Policy & Regulation

Cybersecurity news in this category

🇷🇺Jul 25

Russia's Article 10.1 on Personal Data Dissemination: Apparent and Real Contradictions in Federal Law 152-FZ

Part II of the analysis examines how the rushed redrafting of Article 10.1 between the first and second readings created serious interpretive problems in Federal Law 152-FZ. The core issues include undefined terms such as 'disclosure', conflicting definitions of 'access', 'provision' and 'dissemination' between 152-FZ and 149-FZ, and the removal of the legal basis for processing publicly available data while retaining the consent mechanism that was meant to control it. Courts have consistently held that mere openness of data does not constitute a valid processing ground, forcing subsequent operators to find their own basis under Article 6. The article highlights that the mechanism for subjects to set conditions and prohibitions was preserved, yet the underlying legal foundation that would make those rules effective was eliminated. Two possible readings of the special consent are explored, with judicial practice leaning toward the narrower interpretation that leaves conditions and prohibitions as mere additional restrictions rather than a source of authorization.

Habr
🇷🇺Jul 25

Why Deep Packet Inspection Overestimates Its Reach in Encrypted Networks

Modern encryption has fundamentally limited the effectiveness of Deep Packet Inspection systems, leaving network monitors with only metadata and behavioral patterns rather than actual content. DPI tools can still classify traffic types and apply policies based on visible flow characteristics, but they cannot read messages, files, or credentials inside properly encrypted sessions without explicit TLS inspection. The article details how TLS 1.3, Encrypted Client Hello, and QUIC further reduce passive visibility while corporate inspection remains possible only when endpoint devices trust an organizational certificate. Russian regulatory requirements around TSPU systems are discussed separately from corporate DPI use, with emphasis on the need for technical confirmation rather than assumptions. The piece also clarifies distinctions between DPI, IDS, IPS, and DLP, and explains why machine learning cannot convert metadata into decrypted payloads. Overall, the analysis shows that DPI remains useful for traffic management and known-threat detection where visibility exists, but it cannot serve as a complete security foundation.

Securitylab
🇷🇺Jul 25

How Russia's Article 10.1 on Personal Data Dissemination Emerged: Legislative History and Reform Flaws

The article examines the origins of Article 10.1 in Federal Law 152-FZ, introduced via bill 1057337-7 by deputy Anton Gorelk in in November 2020. It traces how the reform aimed to separate publication, access, extraction, and reuse of personal data but retained outdated definitions from the original law and added exceptions that created contradictions. The piece details pre-reform court rulings, including Supreme Court decisions confirming that open internet profiles do not automatically qualify as publicly available data under Article 8. It highlights the committee's own admission that the bill failed to meet its stated goals and the Legal Department's warning about inconsistent terminology around 'access' and 'transfer'. The resulting 519-FZ law is described as an imprecise attempt to solve real control problems with unsuitable conceptual tools, leaving operators unable to apply the rules consistently.

Habr
🇷🇺Jul 24

EU Imposes 21st Sanctions Package Targeting 94 Russian Banks Including Ozon Bank, Yandex Bank and WB Bank

The European Union has adopted its 21st sanctions package against Russia, placing restrictions on 94 banks, the Moscow Exchange, and several payment organizations. The measures, effective from 23 July, directly affect Rosselkhozbank, Dom.rf, MTS Bank, Ak Bars, Uralsib, Zenit, Absolut Bank, WB Bank, Ozon Bank, Tochka, Yandex Bank, and Post Bank. Personal sanctions were also imposed on Bank of Russia Deputy Chairman Sergey Belov, Russian Railways head Oleg Belozerov, and other individuals. In addition to finance, the package covers energy, trade, and cryptocurrency sectors. Russian financial institutions have stated that operations continue normally, though the Golden Crown payment system has already suspended transfers to Georgia and several other countries. Moscow Exchange and affected banks including Ozon Bank and Tochka confirmed that trading, settlements, and client services remain unchanged.

