Pull to refresh

All streams

Show first
Period
Level of difficulty

We, as the World

Level of difficultyEasy
Reading time8 min
Reach and readers2.2K

Everything we surround ourselves with is both the result of our thoughts and what we think with. Roads set geography, speed, distance, space. Trinkets on the dresser are memory and emotion. Tools on the desk are plans and skills.

Our environment doesn't tell us what to do; it leads us.

Some things lead more gently, some more firmly, but we are not only a brain in a skull. We are also what was created before us and what we created ourselves.

This article is about what surrounds us and how it relates to LLMs and agents.

Read more

Tcl/Tk: SVG‑widgets. In memory of Mats Bengtsson

Level of difficultyMedium
Reading time18 min
Reach and readers4K

Few people do not recognize the convenience of tcl/tk in gui development. Moreover, it is tk called Tkinter, and not something else, that is directly integrated into Python, and into many other languages. But as soon as you show an application in which the gui is developed in tk, you can immediately hear - again, this poor, primitive, at best outdated interface. And here I agree with these critics. There have been many attempts to improve the presentability of tk widgets (in addition to ttk widgets), some of which can be viewed here. But even they look a little pale against the background of the user interface on mobile phones, qt or gtk.

My expectations related to the release of tcl/tk-9.0 were also not fulfilled in terms of the appearance of the widgets.

And since I'm a tcl/tk fan, I really want to fix this situation. It is clear that this problem can be solved by using SVG-graphics. Support for SVG-graphics in tcl/tk is implemented through the tkpath package, authored by Mats Bengtsson:

Read more

BlueSec: an open competition where AI agents investigate security incidents

Reading time7 min
Reach and readers2.1K

Hi all! I'm Andrey Kuznetsov, and I work on ML in cybersecurity. In our community, FalsePositive, we break down research papers and keep up with what's new in ML. Now we're launching BlueSec, an open competition where AI agents investigate security incidents. Each agent starts with a single piece of evidence, reconstructs the attack on its own and delivers a verdict. The platform scores it on accuracy and how few tool calls it needs. If you work with LLMs and agents, this is a chance to test your skills and your agent's on problems at the intersection of ML and cybersecurity, a field that I think is undergoing even more change than software development.

The competition runs online from September 25 to October 10, and you can join from anywhere in the world. The final will be held in Moscow and St. Petersburg, both on-site and online. Sign up on the website.

In this post I'll cover: why we built this kind of competition, how the tasks and scoring work, where to start if you've never built an agent or investigated an incident.

Read more

Biometrics vs. the Paperclip: A Breakdown of Fingerprint Locks and a Basic Security Audit

Reading time14 min
Reach and readers1.3K

One evening, while idly scrolling through a popular online marketplace, I happened upon an electronic lock with a fingerprint scanner. The description painted a picture of a nearly perfect device for a low price: biometric authentication, water resistance, and some sort of "unique" microchip. It sounded convincing, but a researcher's nature is to question marketing claims rather than take them at face value. So, naturally, the very next day, the lock was on my desk. From there, a familiar pattern emerged: one interesting device soon leads to a few more... 

My name is Denis Astafiev, and I am a lead hardware security researcher at Bastion—a Russian cybersecurity company. As part of my job, I regularly disassemble  various devices to see if the manufacturer's claims on the box hold up.

Today, we'll be examining three biometric locks to find the weak spots in their security.

Let me be clear: the goal of this article is not to subject a cheap Chinese lock to an exhaustive, lab-grade analysis at all costs. Instead, I want to use a simple, accessible example to show how a basic hardware security audit is typically conducted and why it's best to start with the simplest attacks, not the most complex ones.

Read more

Recovering EVTX records: carving techniques

Reading time18 min
Reach and readers1.2K

Windows event logs in EVTX format are a key source of telemetry for incident response. They provide evidence of attacker activity on a host and are often the only remaining record of what happened during account compromise, lateral movement, or persistence attempts.

Attackers often try to destroy these logs by clearing them with wevtutil cl, encrypting them, or wiping disks. Ransomware operators increasingly target entire virtual machine disk images, including VDI, VMDK, and VHDX files. The file system of the affected volume may become inaccessible or too badly damaged for standard tools to mount: for example, if the master file table (MFT) has been destroyed or the partition table is missing.

One option is to reconstruct the file system manually by locating lost partitions and recovering deleted files. However, this takes time and may still leave gaps in the event history or severely corrupted EVTX files. This is where carving comes in — a byte-level search for EVTX signatures in raw data from a disk or volume image, a memory dump, a pagefile, or a VSS snapshot. It can recover surviving event data without relying on the file system.

At the Positive Technologies Expert Security Center, our Incident Response team (PT ESC IR) prioritizes automated artifact parsing to detect malicious activity and reconstruct incidents faster. Our processing pipeline is written primarily in Go. We could not find a suitable open-source library that combined EVTX parsing and carving. Existing parsers either crash regularly or consume too much memory, which hinders automation. We developed our own library that parses intact EVTX files, recovers data even when checksums do not match or files are corrupted, and performs event carving from bit-for-bit copies, memory dumps, and virtual disk images.

Read more