<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Aliaksei Saskevich | @asaskevich]]></title><description><![CDATA[CTO at Sequoia | Backend Lead at Gem Space | 11+ years of Expertise]]></description><link>https://asaskevich.hashnode.dev</link><image><url>https://cdn.hashnode.com/uploads/logos/69c3b8208a263e79cb25279f/0e052076-fe28-4664-b88b-659f0a876e98.png</url><title>Aliaksei Saskevich | @asaskevich</title><link>https://asaskevich.hashnode.dev</link></image><generator>RSS for Node</generator><lastBuildDate>Thu, 17 Sep 2026 08:42:59 GMT</lastBuildDate><atom:link href="https://asaskevich.hashnode.dev/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[Sequoia Men’s Health: MedTech Malta 2025 Tech Results]]></title><description><![CDATA[In November 2025, our team visited the MedTech Malta 2025 conference, which Denis Halka already told us about earlier in our blog. From my side, I would like to share my opinion on what that conferenc]]></description><link>https://asaskevich.hashnode.dev/sequoia-men-s-health-medtech-malta-2025-tech-results</link><guid isPermaLink="true">https://asaskevich.hashnode.dev/sequoia-men-s-health-medtech-malta-2025-tech-results</guid><category><![CDATA[startup]]></category><category><![CDATA[Founder]]></category><category><![CDATA[conference]]></category><category><![CDATA[lessons learned]]></category><category><![CDATA[tech ]]></category><dc:creator><![CDATA[Aliaksei Saskevich]]></dc:creator><pubDate>Tue, 31 Mar 2026 07:30:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/69c3b8208a263e79cb25279f/09ce9699-b965-4465-82b6-407a9dcc7610.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In November 2025, our team visited the MedTech Malta 2025 conference, which Denis Halka already <a href="https://sequoia.health/blog/sequoia-at-medtech-malta-2025">told us about earlier in our blog</a>. From my side, I would like to share my opinion on what that conference gave us from the technical position.</p>
<h2><strong>DiHubMT — Maltese Startup Hub</strong></h2>
<p>The day before the conference, we were invited by organizers to visit the local startup hub <a href="https://dihubmt.eu/">DiHubMT</a> — where they held a presentation and gave us a tour of their office.</p>
<p>The hub offers office spaces to its members, meeting points, conference halls, rooms to record podcasts and interviews, its own mini-data center, and much more to help create successful tech products.</p>
<p>We learned about their offering and exchanged contacts, noting that their machine learning and data center services may be useful to us while working with medical and user data.</p>
<h2><strong>Malta Enterprise — helping startups to grow</strong></h2>
<p>Next, we met representatives of the <a href="https://maltaenterprise.com/">Malta Enterprise</a> agency, created and supported by the Malta government. We met them at DiHubMT. We had already heard about them from our friends at another Belarusian startup, who told us that Malta Enterprise helped them relocate their business, providing financial and legal support.</p>
<p>Malta Enterprise offers a wide range of interactions and services, the main goal of which is attracting and legalizing businesses and startups in Malta. Actually, the conference itself is a bright example of the government’s support to grow and scale the technology ecosystem.</p>
<p>Such support is very interesting to us, so we also exchanged contacts and scheduled a meeting to learn more about possible formats of collaboration.</p>
<h2><strong>Gero Sense — technologies to protect longevity</strong></h2>
<p>Another interesting acquaintance was the <a href="https://www.gerosense.ai/">Gero Sense</a> team — a product dedicated to analyzing data from phone sensors (like steps or heartbeats) and calculating age indicators of a person.</p>
<p>We were surprised because this is not the only domain they are working in: they have projects in pharmacology and longevity research. We liked their scientific approach and how they position themselves among their colleagues.</p>
<p>During the conversation, they offered us a partnership, which includes access to their AI models. This gives us the ability to provide our users with relevant information about their health status.</p>
<h2><strong>Sexual Health Malta — sexual health and education</strong></h2>
<p>Beyond startup growth, the government actively supports different health initiatives. <a href="https://sexualhealth.gov.mt/">Sexual Health Malta</a> is an example of the government’s educational program directed at popularizing knowledge about sex, hygiene, and infections.</p>
<p>With them, we discussed that we have experience building research platforms (similar to our partnership with <a href="https://sequoia.health/blog/sequoias-partnership-with-tor-vergata">Tor Vergata University</a>) and educational libraries.</p>
<h2><strong>MedTech Innovator — health-tech accelerator</strong></h2>
<p>The last important contact was <a href="https://medtechinnovator.org/">MedTech Innovator</a> — the largest health-tech accelerator. A partnership with them may help us grow our connections and expertise in building health-tech startups.</p>
<h2><strong>In conclusion</strong></h2>
<p>After <a href="https://med-tech.world/malta/">MedTech Malta</a>, at <a href="https://sequoia.health/">Sequoia: Men’s Health</a> we understood that highly specialized events are more beneficial than large conferences: the percentage of potentially valuable contacts is higher, and the number of random attendees is significantly lower.</p>
<p>The conference and new connections gave us rich food for thought about what we can do now, what is better for our users, how to implement it and deliver it to the user, and, most importantly, how significant are the results of our work?</p>
]]></content:encoded></item><item><title><![CDATA[Kinsing Miner — how to find and neutralise]]></title><description><![CDATA[I’m sure that everyone has encountered malware at some point in their lives. Some have lost passwords to phishing sites, others have been targeted by financial fraud, and some suddenly noticed that th]]></description><link>https://asaskevich.hashnode.dev/kinsing-miner-how-to-find-and-neutralise</link><guid isPermaLink="true">https://asaskevich.hashnode.dev/kinsing-miner-how-to-find-and-neutralise</guid><category><![CDATA[startup]]></category><category><![CDATA[Security]]></category><category><![CDATA[Product Management]]></category><dc:creator><![CDATA[Aliaksei Saskevich]]></dc:creator><pubDate>Wed, 25 Mar 2026 10:52:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/69c3b8208a263e79cb25279f/78c44059-236b-4a9f-af97-50cb1fd1d157.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I’m sure that everyone has encountered malware at some point in their lives. Some have lost passwords to phishing sites, others have been targeted by financial fraud, and some suddenly noticed that their phone or computer began to slow down and overheat.</p>
<p>The concept of a “miner” has become one of the most common attack vectors on user devices in the modern world. The ease of mining cryptocurrencies like Monero has allowed attackers to exploit web browsers as a target.</p>
<p>Attackers are also rapidly infecting cloud infrastructure. Poor digital hygiene and vulnerabilities in both open‑source and proprietary tools create fertile ground for the abuse of computing resources.</p>
<h2><strong>Metabase and product analytics</strong></h2>
<p>For every startup, including <a href="https://sequoia.health">Sequoia</a>, it is important to understand what happens inside the product: which features are most popular, how users behave, what actions they perform, and what helps retain the audience.</p>
<p>In the early stages, it is common to use third‑party tools like <a href="https://firebase.google.com/docs/analytics">Firebase Analytics</a>, <a href="https://amplitude.com/">Amplitude</a>, <a href="https://appmetrica.yandex.com/about">Yandex AppMetrica</a>, and others.</p>
<p>However, for tasks requiring direct access to the primary database, these tools are not suitable. Often, startups use open‑source or self‑hosted solutions. One of the well‑known, popular, and flexible tools is <a href="https://www.metabase.com/">Metabase</a>.</p>
<p>For Sequoia, it proved that we can build any dashboards and charts that were impossible to create with third‑party cloud services.</p>
<h2><strong>Miner detection</strong></h2>
<p>Infrastructure monitoring is a critical part of DevOps culture. When processes are built correctly and competently, it becomes normal to quickly detect and prevent threats.</p>
<p>During our weekly review, we noticed that one of the Docker machines started consuming abnormally high amounts of CPU and RAM.</p>
<p>The first step was to analyze the processes by CPU consumption to determine which one was out of the norm.</p>
<img src="https://miro.medium.com/v2/resize:fit:1400/1*xgsww04mXnEHSrB4zpiRxQ.png" alt="Top processes consuming CPU" style="display:block;margin:0 auto" />

