AntiMalwareJuly 16, 2026🇷🇺Translated from Russian

Google to Allow Competing Android App Stores Directly Inside Play Store After Epic Games Court Ruling

Google is set to open its official Google Play store to competing Android app marketplaces, allowing third-party catalogs to be distributed directly through the platform starting July 22. The move follows a court ruling in the multi-year antitrust case brought by Epic Games, which began in 2020 when Fortnite introduced direct V-Bucks purchases that bypassed Google’s 30% commission rules, leading to the game’s removal from both Google Play and the Apple App Store.

The court found that Google had systematically hindered device manufacturers from promoting or pre-installing alternative app stores, thereby strengthening its monopoly over Android app distribution. One of the key remedies requires Google to host approved competing stores inside Google Play itself. Attempts by Google and Epic to substitute this measure with a softer “Registered App Stores” program—under which users would still need to download rival stores manually—were rejected by the judge, who questioned whether such an approach would meaningfully increase competition.

Under the approved framework, participating stores will receive default access to the Google Play app catalog. Individual developers can still choose to prohibit distribution of their applications through specific marketplaces. Google will charge an annual verification fee of $5,000 per store. In return, approved stores must block malicious applications, respect copyright rules, and maintain the ability to update and remove apps. Any marketplace whose share of suspicious installations exceeds 1% may be removed from the program.

The changes are expected to apply primarily in the United States for now. Nevertheless, the ruling represents a significant shift for the Android ecosystem: Google Play will no longer merely tolerate competitors but will be required to actively distribute them to its users.

Related articles

AntiMalwarePolicy & Regulation

Yandex Cloud Partners with Sogaz and Ingosstrakh to Automate Cyber Risk Assessment for Business Insurance

Yandex Cloud, through its Yandex B2B Tech division, has launched joint cyber insurance programs with Russian insurers Sogaz and Ingosstrakh. The initiative replaces traditional manual questionnaires with automated infrastructure scanning via the Yandex Security Deck service. The tool examines cloud resources, applications, and data to identify open internal information, excessive user privileges, leak risks, and potential compromise vectors. Detected issues are consolidated in a single prioritized interface and shared with insurers to refine policy terms. If critical gaps are found, Yandex Cloud also provides remediation recommendations. The move comes as demand for cyber insurance grows rapidly, with Sogaz reporting that requested coverage volume doubled year-over-year to exceed 12 billion rubles in the first half of 2026.

AntiMalwarePolicy & Regulation

Over 20 VPN Services Hit by Outages After Russian Regulators Block Hosting Provider Subnets

Users of multiple VPN services reported widespread connection problems throughout the day as IP addresses belonging to several large hosting providers were placed under restrictions. The blocks targeted infrastructure used by VPNs to reroute traffic around content filters, causing entire ranges of servers to become inaccessible when whole subnets were affected. The Telegram channel Exploit reported that more than 20 VPN services of varying sizes experienced disruptions, though Roskomnadzor has not issued an official statement on the scope or origin of the measures. The affected providers indicated they are shifting customers to backup servers, noting that the restrictions appear selective yet still force frequent address changes during the day. The incidents coincide with ongoing discussions of new rules that would require hosting providers to independently detect and report masked VPN IP addresses to regulators. Similar large-scale subnet blocks occurred in late May, impacting numerous MTProto-based proxies and VPNs simultaneously.

安全客Policy & Regulation

HackerOne Ends Anonymous Era for Bug Bounty Hunters with Mandatory ID Verification

HackerOne has introduced compulsory identity verification for all researchers submitting reports to paid bug bounty programs, effective August 1. The policy requires users to complete KYC checks through Estonian firm Veriff by uploading government-issued ID and performing a live selfie, with annual renewals. Vulnerability Disclosure Programs remain open to anonymous participants, but any researcher seeking monetary rewards must now reveal their identity. The move follows similar steps by Bugcrowd and Intigriti and is driven by anti-money laundering and cross-border payment regulations. Researchers in high-surveillance regions and newcomers face new barriers, while the platform argues the change improves report quality and enterprise trust. H1 Clear adds an extra criminal background check layer for elite participants.

AntiMalwarePolicy & Regulation

Telegram Briefly Removed from App Store After Apple Detects Child Sexual Abuse Material

Telegram was temporarily pulled from the App Store in multiple countries after Apple moderators identified content linked to child sexual abuse. The removal lasted roughly 20 minutes before the app was reinstated following Telegram's quick removal of the prohibited material and blocking of the responsible user. Apple cited strict App Store rules as the reason for the action. During the outage, already-installed copies continued to function normally while the app remained available via the Mac App Store and Google Play. Telegram responded on X with the quote “Rumors of my death have been greatly exaggerated” before Apple issued its official explanation. This marks at least the third documented instance of Telegram facing App Store removal, including a 2018 incident over unacceptable content and a 2024 removal from the Chinese store at the request of local regulators.