Recent content by Depov

  1. Depov

    Can the phone off spy on you

    What happens when you turn off your smartphone When you shut down, the operating system completes processes, closes applications and disables the main processor. The smartphone stops being "smart": no internet, no apps, no screen. But inside the device there is not one processor - and here...
  2. Depov

    Comparison of IS tools: choice for the task

    SIEM vs Vulnerability Scanner vs Pentest: Three Tasks and Three Modes The difference between classes takes place along the line "proactive - reactive - verification." As Invicti articulates: the vulnerability scanner works proactively - finds weaknesses before the attacker exploits them. SIEM...
  3. Depov

    Forenzika what is it - from stress to career

    Forenzika - what it is and how to pronounce it properly The impact in the word "forenza" is placed on the second syllable: foreZine. By ear - [FarEnzika], with a shock "e." The word is a calca with the English forensics, which goes back to the Latin forensis - "related to the forum." In ancient...
  4. Depov

    DevOps, data security and retail automation: how IT professionals find projects and verified employers in 2026

    The development of large food and FMCG retail has long gone beyond traditional trade. Today, key market players are complex IT ecosystems with their own data centers, distributed microservice architectures, dynamic pricing algorithms and highly loaded express delivery services.In the face of...
  5. Depov

    Static side-channel attack: generator freeze

    Static side-channel attacks: why you need to stop a clock generator Classic dynamic side-channel attacks - DPA (Differential Power Analysis) and CPA (Correlation Power Analysis) - operate transition processes in the circuit during computing. Each clock of operation of the cryptographic module...
  6. Depov

    MCP AI agent security: attack vectors

    Vulnerabilities of the Model Context Protocol through the eyes of the attacker MCP works on a client-server model with three components. Host - AI-app (Claude Desktop, IDE-copy, custom agent). Client - manages connections and communicates context between LLM and servers. Server - provides tools...
  7. Depov

    Vibe coding security: 74 CVE in three months

    Scale of the problem: data from studies 2025–2026 Veracode tested more than 100 LLM on code generation tasks in Java, Python, C# and JavaScript on four categories of vulnerabilities from OWASP Top 10: SQL injection (CWE-89), cross-site scripting (CWE-80), log injection (CWE-117) and weak...
  8. Depov

    Pentest restrictions: what the test checks and what is not

    What is a Pentest in Terms of scope Pentest - controlled simulation of an attack on a pre-agreed set of systems. The key word here is "pre-agreed." Before starting work, the pentester and the customer sign Rules of Engagement, where it is clearly prescribed: which IP addresses, applications and...
  9. Depov

    MLSecOps: protection of ML-pail from data to sale

    Why DevSecOps for Machine Learning Doesn't Work Out of the Box In the usual DevSecOps we protect code, dependencies and infrastructure. SAST searches for injections in source, SCA checks CVE in packets, DAST tests HTTP-endpoints. For the usual application - enough. ML-pipeline adds artifacts...
  10. Depov

    Ethics and Safety in Biometrics and Behavioral Authentication: A Balance of Amenity and Risk

    Biometrics and behavioral authentication have become a prominent part of modern access protection because they reduce password dependence, increase in-entry convenience, and reduce some of the phishing risks. At the same time, such mechanisms affect not only security, but also confidentiality...
  11. Depov

    Terminal for Pentester: Alias, AI and automation

    For the last year and a half, I have been pushing LLM into its terminal chains - the result, to put it mildly, mixed. On one engagement, Ollama with mistral:7b generated a working awk parser to output nmap in 15 seconds - with my hands I would pick five minutes. On the next project ChatGPT...
  12. Depov

    Analysis of the attack SSTI Standoff 365: from injection to root

    Operation of Templater Vulnerability: SSTI Reconnaissance and Detect Any hacking of a web application on a cyber battle starts with intelligence. nmap -sV -sC by host Messenger showed three open ports: SSH (22), nginx (80) and tcpwrapped (3000). On the 80's - self-written messenger in...
  13. Depov

    Race condition in Linux kernel: delay injection and MACcConc

    ight years. Exactly so much condition race CVE-2017-2636 (CVSS 7.0 HIGH) lived quietly in the mainline Linux core. The Committee be10eb75893 brought the race into the driver n_hdlc in 2009, syzkaller came across a suspicious crash only in 2017 - and between the detection and stable reproduction...
  14. Depov

    How to remove information about yourself from the Internet

    Intelligence on MITRE ATT&CK: why attack your data Before you delete something, it is worth to understand what the enemy is looking for. Attackers work on specific techniques from MITRE ATT&CK matrix, Reconnaissance tactics: Read more in our the Osint Review for Information Security Specialist...
  15. Depov

    Cyberweapons are now measured in scores. The leader scored 80 out of 100

    AI models for the first time received their own "cyberweapons index," which evaluates not knowledge of the hacking, but the ability to independently conduct a real chain of attack. In the first Cyber Weapon Index, Booz Allen tested 18 American and Chinese models, and the result was extremely...
Top Bottom