<p>We detected the process <code>kdevtmpfsi</code>. A quick search shows that it is a well‑known malware miner.</p>
<h2><strong>The source of the problem</strong></h2>
<p>After removing the miner and its files and blocking outgoing ports, we needed to determine how it got into the system. Initially, our cloud infrastructure blocked access to the machine (except HTTP(S) and SSH).</p>
<p>To understand who actually initiated this process, it is necessary to consult the process tree, which reveals the initiator behind the launch of a specific program — whether it be the system, a user, or another program.</p>
<p>Analysis of the process tree revealed that the miner was not located on the host machine but inside an active Docker container.</p>
<img src="https://miro.medium.com/v2/resize:fit:1400/1*-wXHRcvA8dUvW5GF5GJU8A.png" alt="Process tree" style="display:block;margin:0 auto" />

<p>The next step was to identify the Docker image the miner was running in. To do this, we examined the path to the executable file.</p>
<img src="https://miro.medium.com/v2/resize:fit:1400/1*GjT6k6jcDks_6EVgLs5byw.png" alt="The path to the executable file" style="display:block;margin:0 auto" />

<p>It turned out that the miner was running inside a Metabase container — the product analytics tool we use at Sequoia.</p>
<h2><strong>Reason for appearance</strong></h2>
<p>The self‑hosted version of Metabase installed on Sequoia’s servers contained a vulnerability that allowed an attacker to connect to the machine and execute arbitrary commands. The miner was installed through this vulnerability.</p>
<p>A detailed analysis of the vulnerability was published on the Metabase blog: <a href="https://www.metabase.com/blog/vulnerability-post-mortem">https://www.metabase.com/blog/vulnerability-post-mortem</a></p>
<h2><strong>Consequences</strong></h2>
<p>In Sequoia’s case, user data was not affected. However, the infrastructure was disrupted for several days, resulting in decreased API response time.</p>
<p>We updated self‑hosted tools, changed infrastructure configuration, and reviewed security policies — all without harming user experience or data.</p>
<h2><strong>Tips for the Future</strong></h2>
<p>I would advise our readers to pay closer attention to the frequency and tools used for their security audits. Review all dependencies and reduce their number to minimize their impact on your infrastructure. And always isolate user data to minimize both technological and reputational risks.</p>
]]></content:encoded></item></channel></rss>