20 July 2026
Ссылка
click to show
click to show
What is File Integrity Monitoring (FIM)?
File Integrity Monitoring (FIM) is a security control that detects unauthorized changes to files, directories, registry keys, configuration files, and other critical system objects.
The basic idea is simple:
Create a trusted baselineCalculate a cryptographic hash (SHA-256, SHA-512, etc.) of important files.
Store metadata such as permissions, owner, timestamps, ACLs, and size.
Continuously monitorWatch for changes in real time (using mechanisms like Linux inotify or Windows USN Journal) or perform scheduled scans.
Compare with the baselineDetect whether a file has been:
Modified
Created
Deleted
Renamed
Permission changed
Ownership changed
Generate an alertSend the event to the SIEM for correlation and investigation.
https://t.me/unixmens
#yashar_esmaildokht #deops #security #linux #wazuh #siem
71 · Ссылка
click to show
click to show
Ссылка
click to show
click to show
Ссылка
click to show
click to show
Healthcare payer organizations are navigating a complex intersection of rising member expectations, strict regulatory mandates, and aging technology infrastructures. Modernizing these environments to accelerate claims adjudication and improve the member experience is a key priority for many executives. However, the path to modernization is often blocked by isolated team structures and technical debt.To bridge this gap, many payers are turning to automation, such as Red Hat Ansible Automation Platform, as a strategic layer across their enterprise. However, despite the clear business outcomes, s
via Red Hat Blog https://ift.tt/UcLBIGw
109 · Ссылка
click to show
click to show
This guide provides working steps on deploying CloudBees CI on OpenShift. My first CloudBees CI deployment on OpenShift looked successful until the Operations Center entered
via kifarunix.com https://ift.tt/mo8uixw
114 · 21 July 2026
Фотография
click to show
click to show
بانک مرکزی: شاپرک هک نشده؛ گواهینامه امنیتیاش لغو شده است
⬛️بانک مرکزی با رد شایعه حمله سایبری به شاپرک، اعلام کرد که گواهینامه فنی-امنیتی این شرکت بدون اطلاع قبلی لغو شده است.
به گزارش دیجیاتو، بانک مرکزی در اطلاعیهای اعلام کرد:
⬛️«در ادامه اقدامات خصمانه رژیم جنایتکار آمریکا در حوزههای نظامی و سایبری، گواهینامه فنی-امنیتی شرکت شاپرک بدون هیچ اعلام قبلی از طرف تأمینکننده خارجی لغو شده است. این اقدام با هدف ایجاد اختلال در عملکرد درگاههای پرداخت اینترنتی انجام شده؛ با این وجود به هموطنان اطمینان داده میشود خدمات شرکت شاپرک هیچگونه اختلالی زیرساختی نداشته و با اتخاذ تدابیر جایگزین، خدمترسانی طبق روال قبلی انجام میگردد.»
بانک مرکزی افزوده است:
⬛️«تیمهای فنی شرکت شاپرک و شبکه پرداخت کشور در تلاش هستند تا پیش از بروز اختلال در روال خدماتدهی، نسبت به اتخاذ تدابیر فنی جایگزین اقدام کنند. بنابراین هیچگونه نگرانی از این بابت وجود نداشته و روند خدماتدهی بدون وقفه ادامه خواهد داشت.»
135 · id 1005983125بانک مرکزی: شاپرک هک نشده؛ گواهینامه امنیتیاش لغو شده است
⬛️بانک مرکزی با رد شایعه حمله سایبری به شاپرک، اعلام کرد که گواهینامه فنی-امنیتی این شرکت بدون اطلاع قبلی لغو شده است.
به گزارش دیجیاتو، بانک مرکزی در اطلاعیهای اعلام کرد:
⬛️«در ادامه اقدامات خصمانه رژیم جنایتکار آمریکا در حوزههای نظامی و
Central Bank: Shoprak is not hacked; Its security certificate has been revoked
Rejecting the rumor of a cyber attack on Shoprak, the Central Bank announced that the technical-security certificate of this company was canceled without prior notice.