AntiMalware
🇷🇺Jul 24

Sberbank to Terminate Currency and Multicurrency Visa Cards from September 2026 Despite Prior Extensions to 2030

Sberbank announced it will cease servicing currency and multicurrency Visa cards starting September 1, 2026, including those whose validity was previously extended until 2030. The bank notified customers via SMS and advised them to close affected cards in advance through the Sberbank Online app or at a branch to avoid access issues with their funds. This decision aligns with ongoing sanctions against Russia, import substitution policies, and the gradual removal of Visa and Mastercard from the Russian market. Central Bank officials, including Elvira Nabiullina and Alla Bakina, have confirmed that international payment systems must exit Russia, with the share of Visa and Mastercard already reduced to less than 17 percent. The National System of Payment Cards continues to incur costs supporting legacy cards while promoting domestic alternatives such as Mir. Customers are encouraged to transfer remaining balances to other accounts to maintain uninterrupted access to their money.

AntiMalware
🇷🇺Jul 23

.RU and .РФ Registries Stop Disclosing Legal Entity Domain Owners in WHOIS

The domain registries for .RU and .РФ have ceased displaying detailed information about administrators that are legal entities. Previously the WHOIS service revealed the full name of the organization along with its INN tax identification number, but the records now show only the generic term Organization. The change was first noticed on 22 July by Habr user @ifap, who observed that domains previously linked to government bodies such as the Federal Protective Service no longer reveal the actual administrator. Support staff at the Coordination Center attributed the disappearance of data to unspecified technical issues and described the outage as temporary, without providing any timeline or details on the root cause. Observers note that the reduced transparency turns routine owner identification into a lengthy investigation, especially for less prominent domains. One unconfirmed theory suggests the registry is being reconfigured to meet new authentication requirements for domain administrators. It remains unclear whether the previous level of disclosure will be restored or whether the current limited view will become permanent.

AntiMalware
🇷🇺Jul 21

Advanced Windows Auditing Configuration Guide for Effective Incident Response in SOC Environments

The article provides a detailed walkthrough on configuring advanced audit policies in Windows 10 and Windows 11 to generate meaningful security events for incident investigation. It explains the role of the LSASS service in logging activities to the Security event log and contrasts basic auditing with the more granular advanced auditing that offers 53 subcategories. The guide covers enabling key subcategories such as Logon, Process Creation, and Account Management using auditpol commands, along with registry tweaks for PowerShell Script Block Logging and command-line auditing in process creation events. Practical tests demonstrate real-world events including successful and failed logons (Event IDs 4624 and 4625), process creation with arguments (Event ID 4688), and user account creation (Event IDs 4720 and 4732). All steps are performed on a VMware Workstation virtual machine running Windows 10 Pro 22H2 to avoid impacting production systems.

Habr
🇷🇺Jul 21

Russia's Supreme Court Bans Silent Crow and Cyberpartisans BY as Extremist Organizations

The Supreme Court of the Russian Federation has officially recognized the hacker groups Silent Crow and Cyberpartisans BY as extremist organizations and banned their activities in Russia. The closed-door ruling, issued at the request of the General Prosecutor's Office, accuses both groups of conducting joint cyberattacks against Russian and Belarusian critical information infrastructure with the aim of destabilizing the political situation and achieving an unconstitutional change of government. Cyberpartisans BY are described as part of the Belarusian association Supratsiv, which allegedly seeks a violent overthrow of the constitutional order, and are linked to the banned Polk named after Kastus Kalinouski as well as Ukrainian military information-psychological operations units. Silent Crow, previously known as CyberWar and Cyber LegionsUA, is portrayed as a pro-Ukrainian collective of politically motivated hacktivists whose primary objective is to damage Russian state bodies, companies, and critical infrastructure. Both groups are held responsible for attacks on Aeroflot IT systems, Rostelecom databases, Rosreestr servers, and the Belarusian Railway infrastructure. Participation in or support for these organizations now carries legal liability under Russian law.

