Turan Security
2.31K subscribers
283 photos
38 videos
1 file
146 links
Turan Security Information Security services provider founded by heavily experienced guys | turansec.uz

www.instagram.com/turan.security
www.linkedin.com/company/turansecurity

Aloqa uchun: @turan_admin , info@turansec.uz
Download Telegram
Turan Security asoschilaridan biri 17-dekabr kuni Markaziy bank va “Kapitalbank” tomonidan hamkorlikda tashkil etilgan tadbirda spiker sifatida ishtirok etdi. Kun quyidagi mavzularga bag‘ishlandi: “Axborot xavfsizligi va firibgarlikka qarshi kurashish" Cyber Security Baseline systems.

Tadbir esa kengroq va nihoyatda dolzarb mavzu doirasida o‘tkazildi: “Axborot xavfsizligi va firibgarlikka qarshi kurashish: 2025-yilga kelib natijalar, tendensiyalar va transformatsiya.” Muhokamalar davomida quyidagi masalalarga alohida e’tibor qaratildi: Kiberxavflar va firibgarlik sxemalarining ortib borishi; avtomatlashtirish va kirishlarni nazorat qilishning operatsion hamda regulyator risklarni kamaytirishdagi roli; moliya sektorida axborot xavfsizligiga yondashuvlarning transformatsiyasi. Tadbir tashkilotchilariga amaliy tajriba bilan o‘rtoqlashish imkoniyati uchun, shuningdek, ishtirokchilarga professional muloqot va mavzuga bo‘lgan katta qiziqishlari uchun samimiy minnatdorlik bildiramiz.

_______________________________

One of the founders of Turan Security participated as a speaker on December 17 at an event jointly organized by the Central Bank and Kapitalbank.

The presentation was dedicated to the topic:
“Information Security and Countering Fraud: Cybersecurity Baseline Systems.”

The event itself was held within a broader and highly relevant agenda:
“Information Security and Countering Fraud: Results, Trends, and Transformation Towards 2025.”

During the discussions, special attention was given to the following issues:

the growing number of cyber threats and fraud schemes;

the role of automation and access control in reducing operational and regulatory risks;

the transformation of information security approaches in the financial sector.

We would like to express our sincere gratitude to the event organizers for the opportunity to share practical experience, as well as to the participants for the professional dialogue and strong interest in the topic.

@TuranSecurity | www.turansec.uz
34👍137🔥6👨‍💻2
#KiberXavfsizlik
#BirgaKuchliroqmiz
Kiberxavfsizlikda yangi hamkorlik


“Cyber university” davlat universiteti va Turan Security o‘rtasida kiberxavfsizlik sohasida hamkorlik memorandumi imzolandi.

➡️Hamkorlik doirasida kiberxavfsizlik bo‘yicha amaliy mashg‘ulotlar, trening va master-klasslar o‘tkazish, CTF musobaqalarini tashkil etish, kiberxavfsizlik klubini yo‘lga qo‘yish, iqtidorli talabalarni qo‘llab-quvvatlash hamda talabalar uchun amaliyot dasturlarini amalga oshirish belgilandi.

😑😑😑😑

A New Milestone in Cybersecurity Cooperation

TASHKENT – Cyber University and Turan Security have officially entered into a strategic partnership by signing a Memorandum of Cooperation (MoC) today. This alliance aims to significantly advance the cybersecurity landscape through academic and industrial synergy.

@TuranSecurity | www.turansec.uz
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥1919👍72
#KiberXavfsizlik
#BirgaKuchliroqmiz
Oʻzbekiston Respublikasi Jamoat xavfsizligi universiteti bilan Turan Security o'rtasida memorandum imzolandi.


Turan Security va oliy ta’lim muassasalari o‘rtasida imzolangan Memorandumning asosiy maqsadi — kiberxavfsizlik ta’limini real amaliyot bilan uyg‘unlashtirish orqali yuqori malakali mutaxassislarni tayyorlashdir. Hamkorlik doirasida talabalar uchun amaliyot va stajirovkalar, qo‘shma ilmiy-tadqiqot loyihalari hamda mutaxassislar almashinuvi yo‘lga qo‘yiladi. Turan Security’ning xalqaro tajribasi va e’tirof etilgan yutuqlari yoshlar uchun real kiberxavflar bilan ishlash imkonini yaratadi. Ushbu hamkorlik kiberxavfsizlik madaniyatini rivojlantirish va sohaga kuchli kadrlar yetishtirishga xizmat qiladi.