According to Digiato, the central bank announced in a statement:
⬛️ "Following the hostile actions of the American criminal regime in the military and cyber fields, the technical-security certificate of Shapark Company has been canceled without any prior notice from the foreign supplier. This action was carried out with the aim of disrupting the functioning of online payment portals; Nevertheless, the compatriots are assured that the services of Shapark Company have no infrastructure disruptions and by adopting alternative measures, service delivery will be carried out according to the previous routine.
The central bank added:
⬛️ "Technical teams of Shoprak and the country's payment network are trying to adopt alternative technical measures before disruptions occur in the service routine. Therefore, there is no concern about this and the service process will continue without interruption."
id 1005983125Фотография
The Financial Times reported that the Wisconsin Public Utilities Commission has refused to reconsider the regulations imposed on We Energies. According to these provisions, Oracle must provide a guarantee worth seven billion dollars at an annual cost of more than $100 million.
Oracle's nearly one gigawatt data center in Port Washington, Wisconsin is one of the company's key investments to implement a $300 billion contract with OpenAI to provide computing power. However, the rising cost of local power supply exacerbates the challenges facing Oracle's AI plans, including rising debt and rapidly draining cash.
According to the tariff of "V Energies" company for very large subscribers, all the builders of data centers whose "S&P" credit rating is lower than "A-" are required to provide the collateral in the form of cash or letter of credit. The Financial Times reported that the amount of this bond will be determined based on the value of the power plants and transmission lines that will be built to serve the data center.
At the time of drafting these regulations, Oracle's credit rating was "BBB".
روزنامه فایننشال تایمز نوشت که کمیسیون خدمات عمومی ویسکانسین از تجدیدنظر در مقررات تعیینشده برای شرکت برق «وی انرژیز» (We Energies) خودداری کرده است. بر اساس این مقررات، اوراکل باید ضمانتنامهای به ارزش هفت میلیارد دلار با هزینه سالانه بیش از ۱۰۰ میلیون دلار ارائه دهد.
مرکز داده نزدیک به یک گیگاواتی اوراکل در پورت واشنگتنِ ویسکانسین، یکی از سرمایهگذاریهای کلیدی این شرکت برای اجرای قرارداد ۳۰۰ میلیارد دلاری با شرکت اوپنایآی به منظور تأمین توان رایانشی محسوب میشود. با این حال، افزایش هزینههای تأمین برق محلی، چالشهای پیش روی برنامههای هوش مصنوعی اوراکل، از جمله افزایش بدهی و مصرف سریع نقدینگی، را تشدید میکند.
بر اساس تعرفه شرکت «وی انرژیز» برای مشترکان بسیار بزرگ، تمامی سازندگان مراکز داده که رتبه اعتباری «اساندپی» آنها کمتر از «A-» باشد، موظفاند وثیقه را بهصورت نقدی یا اعتبارنامه ارائه کنند. فایننشال تایمز گزارش داده است که میزان این وثیقه بر مبنای ارزش نیروگاهها و خطوط انتقالی که برای خدمترسانی به مرکز داده احداث میشوند، تعیین خواهد شد.
در زمان تدوین این مقررات، رتبه اعتباری اوراکل «BBB» بود که دو پله پایینتر از حداقل رتبه مورد نیاز قرار داشت.
اوراکل ماه گذشته از یک قاضی در ویسکانسین درخواست کرد این مقررات را لغو کند و به شرکت «وی انرژیز» اجازه دهد از اجرای این الزام صرفنظر کند.
طبق گزارش فایننشال تایمز، اوراکل اعلام کرده است که اجرای این مقررات میتواند هزینههای مالی سنگینی را به شرکت تحمیل کرده و سرمایهگذاریهای آینده در ویسکانسین را با کاهش انگیزه مواجه کند.
با این حال، نماینده کمیسیون خدمات عمومی ویسکانسین روز دوشنبه به فایننشال تایمز گفت که این نهاد از اقدام در قبال این دادخواست خودداری کرده است.