AntiMalware
🇷🇺Jul 21

How CISOs Can Speak to CEOs: Translating Cyber Risks into Business Impact and Financial Consequences

The July 2025 Aeroflot cyber incident, claimed by Silent Crow and Belarusian Cyber-Partisans, demonstrated how technical vulnerabilities quickly translate into canceled flights, regulatory investigations, stock market reactions, and direct executive accountability. The article examines the persistent communication gap between CISOs, who focus on metrics like EDR coverage and mean time to detect, and CEOs, who prioritize costs, operational disruptions, revenue loss, and personal liability. Research from EY and Splunk highlights differing perceptions of threats and success measures, while real-world cases such as Marks & Spencer, Jaguar Land Rover, Clorox, Change Healthcare, SolarWinds, and Uber show how contractor weaknesses, missing MFA, and delayed disclosures lead to hundreds of millions in damages and legal actions. Regulatory developments, including SEC charges against CISOs and Russia's 420-FZ with turnover-based fines, further force cybersecurity discussions into the boardroom. The piece provides a practical translation table showing how technical warnings should be reframed using concrete business scenarios and financial impacts. It concludes that both CISOs and CEOs must initiate conversations around unacceptable events, downtime costs, and risk reduction versus post-incident consequences.

Securitylab
🇵🇹Jul 21

EU Forces Google to Open Android Microphone, Camera and Screen Access for Rival AI Assistants

The European Union has ordered Google to provide competing AI assistants with the same level of access to sensitive Android resources that is currently reserved for Gemini. The ruling covers eleven system functions, including voice activation, home button integration, background execution, and on-device AI model access. Rival assistants will also gain real-time environmental data streams from the microphone, camera, screen, and speakers under identical consent and notification rules applied to Google services. Additional capabilities include cross-app interaction, messaging, scheduling, device settings control, and multi-step task automation. Screen automation will allow assistants to operate apps inside a virtual window while the user performs other activities. Most changes are scheduled for Android 18 by 1 August 2027, while simultaneous activation of multiple assistants by voice keyword will arrive in Android 19 no later than 1 August 2028. Access to the most sensitive functions may require objective security certification and explicit user authorization.

BoletimSec
🇷🇺Jul 20

Walk In, You've Been Recognized: The Evolution of Identification Technologies in Modern Access Control Systems

PERCo has expanded its PERCo-Web access control system with new BLE-enabled readers, companion mobile apps, and a joint facial recognition solution developed with the CRТ group. The update provides an opportunity to examine how identification methods in physical access control have developed without any single technology fully displacing the others. Traditional proximity and MIFARE cards remain the foundation, while QR codes, NFC, BLE, and biometrics each occupy specific niches based on convenience, security, and regulatory requirements. Russian Federal Law 572-FZ has fundamentally changed facial biometrics deployment by mandating use of the Unified Biometric System (EBS) or accredited commercial systems (KBS) for authentication. The article explains the technical workflow from reader to controller, the cryptographic protections of modern cards, the contactless advantages of BLE, and the privacy and compliance considerations that now make facial recognition a 'technology of trust' rather than simple convenience.

Habr
🇷🇺Jul 20

Russian Users Report Widespread App Store Outages as Roskomnadzor Denies Any Role in Restricting Access

Russian users began experiencing technical problems with the App Store starting early in the day, with the monitoring service Sboy.rf receiving 251 complaints about instability and failed downloads. The majority of reports originated from Moscow, accounting for 20 percent of cases, followed by Saint Petersburg at 13 percent and several other regions including Udmurtia, Kursk, Rostov, Bryansk oblasts and Stavropol Krai each contributing 5 percent. Affected users described inconsistent behavior of the App Store application itself along with difficulties downloading games and other software, where the Get button would appear but actual downloads would succeed only sporadically. In response to the growing number of reports, Roskomnadzor quickly issued a brief statement clarifying that it is not imposing any restrictions on access to the App Store. The exact cause of the disruptions remains unknown, Apple has not provided any official comment, and the scale of the incident is considered limited since only several hundred users have reported issues and not everyone is affected. Standard troubleshooting steps such as verifying internet connectivity, restarting the App Store application, and waiting for service restoration have been recommended to users.