-—-—-—-—-—-—-—-—-—-—-—-—
#CyberSecurity
#StrongerTogether
Memorandum signed between the Public Security University of the Republic of Uzbekistan and Turan Security.

The main goal of the Memorandum signed between Turan Security and higher education institutions is to train highly qualified specialists by integrating cybersecurity education with real practice. Within the framework of cooperation, internships and practical training for students, joint scientific research projects, and expert exchanges will be organized. Turan Security’s international experience and recognized achievements provide young people with the opportunity to work with real cyber threats. This cooperation serves to develop a cybersecurity culture and train strong personnel for the sector.

@TuranSecurity| www.turansec.uz
32🔥11👍94
This media is not supported in your browser
VIEW IN TELEGRAM
Pwn2Own 2025: Samsung S25 Ultra zero-click orqali buzildi - $100 000 mukofot

Pwn2Own 2025 xalqaro xakerlik musobaqasida tadqiqotchilar Samsung S25 Ultra qurilmasini zero-click zaiflik orqali 1 daqiqadan kam vaqt ichida komprometatsiya qilishdi va $100 000 mukofotni qo‘lga kiritishdi.

Muhim jihatlar:
▫️Foydalanuvchidan hech qanday harakat talab qilinmadi;
▫️Link bosish, fayl ochish yoki ilova o‘rnatish bo‘lmadi;
▫️To‘liq masofaviy ekspluatatsiya;
▫️Qurilma flagman bo‘lishiga qaramay buzildi;

Texnik xulosa:
Zero-click hujumlar bugungi kunda mobil OS, xizmatlar va kommunikatsiya steklari uchun eng xavfli tahdidlardan biri bo‘lib qolmoqda. Qurilmaning yangiligi xavfsizlik kafolati emas.

Tavsiyalar:
Mobil qurilmalar uchun Threat Model’ni yangilash
MDM / EMM siyosatlarini qayta ko‘rib chiqish
Zero-click ssenariylarini incident response rejalariga kiritish

😎Turan Security eslatib o'tadi:
Hujum uchun foydalanuvchi xatosi shart emas.


#TuranSec #Pwn2Own2025 #ZeroClick #MobileSecurity #Samsung #Infosec #CyberThreats

Komprometatsiya - Tizim egallab olinishi

@TuranSecurity| www.turansec.uz
Please open Telegram to view this post
VIEW IN TELEGRAM
33👍16🔥121😁1
Bayram muborak!

📖Bugun 14-yanvar O‘zbekiston Respublikasi Qurolli Kuchlari tashkil etilganiga 34 yil to‘ldi. Vatani va oilasini himoya qilayotgan har bir erkakga mustahkam sog‘liq, uzoq umr va farovon hayot tilaymiz.

Do'stlar, tashqi tahdidlar kibermakonga ko'chib ulgurdi! Raqamli dunyoda yurtimiz xavfsizligini oshirish yo'lida, sizga sabr-toqat va kuch-quvvat tilab qolamiz. Ilm olishdan, o'z ustingizda ishlashdan to'xtamang!

Sizlarga mustahkam sog‘lik va yurt ravnaqi yo‘lidagi faoliyatingizda ulkan zafarlar tilaymiz. Bayramingiz muborak bo‘lsin!

Hurmat bilan, 
Turan Security jamoasi

www.turansec.uz | info@turansec.uz
🔥251716
⚠️ AuraAudit (AuraInspector): Salesforce Aura muhitidagi noto‘g‘ri sozlamalarni aniqlovchi ochiq manbali xavfsizlik vositasi

Kiberxavfsizlik sohasida yetakchi kompaniyalardan biri bo‘lgan Mandiant Salesforce platformasida xavfsizlikni kuchaytirishga qaratilgan yangi ochiq manbali vositani taqdim etdi. AuraInspector (ko‘pincha AuraAudit deb ham ataladi) — bu buyruqlar satrida ishlovchi (CLI) audit vositasi bo‘lib, Salesforce Aura framework’idagi kirish huquqlarining noto‘g‘ri sozlanishini aniqlash va tahlil qilish uchun mo‘ljallangan.

