AntiMalwareJuly 16, 2026🇷🇺Translated from Russian

Google to Allow Competing Android App Stores Directly Inside Play Store After Epic Games Court Ruling

Google is set to open its official Google Play store to competing Android app marketplaces, allowing third-party catalogs to be distributed directly through the platform starting July 22. The move follows a court ruling in the multi-year antitrust case brought by Epic Games, which began in 2020 when Fortnite introduced direct V-Bucks purchases that bypassed Google’s 30% commission rules, leading to the game’s removal from both Google Play and the Apple App Store.

The court found that Google had systematically hindered device manufacturers from promoting or pre-installing alternative app stores, thereby strengthening its monopoly over Android app distribution. One of the key remedies requires Google to host approved competing stores inside Google Play itself. Attempts by Google and Epic to substitute this measure with a softer “Registered App Stores” program—under which users would still need to download rival stores manually—were rejected by the judge, who questioned whether such an approach would meaningfully increase competition.

Under the approved framework, participating stores will receive default access to the Google Play app catalog. Individual developers can still choose to prohibit distribution of their applications through specific marketplaces. Google will charge an annual verification fee of $5,000 per store. In return, approved stores must block malicious applications, respect copyright rules, and maintain the ability to update and remove apps. Any marketplace whose share of suspicious installations exceeds 1% may be removed from the program.

The changes are expected to apply primarily in the United States for now. Nevertheless, the ruling represents a significant shift for the Android ecosystem: Google Play will no longer merely tolerate competitors but will be required to actively distribute them to its users.

Related articles

HabrPolicy & Regulation

Russia's Data Leak Penalties: 2.6 Million Rubles in Fines Despite 1.58 Billion Records Exposed in 2025

Russia introduced turnover-based fines for personal data leaks through Federal Law 420-FZ in late 2024, fundamentally altering the economics of information security investments. Over the first 18 months, Roskomnadzor opened 52 administrative investigations and issued 40 protocols totaling just 2.6 million rubles in penalties, with zero turnover fines applied. This occurred against a backdrop of 1.58 billion compromised records in 2025 alone. Public data leaks dropped fourfold in the first half of 2026, yet trading activity on underground forums rose nearly 60 percent as operators shifted to private sales. The law now ties penalties directly to the number of affected individuals and adds a turnover component for repeat violations under Article 13.11 of the Code of Administrative Offenses. Analysts note that the mere threat of larger fines has prompted companies to reassess data retention policies and risk models even without actual enforcement precedents.

AntiMalwarePolicy & Regulation

Russia Authorizes Temporary State Takeover of Unprotected Critical Infrastructure

President Vladimir Putin has signed a decree that empowers the Russian government to appoint temporary managers for critical infrastructure facilities whose owners have failed to ensure adequate security. The measure directly targets operators of objects classified as critical infrastructure who have not met protection requirements. Under the new rules, the state can intervene by installing an interim administrator to oversee operations until security standards are satisfied. This approach aims to prevent potential disruptions or threats arising from insufficiently defended assets. The decree provides a legal mechanism for rapid governmental response without permanent nationalization of the facilities. It reflects ongoing efforts to strengthen oversight of sectors deemed essential to national security and stability.

AntiMalwarePolicy & Regulation

Microsoft Removes Reinstallation Requirement for Enabling Smart App Control in Windows 11

Microsoft has eliminated the primary restriction on Smart App Control, allowing home users to activate or reactivate the Windows 11 security feature without performing a clean installation of the operating system. Previously, toggling the setting effectively required users to reinstall the entire system. Smart App Control leverages Microsoft's cloud-based reputation system and analyzes digital signatures to block suspicious, potentially dangerous, or unsigned files before execution. The toggle is now accessible through Windows Security under App & browser control. The update is being rolled out gradually via Windows 11 updates, though users who have disabled optional diagnostic data may still need a reset or reinstallation. The feature can interfere with developers and enterprise users working with rare or unsigned tools, as there is no option to whitelist individual blocked applications.

AntiMalwarePolicy & Regulation

Russian State Operators Must Report Cyber Incidents to FSB Within 24 Hours From September 2026

Starting 1 September 2026, operators of state information systems in Russia will be required to notify the National Coordination Center for Computer Incidents within 24 hours of detecting a cyber incident. The mandate is set out in FSB Order 297 and applies to operators of GIS, information systems of state bodies, state unitary enterprises and state institutions. The order places particular emphasis on incidents involving unauthorized data transfers. Organizations will interact with GosSOPKA through the technical infrastructure of NKTsKI, which will issue an incident identifier upon receipt of the report. The new rules formalize what was previously considered good practice and stem directly from Law 568-FZ adopted in December 2025. The requirement removes any possibility of delaying notification to the FSB.