اوراکل نیز به فایننشال تایمز اعلام کرد همچنان امیدوار است کمیسیون با در نظر گرفتن فرصتهای شغلی و رشد اقتصادی ناشی از اجرای این پروژه ۱۵ میلیارد دلاری، در موضع خود تجدیدنظر کند.
84 · id 1005983125روزنامه فایننشال تایمز نوشت که کمیسیون خدمات عمومی ویسکانسین از تجدیدنظر در مقررات تعیینشده برای شرکت برق «وی انرژیز» (We Energies) خودداری کرده است. بر اساس این مقررات، اوراکل باید ضمانتنامهای به ارزش هفت میلیارد دلار با هزینه سالانه بیش از ۱۰۰ میلیون دلار ارائه دهد.
مرکز داده نزدیک به یک گیگاو
The Financial Times reported that the Wisconsin Public Utilities Commission has refused to reconsider the regulations imposed on We Energies. According to these provisions, Oracle must provide a guarantee worth seven billion dollars at an annual cost of more than $100 million.
Oracle's nearly one gigawatt data center in Port Washington, Wisconsin is one of the company's key investments to implement a $300 billion contract with OpenAI to provide computing power. However, the rising cost of local power supply exacerbates the challenges facing Oracle's AI plans, including rising debt and rapidly draining cash.
According to the tariff of "V Energies" company for very large subscribers, all the builders of data centers whose "S&P" credit rating is lower than "A-" are required to provide the collateral in the form of cash or letter of credit. The Financial Times reported that the amount of this bond will be determined based on the value of the power plants and transmission lines that will be built to serve the data center.
At the time these regulations were drafted, Oracle's credit rating was BBB, two notches below the minimum required rating.
Last month, Oracle asked a judge in Wisconsin to overturn the regulations and allow WeEnergies to waive the requirement.
According to the Financial Times, Oracle has stated that enforcement of these regulations could impose heavy financial costs on the company and discourage future investments in Wisconsin.
However, a representative of the Wisconsin Public Utilities Commission told the Financial Times on Monday that the agency has declined to act on the petition.
Oracle also told the Financial Times that it still hopes the commission will reconsider its position considering the job opportunities and economic growth resulting from the implementation of this 15 billion dollar project.
Ссылка
click to show
click to show
Ссылка
click to show
click to show
Ссылка
click to show
click to show
In our previous post, we talked about the API key lifecycle in MaaS. In this article, we'll set up the governance layer those keys bind to, focusing on 2 core controls: managing token quotas (via MaaSSubscription) and defining model access rules (via MaaSAuthPolicy).Models-as-a-Service (MaaS), an integrated component of Red Hat Openshift AI, aims to give enterprises a flexible GitOps friendly way to set up their policy framework.Both attach to models through a MaaSModelRef:MaaSSubscription defines how much a user can consume in a given time window.MaaSAuthPolicy defines which models a user is
via Red Hat Blog https://ift.tt/eqAVjko
65 · Ссылка
click to show
click to show
An agent charged $4,000 to the wrong customer billing account. Nobody noticed until Monday. The agent wasn't broken—it was working exactly as designed. It had broad API credentials, the model picked a plausible but wrong account identifier, and nothing in the infrastructure stopped the call from going through. No identity boundary. No scope limit. No audit trail.I've seen teams react to failures like this by adding more checks inside the agent code—if-else blocks, hardcoded allowlists, manual credential rotation. That approach doesn't scale. When 3 failures hit a single AI agent deployment
via Red Hat Blog https://ift.tt/PVve2ky
86 · 22 July 2026
Ссылка
click to show
click to show
Druva Advances AI Resilience to Address the Speed and Sophistication of AI-Driven Risk
https://www.linkedin.com/pulse/druva-advances-ai-resilience-address-speed-ai-driven-risk-heayie-rp9kc?utm_source=share&utm_medium=member_android&utm_campaign=share_via
91 · Фотография
click to show
click to show
ابراهیم ترائوره (رئیسجمهور نظامی جوان) به هزاران شهروند کشورش که برای درسهای دینی (شریعت) به عربستان سعودی رفته بودند، گفت:
«به جای اینکه برید شریعت بخونید، باید علم، تکنولوژی و مهارتهای فنی یاد میگرفتید تا کشور رو جلو ببرید! حالا که اون راه رو انتخاب کردید، همونجا بمونید و شریعت رو تطبیق بدید!»