⚠️ Mazkur vosita, ayniqsa, Salesforce Experience Cloud muhitlarida tez-tez uchraydigan va jiddiy oqibatlarga olib kelishi mumkin bo‘lgan xavfsizlik bo‘shliqlarini aniqlashga yordam beradi.

📱 Batafsil

PS : UZCERTning rasmiy kanaliga a'zo bo'lishni maslahat qilamiz.

#AuraAudit #AuraInspector #Salesforce #Aura #xavfsizlik #vosita
🚀 UZCERT xizmatining rasmiy telegram sahifasiga a’zo bo‘ling!
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥14137
2026-yildagi birinchi CVE - NVIDIA dasturiy ta'minotida

Security Research guruhimiz a'zosi Javohir Abduxalilov kapitalizatsiyasi bo'yicha dunyoda birinchi o'rinda turuvchi NVIDIA kompaniyasidan jiddiy zaiflikni aniqladi va bu kompaniya tomonidan e'tirof etildi!

Zaiflik Nvidia Merlin dasturiy ta'minotiga ta'sir qiladi, ushbu dastur Tencent/WeChat, Snapchat, Netflix, Fidelity, Spotify, Walmart, Postmates/Uber, Meituan, Microsoft kabi kompaniyalar tomonidan foydalaniladi.

📋 CVE-2025-33233 (Nvidia Merlin - Transformers4Rec library)
🔴 Zaiflik darajasi: High (7.8 CVSS)
⚠️ Ta'siri: Code Execution, Escalation of Privileges, Information Disclosure, Data Tampering
🔗 Security Bulletin

Bunday natijalar O'zbekistonning kiberxavfsizlik sohasidagi xalqaro nufuzini oshirishga xizmat qiladi.

P.S. Eslatib o'tamiz mutaxassislarimiz tomonidan NASA, Google, Amazon, Toyota kabi dunyoning yetakchi texnologik kompaniyalaridan ham zaifliklar aniqlangan.

www.turansec.uz | info@turansec.uz
🔥52👍282285
⚠️ Hurmatli fuqarolar! Firibgarlik qurboni bo‘lib qolmaslik uchun shaxsi va faoliyati aniq tasdiqlanmagan manzillarga hech qachon pul o‘tkazmang!

Kiberxavfsizlik markazining UZCERT xizmati tomonidan olib borilgan o‘rganishlar hamda fuqarolardan kelib tushgan murojaatlar asosida “Pioneer Global Media LTD” nomi ostida faoliyat yuritayotgan firibgarlar aniqlangan.

⌨️ Mazkur shaxslar fuqarolarni onlayn ishga taklif qilish bahonasida, go‘yoki har hafta muntazam daromad topish mumkinligini va’da qilib, eng kamida 3 500 000 (uch million besh yuz ming) so‘m miqdorida to‘lovlarni aldov yo‘li bilan undirish bilan shug‘ullanib kelayotganligi ma’lum bo‘ldi.

🔎 Aniqlanishicha, hozirgi kunda respublikaning bir nechta viloyatlarida “Pioneer Global Media LTD”, qisqacha PGM, nomi ostida Telegram messenjerida maxfiy guruhlar tashkil etilgan. Ushbu guruhlarga faqat administratorlar tomonidan tasdiqlangan foydalanuvchilargina qo‘shilishi mumkin.

O‘rganishlar davomida ma’lum bo‘lishicha, maxfiy guruhga qo‘shilgan fuqarolarga kamida 3 500 000 so‘m to‘lovni amalga oshirish evaziga onlayn ishga qabul qilinishi va ma’lum topshiriqlarni bajarganidan so‘ng har hafta xizmat haqi to‘lab berilishi aytilgan. Shu yo‘l bilan fuqarolar firibgarlik sxemasiga jalb etilgan.