AntiMalware
🇷🇺Jul 17

VK Apps Remain Downloadable in US Google Play Despite Removal in Russia and Turkey Amid Sanctions

The removal of VK services from Google Play has proven to be less global than initially reported, with applications still accessible to users whose Google accounts are registered in the United States region. Testing revealed a clear geographic pattern: the apps are unavailable in Russian and Turkish storefronts but remain fully visible and installable under the American region. The services disappeared from the store on July 16, prompting VK to confirm that already installed applications will continue functioning without restrictions and directing users to alternative stores such as RuStore. The exact cause of the regional discrepancy remains unclear and may relate to Google Play configuration settings, ongoing sanctions against Russia, distribution policies, or simple catalog synchronization delays. In a related development, VK users have begun receiving notifications urging them to switch to the vk.ru domain, which the company states offers superior speed and reliability and will now serve as the primary address.

AntiMalware
🇷🇺Jul 16

VK and MAX Apps Removed from Google Play Store Amid EU Sanctions on Russian Company

VK and its national messenger MAX have been removed from the Google Play Store following the European Union's decision to add the parent company to its sanctions list. The company confirmed that the apps are no longer available for new downloads or updates through Google, but existing installations continue to function normally with full access to messaging, calls, events, and push notifications. Users can obtain updates and new installations through alternative Android stores including RuStore, Huawei AppGallery, Samsung Galaxy Store, and Xiaomi GetApps, or receive in-app update prompts when new versions become available. The removal comes shortly after similar apps such as Dzen and VK Video disappeared from the Apple App Store last month. Although the exact reasons were not disclosed in VK's statement, the sanctions were triggered specifically by the development of the MAX messenger as a national platform. This development highlights how regulatory actions are reshaping app distribution channels for Russian digital services, positioning RuStore as a primary rather than backup marketplace.

AntiMalware
🇷🇺Jul 16

Russian Players Report Mass Launch Failures in Diablo IV, Marvel Rivals and Other Online Games Amid Suspected Regional Restrictions

Russian gamers are experiencing widespread problems launching popular online titles including Diablo IV, Marvel Rivals, and Neverness to Everness, with games either failing to start or disconnecting at the server connection stage. Reports on Steam highlight the recurring Server Connection Failed error in Marvel Rivals, where standard troubleshooting steps such as client restarts, file verification, and account re-logins provide no relief for many users. The issues coincide with mentions of content web filtering systems and follow a partial Steam outage on July 14 that already disrupted platform sections and page loading. Players are divided between theories of deliberate regional blocks or ordinary technical faults, yet neither game developers nor Russian authorities have issued any official statements. Steam itself remains accessible, allowing users to reach their libraries and the Play button, but actual gameplay connections have turned into an unpredictable lottery. Without confirmed explanations, affected players can only continue testing connections and hoping for successful launches.

AntiMalware
🇷🇺Jul 16

Google to Allow Competing Android App Stores Directly Inside Play Store After Epic Games Court Ruling

Google is preparing to open its official Google Play store to rival Android app marketplaces starting July 22, following a court order issued in the long-running antitrust lawsuit with Epic Games. The ruling stems from the 2020 Fortnite dispute over Google’s 30% commission and direct in-app purchases that bypassed the platform’s billing system. A federal judge determined that Google had unlawfully prevented device makers from promoting or pre-installing alternative app stores, thereby reinforcing Google Play’s monopoly position. As a result, approved third-party stores will now be distributed directly through Google Play, receive default access to its app catalog, and be subject to an annual $5,000 verification fee. Developers retain the right to block distribution of their apps on specific stores, while participating marketplaces must meet strict security, copyright, and update obligations or risk removal if suspicious installations exceed 1%. Although the changes are expected to apply primarily in the United States, the decision marks a fundamental shift in how Google must accommodate competitors within its own ecosystem.

