 20:00 Moscow time and require only free registration. The digest also includes sessions on career growth from tech lead to CTO and effective responsibility distribution for team leads.