AntiMalwareSeptember 8, 2026🇷🇺Translated from Russian

CryptoPro Develops CryptoPro-Browser with Russian Cryptography for FSB Compliance

CryptoPro is developing a dedicated browser named CryptoPro-Browser that will become part of the CryptoPro CSP version 6.0 cryptographic information protection system. The new browser will feature built-in cryptographic tools, support for the company's plugin, and TLS connections based on Russian cryptographic algorithms.

The initiative stems from difficulties users face when trying to install the CryptoPro extension after Google removed it from the Chrome Web Store in February 2025. New Chrome installations left customers without their usual method of adding the extension. In response, the company suggested Yandex Browser and its own Chromium-Gost project, which it has been developing since 2017.

According to CryptoPro CEO Stanislav Smyshlyaev, the product is intended for use cases where information protection must meet requirements set by the FSB of Russia. The agency has already approved the project, as stated in the company's information letter reported by Kommersant.

The company promises to take into account all accumulated experience from previous developments, although it has not confirmed whether Chromium-Gost will serve as the direct foundation. Analyst Leonid Delitsyn from Finam estimates the cost of creating the browser at several tens of millions of rubles.

The primary target audience consists of corporate customers. Large organizations require not only document signing and website access but also certificate management, component control, and specialized technical support. Meanwhile, Yandex reports that its browser is already used by more than 30,000 companies and 5.2 million employees, with ongoing integration of cryptographic tools.

Related articles

HabrPolicy & Regulation

Yandex 360 Email Archive Documentation Shows Search Snapshots and Former Employee Log Filters

The Yandex 360 administrator guide describes the email archive as a tool that stores copies of all messages sent and received by employees on the organization's domain. Two specific statements in the documentation indicate that each saved search returns a static snapshot that does not update automatically when new mail arrives, requiring manual cloning or recreation of the search to obtain current results. The same documentation states that the action log records every operation performed in the archive, yet the employee filter in the log interface only displays currently active accounts, making it impossible to select a former administrator by name. API 360 currently provides no documented endpoints for creating, executing, or retrieving archive searches, leaving all operations dependent on the web console. Additional notes clarify that messages remain available after an account is blocked but disappear once the account is deleted, and that messages removed before the archive was enabled cannot be recovered. These documented behaviors directly affect incident response and offboarding procedures that rely on historical email retrieval and audit trails.

HabrPolicy & Regulation

Global AI Regulation: From Strict School Bans to Unregulated AI Havens

Countries are adopting sharply different approaches to AI oversight, ranging from comprehensive risk-based frameworks to outright prohibitions on generative tools in education. The United States relies on a patchwork of state laws and presidential actions, including Texas TRAIGA restrictions on high-risk AI systems and New York’s moratorium on generative AI in grades 2–8. The European Union enforces the AI Act with four risk categories, while Italy adds criminal liability and human oversight requirements in critical sectors. Norway and China have implemented some of the strictest classroom and content-authenticity rules, and Russia introduced its first baseline AI law defining sovereign models effective September 2026. Several nations have also blocked popular chatbots such as ChatGPT, DeepSeek, and Grok. Meanwhile, commercial platforms like FinamX continue integrating multiple AI models into financial workflows despite the regulatory tightening.

HabrPolicy & Regulation

How Russian Companies Can Legally Transfer Personal Data to Contractors Under 152-FZ

The article explains the legal distinction between data processors and independent operators when outsourcing tasks involving personal data. It details that the role of a contractor is determined by who sets the processing purpose, not by the service contract itself. For processors, a detailed data processing instruction under Article 6 of 152-FZ is required, while independent operators need a separate legal basis such as consent or contract performance. Special rules apply to employee data under Article 88 of the Labor Code, mandating written employee consent for transfers to third parties. The guidance also covers sub-processing risks, transparency obligations, and penalties under Article 13.11 of the Code of Administrative Offenses. Practical checklists help organizations classify contractors and prepare the correct documentation.

AntiMalwarePolicy & Regulation

Russian Data Centers May Face Temporary State Management Under Decree 604 for Protection Shortfalls

Large Russian data centers could be placed under temporary government administration if they fail to meet security requirements outlined in presidential decree No. 604. The measure targets critical infrastructure operators that neglect physical and cyber protections, create operational risks, or respond slowly to incidents such as drone strikes. Rosimushchestvo would typically assume management duties by default. Market participants note that Tier III and higher facilities generally maintain strong cyber defenses, shifting the main compliance burden to physical safeguards for generators, cooling systems, and network nodes. Operators including RTK-DC and RUVDS have already begun reviewing and upgrading external equipment protection. Additional costs for redundant communications, DDoS mitigation, vulnerability management, and faster recovery are expected to be passed on to clients in government, finance, and telecom sectors. First Deputy Prime Minister Denis Manturov stated that decisions will remain targeted and will not trigger widespread nationalization.