Shuningdek, to‘lovni amalga oshirib, go‘yoki onlayn ishga kirgan shaxslarga o‘z tanishlariga taklif havolasini yuborish imkoniyati berilgan. Agar taklif havolasi orqali boshqa fuqarolar to‘lovni amalga oshirsa, ushbu mablag‘ning 10 foizi havolani yuborgan shaxsga mukofot sifatida to‘lab berilishi va’da qilingan.

⚠️ Mazkur holatlar moliyaviy piramida va firibgarlik alomatlariga ega bo‘lib, fuqarolardan bunday takliflarga ishonmaslik, shubhali guruhlar va shaxslarga pul o‘tkazmaslik qat’iy tavsiya etiladi.

#Firibgarlik #uzcert #piramida #moliyaviy
🚀 UZCERT xizmatining rasmiy telegram sahifasiga a’zo bo‘ling!
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥15993👍1
🔥 Mutaxassislarimiz Winter Cyber Security Camp’da muvaffaqiyatli ishtirok etdi!

Gruziyaning Bakuriani shahrida bo‘lib o‘tgan Xalqaro qishki kiberxavfsizlik oromgohida mutaxassislarimiz bilim va ko‘nikmalarini oshirib qaytishdi.

Mazkur xalqaro dastur doirasida Gruziya Ilmiy Kiberxavfsizlik Assotsiatsiyasi (SCSA) tomonidan: Axloqiy xakerlik (Ethical Hacking), Kriptografiya, Python dasturlash va Web Penetration testing yo‘nalishlarida intensiv ma’ruza va amaliy treninglar tashkil etildi.

🏆 Treninglar yakunida kiberxavfsizlikning real ssenariylarini simulyatsiya qiluvchi xakatonda mutaxassisimiz Behzod Hamroyev faxrli 1-o‘rinni egalladi.

📌 P.S. Ushbu dasturga taklif uchun Toshkent shahridagi Inha universitetiga o‘z minnatdorligimizni bildiramiz.

www.turansec.uz | info@turansec.uz
🔥3615116😁4
Shuning uchun...
That's why...

@TuranSecurity | www.turansec.uz
😁392817🔥8🌚5
15 mln zaif nuqta: Nima uchun Turan Security’ning jahon darajasidagi tajribasi bugun O‘zbekiston biznesiga kerak?

Batafsil — https://daryo.uz/TuranSecurity

Turan Security kompaniyasidan tavsiyalar:

Parollarni mustahkamlang
Kamida 12 ta belgili, katta-kichik harf, raqam va maxsus belgilardan iborat parollar qo'ying.
Barcha tizimlar va ijtimoiy tarmoqlarda 2FA ni faollashtiring.
Dasturiy ta'minotni muntazam yangilang
Operatsion tizim, brauzer, antivirus va boshqa tizimlarni doimo oxirgi versiyada saqlang.
Ma'lumotlarning zaxira nusxasini yarating (backup)
Muhim fayllarni kamida 2 ta alohida joyda saqlang. Kunlik yoki haftada minimum 1 marta backup qiling.
Kiberhujumlarning 90%+ inson xatosi orqali amalga oshadi. Xodimlarni phishing, parol siyosati va ijtimoiy muhandislik bo'yicha o'qiting.
Muntazam pentest (penetration test) o'tkazing. Professional xavfsizlik auditi orqali zaif nuqtalarni xakerlardan oldin aniqlab bartaraf qiling. Yiliga kamida 1–2 marta.


www.turansec.uz | info@turansec.uz
👍262412😁5😢1
#TodayBoburDay

Jonimdin o'zga yori vafodor topmadim,
Ko'nglumdin o'zga mahrami asror
topmadim.
Jonimdin o'zga jonni dilafkor ko'rmadim,
Ko'nglum kibi ko'ngulni giriftor topmadim.
Usruk ko'ziga toki ko'ngul bo'ldi mubtalo,
Hargiz bu telbani yana hushyor topmadim.
Nochor furqati bila xo'y etmisham, netay,
Chun vaslig'a o'zumni sazovor topmadim.
Bore boray eshigiga bu navbat, ey ko'ngul,
Nechaki borib eshigiga bor topmadim.
Bobur, o'zungni o'rgatako'r yorsizki, men
Istab jahonni muncha qilib yor topmadim.

www.turansec.uz | info@turansec.uz
1815👍8😁6🔥1