AntiMalware
🇷🇺Jul 15

UK Plans Nighttime Social Media Curfew and Addictive Feature Restrictions for Teens from 2027

The United Kingdom has announced plans to restrict social media access for teenagers aged 16-17, introducing a nightly curfew from midnight to 6 a.m. starting in spring 2027. In addition to the time-based ban, platforms will be required to disable addictive features such as infinite personalized feeds, autoplay videos, Reels, and TikTok-style content by default for this age group. The measures are designed as a transitional step ahead of a complete social media ban for children under 16, which will also take effect in spring 2027. Government officials cite a pilot study involving 300 participants that demonstrated improved sleep quality and concentration after implementing similar nighttime restrictions. The policy also targets AI chatbots, mandating mandatory breaks for minors and potentially banning services that provide dangerous or unverified mental health advice. Schools will incorporate new digital literacy modules covering safe AI usage, detection of deepfakes, disinformation, and harmful content such as violent or misogynistic material.

AntiMalware
🇷🇺Jul 15

US Prepares for Free Chinese AI Models Distributed Like Torrents, Weighs Policy Shift on Open-Source Systems

The Trump administration is actively discussing uniform capability requirements for American open-source AI models, using advanced Chinese systems as the benchmark. Chinese developers are expected to release powerful Mythos-class models within the next 6–12 months that anyone can freely download, run locally, fine-tune, and integrate without developer oversight. This development creates a policy dilemma for Washington, as overly strict controls risk slowing domestic innovation while failing to prevent the spread of foreign technology. China is deliberately promoting open AI releases to expand the global reach of its developers, especially after restrictions limited the availability of leading U.S. models. At the same time, the industry is exploring superconducting cables and optical interconnects to curb the rapid growth in data-center electricity consumption, which already accounts for 1.5% of global power usage. The Washington Post notes that long-term energy forecasts may be overstated if these efficiency technologies are adopted at scale.

securitylab_n
🇷🇺Jul 15

Google Urges European Commission to Stop Mass Blocking of IP Addresses, DNS Services and VPNs in Piracy Fight

Google has called on the European Commission to abandon the widespread practice of blocking IP addresses, DNS services and VPNs as a means of combating pirate sites, describing the approach as both ineffective and risky. The company explained that such blocks fail to remove illegal content permanently and allow users to quickly switch to alternative DNS providers, VPNs or new addresses, enabling piracy to continue uninterrupted. Blocking entire IP ranges is particularly problematic because a single address or range is often shared by multiple unrelated legitimate websites and cloud services, leading to collateral damage for lawful users. Google cited the December 2019 incident in Portugal, where ISP blocks on virtual IP addresses disrupted important Google services and affected Google Cloud customers sharing the same infrastructure. A similar outcome followed the blocking of The Pirate Bay in the United Kingdom, after which lists of proxy servers rapidly appeared online to restore access. The search giant stressed that these measures only create temporary obstacles rather than eliminating the source of pirated material and increase the chance of accidentally disabling legitimate online resources.

securitylab_n
🇷🇺Jul 14

Kremlin Spokesperson Peskov Labels EU Sanctions Against MAX Messenger as Manifestation of Repressive Policy

Dmitry Peskov, the press secretary to the Russian president, has strongly condemned the European Union's decision to impose sanctions on the Russian messenger MAX, describing the move as absolutely absurd and a clear demonstration of the repressive character of European sanctions policy. The EU added the parent company VK and its subsidiary LLC Communication Platform, the developer and operator of MAX, to its sanctions list due to their connection with Russia's national messenger. This action follows the removal of the VK and MAX applications from the Apple App Store in June, although already installed versions continue to function without the ability to receive updates through the store. VK has stated that the sanctions have not impacted the messenger's operations and that MAX along with other services remain fully available to users in normal mode. The situation raises questions about whether further barriers will emerge around MAX beyond the current sanctions listings and App Store restrictions, with political rhetoric currently outweighing any significant technical consequences.