و حتی تهدید کرد که اگر برنگردند، ممکنه شهروندیشون رو بگیره!
ترائوره با یه جمله رک و پوستکنده همه رو شوکه کرد:
«ما به مهندس، دکتر و متخصص کشاورزی نیاز داریم، نه فقط عالم دینی!» 😳
97 · id 1005983125ابراهیم ترائوره (رئیسجمهور نظامی جوان) به هزاران شهروند کشورش که برای درسهای دینی (شریعت) به عربستان سعودی رفته بودند، گفت:
«به جای اینکه برید شریعت بخونید، باید علم، تکنولوژی و مهارتهای فنی یاد میگرفتید تا کشور رو جلو ببرید! حالا که اون راه رو انتخاب کردید، همونجا بمونید و شریعت رو تطبیق بدید!
Ibrahim Traore (young military president) told thousands of citizens of his country who went to Saudi Arabia for religious lessons (Sharia):
"Instead of going to study Sharia, you should have learned science, technology and technical skills to move the country forward!" Now that you have chosen that path, stay there and apply Sharia law!"
And he even threatened that if they don't return, he might take their citizenship!
Traore shocked everyone with a frank statement:
"We need engineers, doctors and agricultural specialists, not just religious scholars!" 😳
Ссылка
click to show
click to show
حملات سایبری امروز دیگر تنها به سرقت اطلاعات یا رمزگذاری فایلها محدود نمیشوند. در بسیاری از موارد، هدف اصلی مهاجم متوقف کردن چرخه فعالیت سازمان است؛ بهگونهای که حتی اگر هیچ دادهای به بیرون نشت نکند، خسارت ناشی از توقف عملیات، از هر آسیب دیگری سنگینتر باشد.
نمونهای از این واقعیت، اتفاقی است که برای شرکت آلمانی ZEGO رخ داد. این شرکت اعلام کرده است که در پی حمله سایبری ۲۹ مارس ۲۰۲۶**، خطوط تولید و بخشی از عملیات خود را برای نزدیک به **شش هفته متوقف کرده است. این وقفه طولانی، علاوه بر اختلال در زنجیره تأمین، تحویل سفارشها، درآمد و اعتماد مشتریان، فشار مالی قابلتوجهی به شرکت وارد کرد؛ تا جایی که در نهایت مجبور به ثبت درخواست آغاز فرآیند ورشکستگی شد.
نکته قابلتوجه این است که تاکنون جزئیات دقیقی از نوع حمله، روش نفوذ یا آسیبپذیری مورد سوءاستفاده منتشر نشده است. با این حال، نتیجه نهایی یک پیام بسیار مهم برای تمام سازمانها دارد:
وقتی زیرساخت فناوری اطلاعات از کار میافتد، ممکن است کل کسبوکار نیز از حرکت بایستد.
در بسیاری از صنایع، از تولید و انرژی گرفته تا بانکداری، سلامت، حملونقل و تجارت الکترونیک، سامانههای فناوری اطلاعات تنها یک ابزار پشتیبان نیستند؛ بلکه ستون فقرات عملیات سازمان محسوب میشوند. از کار افتادن Active Directory، سامانههای ERP، پایگاههای داده، سرویسهای احراز هویت، سیستمهای مانیتورینگ یا حتی زیرساخت مجازیسازی میتواند باعث توقف کامل فرآیندهای عملیاتی شود.
