Alive Photos: Creating a Private Steganographic Audio Player with Python and PyQt6
Hello, tekkix!
Hello, tekkix! Every developer reaches a point in a serious project when they want to take a break and write something just for fun. Something simple, classic, and yet…
In this article, I will explain how to add Differential Privacy mechanisms to your ETL and analytical pipelines in Python to protect user data while maintaining the quality…
My friend passed away recently.
Hello! We share with you the material prepared by Roman Strelnikov — head of the information security department at Bitrix24. Roman is the person who controls everything…
This article is dedicated to the bug in Power Dependency Coordinator, patched by Microsoft in April of this year.
When I started writing the Node.js service that was supposed to integrate with the LLM model, I already understood that access to some foreign APIs from Russia could…
If you enter the phrase "most famous female hackers" into any foreign search engine, the impartial search engine will instantly generate a list, with Kristina Svechinskaya…
As a result of my security research of 3,000 Russian frontend applications, it was discovered that Bitrix CMS has been transmitting website visitors' personal data to…
Imagine you're running a call center and decide to implement an open LLM for automating communication. Everything works great—until a scammer whispers a strange phrase,…
Hello, reader. In front of you is the second article about a serious vulnerability I found in UEFI-compatible firmware based on the Insyde H2O platform, which I named…
Electronic signatures have long been an integral part of corporate processes. They are used to sign crucial documents, confirm transactions, and conduct financial operations.…
Many remember the year-before-last incident with the Man-in-the-Middle attack on the XMPP service jabber.ru. This story caused a lot of noise, but I think the main point…
Finite fields, hash mincers, covert radio channels, and trojans soldered into silicon. While we pride ourselves on AES-256 locks, intelligence agencies seek workarounds:…
Let’s recall the main idea of ZT for admin panel protection: you can only access the admin panel by providing a certificate that’s stored in a secure device keystore.…
HTTPS makes it possible to implement secure interaction with the DNS resolver interface, concealing the DNS traffic that would otherwise be transmitted in plain text.…
Incident Description: The attacker uses stolen credentials to access the company’s server, website, or cloud.