AntiMalware
🇷🇺Jul 14

RZD Trunk Quantum Network Obtains FSTEC Attestation and Enters External Commercial Market

Russia’s state-owned railway operator RZD has successfully passed certification by the Federal Service for Technical and Export Control (FSTEC), confirming that its trunk quantum network meets the requirements for information systems of the second protection class. The attestation enables RZD to begin offering quantum-secured communication services to external organizations, including banks, industrial enterprises, medical institutions, and transport companies. Quantum key distribution technology allows any interception attempt to be detected because interference with the quantum channel alters the state of transmitted particles, providing a level of security far beyond conventional encryption methods. The network is already being tested by the Bank of Russia, the Federal Treasury, the Financial University, and several major banks, with potential clients also identified in the oil-and-gas, industrial, healthcare, and transportation sectors. The Ministry of Digital Development considers the technology sufficiently mature and has included further expansion of the quantum network through 2030 in the national “Data Economy” project roadmap. As a result, RZD is gradually transforming from a traditional carrier of passengers and cargo into an operator of protected digital highways.

AntiMalware
🇷🇺Jul 14

Telegram Loses Global Short Links as t.me Domain Disabled Worldwide by .me Registry

On July 13, users worldwide discovered that Telegram’s short links in the t.me format stopped opening in web browsers, although the messenger itself continued to function normally. The issue was first reported by the Russian publication Kode Durova and affects only external browser access, while links remain fully operational inside the Telegram desktop client and mobile applications. According to preliminary findings, the domain was effectively removed from the DNS system at the registry level of the .me top-level domain, which belongs to Montenegro and is operated by the company doMEn. The exact reason for the deactivation remains unknown, with possible explanations including a legal dispute, routine verification, government requests, or a violation of the domain zone’s rules. Notably, the t.me domain is registered to Telegram until 2035, ruling out simple expiration or administrative oversight. As a result, users are currently advised to open t.me links directly through the Telegram app while waiting for the domain to be restored in the global DNS.

AntiMalware
🇷🇺Jul 13

EU Adds Russian Tech Giant VK to Sanctions List Over Development of National Messenger MAX

The European Union has included VK in its sanctions regime, targeting the parent company of Russia’s largest social media platforms including VKontakte and Odnoklassniki. The move was triggered by VK’s ownership of the developer behind the national messenger application MAX, which Russian authorities have been promoting as a domestic digital platform. According to the Council of the EU, VK serves as the parent structure for LLC Communication Platform, the entity directly responsible for creating and operating MAX. The sanctions decision was formally published on 13 July in the Official Journal of the European Union, marking the first time Brussels has directly sanctioned a major Russian IT holding in connection with a consumer messaging service. While the exact operational and commercial consequences for VK, its subsidiaries, and international partners remain unspecified in the official notice, the action extends EU restrictive measures beyond traditional sectors such as banking, energy, and manufacturing into the Russian technology industry. VK’s press service stated that the sanctions do not affect the functioning of VK or MAX and that all applications and services remain available to users without disruption.

AntiMalware
🇷🇺Jul 13

Russia to Mandate Gosuslugi Authentication for Hosting Providers, Further Reducing Anonymity in Runet

The Russian Ministry of Digital Development (MinTsifry) is advancing plans to require all hosting providers to identify clients exclusively through the Gosuslugi portal and the ESIA system. The measure aims to ensure that every allocated IP address is linked to a verified individual, going beyond current methods such as email or bank card verification. This approach mirrors the identification rules already enforced since September for .ru, .рф, and .su domain registrations and renewals. Industry reactions are divided: while some providers like Turbo Cloud support the initiative for combating fraud, others warn of high implementation costs and significant client losses. Smaller users, including students and independent developers, may migrate to foreign hosting services, and foreigners could face restricted access without alternative verification options.

AntiMalware
🇨🇳Jul 12

Phase II of National 100-City FDE Frontier Deployment Engineer Onboarding Program Officially Launches

The second phase of the nationwide "Hundred Cities On-the-Job Plan" for FDE Frontier Deployment Engineers has been announced, expanding opportunities across China. The initiative targets experienced engineers specializing in advanced deployment technologies and aims to place professionals in key urban centers. Building on the success of the first phase, this new round seeks to strengthen technical capabilities in critical infrastructure and cybersecurity domains. Participants will receive structured onboarding, training, and direct placement support in multiple cities. The program underscores growing demand for specialized deployment expertise amid rapid digital transformation.

安全客