به همین دلیل، داشتن نسخه پشتیبان (Backup) بهتنهایی تضمینکننده تداوم کسبوکار نیست. بسیاری از سازمانها تصور میکنند تا زمانی که فایلهای بکاپ را در اختیار دارند، در برابر حملات سایبری ایمن هستند؛ در حالی که واقعیت چیز دیگری است.
یک راهکار مؤثر بازیابی باید به سؤالات مهمی پاسخ دهد:
* آیا نسخههای پشتیبان سالم و قابل بازیابی هستند؟
* آیا فرآیند Restore بهصورت دورهای آزمایش میشود؟
* در صورت نابودی کامل زیرساخت، چه مدت زمان برای بازگردانی سرویسهای حیاتی نیاز است؟
* مقدار دادهای که سازمان حاضر است از دست بدهد (RPO) چقدر است؟
* حداکثر زمان قابلقبول برای از دسترس خارج بودن سرویسها (RTO) چقدر است؟
* آیا برنامه مدون Disaster Recovery و Business Continuity وجود دارد یا تنها به تهیه ب
74 · Фотография
click to show
click to show
💎 تازهترین اقدام آمریکا علیه خبرگزاری فارس
🔹در تازهترین اقدام آمریکا با اعمال تحریم جدید، صدور گواهی امنیتی (SSL) برای وبسایت خبرگزاری فارس را مسدود کرده است. این اقدام که به اختلال در دسترسی کاربران و حذف تدریجی اخبار از نتایج جستجوی گوگل منجر شده است.
🔹بررسیهای فنی انجامشده توسط تیم فناوری اطلاعات فارس نشان میدهد که درخواست صدور یا تمدید گواهی امنیتی این رسانه نزد تمامی مراکز معتبر بینالمللی صدور گواهی عمومی (Public CA) که مورد اعتماد مرورگرهای اینترنتی هستند، با رد درخواست یا عدم ارائه خدمت مواجه شده است.
🔹در میان این مراکز میتوان به Let's Encrypt، Actalis، Certum، GlobalSign، DigiCert، Sectigo، HARICA و سایر ارائهدهندگان معتبر اشاره کرد که به دلایل ناشی از سیاستهای تحریمی یا محدودیتهای داخلی خود، از صدور گواهی برای دامنههای متعلق به خبرگزاری فارس خودداری کردهاند.
63 · id 1005983125💎 تازهترین اقدام آمریکا علیه خبرگزاری فارس
🔹در تازهترین اقدام آمریکا با اعمال تحریم جدید، صدور گواهی امنیتی (SSL) برای وبسایت خبرگزاری فارس را مسدود کرده است. این اقدام که به اختلال در دسترسی کاربران و حذف تدریجی اخبار از نتایج جستجوی گوگل منجر شده است.
🔹بررسیهای فنی انجامشده توسط تیم فناوری
💎 The latest US action against Fars news agency
🔹 In the latest action, the US has blocked the issuance of a security certificate (SSL) for the website of the Fars news agency by imposing new sanctions. This action has led to the disruption of users' access and the gradual removal of news from Google search results.
The technical checks carried out by the Fars IT team show that the request for issuing or renewing the security certificate of this media has been rejected or not provided by all the internationally recognized public certificate issuing centers (Public CA) that are trusted by internet browsers.
Among these centers, we can mention Let's Encrypt, Actalis, Certum, GlobalSign, DigiCert, Sectigo, HARICA, and other reputable providers that have refused to issue certificates for domains owned by Fars news agency due to sanctions policies or internal restrictions.
Ссылка
click to show
click to show
For system administrators and IT leaders, keeping infrastructure secure while strictly aligning with corporate compliance standards is a continuous, high-stakes balancing act. This challenge escalates dramatically when environments span legacy workloads or platforms locked into extended operational lifecycles.Managing disparate software repositories manually or trying to lock package versions across older, fragmented systems is highly time-consuming and introduces a severe risk of operational drift. When systems drift, predictability drops, compliance fails, and security vulnerabilities multip
via Red Hat Blog https://ift.tt/5kbIypd
28 ·