AntiMalware•July 27, 2026•🇷🇺Translated from Russian

Microsoft Tightens Corporate Windows Activation with TPM-Bound KMS Servers

Microsoft has decided to tighten controls in its corporate Windows activation system, prompting some media outlets to declare the end of pirated Windows 11. In reality, the hunt for home users has not begun: the new requirement will only affect organizations that maintain their own KMS servers.

KMS allows companies to activate computers inside their network through a single server without sending each machine directly to Microsoft. The problem is that attackers have learned to create fake and cloned KMS hosts that distribute licenses to devices for which no one has paid.

The new KMS Hardware-Secured technology will bind such a server to TPM. The chip must confirm the hardware identity to Microsoft and prove that the platform has not been modified after registration. If the check fails, activation of the corporate fleet will be blocked.

In August 2026, Windows Server 2025 will begin displaying warnings about readiness for the new requirements. They will become mandatory with the release of the next LTSC version of Windows Server, whose date has not yet been announced. Until then, existing KMS systems will continue to work as usual.

Administrators of physical servers can already check support for TPM attestation using the command Get-TpmSupportedFeature -FeatureList "Key Attestation". For virtual KMS hosts, Microsoft is still preparing separate recommendations.

The innovation is not directly related to pirated copies of Windows on home PCs. It does not check the user computer and does not affect popular illegal activation methods that do not rely on corporate KMS servers. Even the KMS38 method closed in November 2025 was a different story: it faked the activation period through a system file and had nothing to do with TPM or real KMS infrastructure.

Thus, Microsoft is indeed strengthening license protection, but so far only where Windows is activated in bulk. Home pirates can breathe easy, while corporate administrators should check their TPM support.

Related articles

Securitylab•Policy & Regulation

Implementing DevSecOps in Unprepared Teams: A Practical Three-Month Roadmap

Many development teams face resistance when security tools are introduced without proper process changes, leading to bypassed checks and unresolved findings. The article outlines a structured approach for small teams of five to eight developers without a dedicated security specialist, focusing on one service as a pilot. It emphasizes assigning clear roles including a Security Champion, selecting initial checks such as secret scanning with Gitleaks and dependency analysis, and converting scanner reports into actionable tasks with owners and deadlines. The plan covers the first eight weeks of setup, including baseline handling for legacy issues, automated blocking rules, and incident rehearsal exercises. Metrics recommended include time to first triage, age of open critical defects, and false positive rates, aligned with DORA indicators for release performance. The guidance draws on OWASP SAMM practices and stresses that security requirements must be integrated into daily workflows rather than added as extra gates.

Habr•Policy & Regulation

Why Technically Strong CISOs Lose to Weaker Peers: The Hidden Role of Internal Politics

A new analysis from independent expert Andrey Biryukov explains why technically proficient CISOs frequently fail to secure budgets and executive support while less technical peers succeed. The core issue lies not in technical knowledge but in the ability to translate security risks into business language that resonates with CFOs, CEOs, and boards. Biryukov details how influence, rather than formal authority, determines whether security initiatives gain traction or stall in endless approvals. He emphasizes building coalitions in advance, crafting compelling narratives, and preparing concrete business cases that quantify revenue impact and regulatory exposure. The article also highlights common pitfalls such as relying on fear-based arguments or ignoring stakeholder KPIs. Ultimately, the piece argues that selling security internally is essential for any CISO who wants both resources and long-term survival in the role.

AntiMalware•Policy & Regulation

Bybit Restricts Transfers to Sanctioned Entities Including Lazarus Group and CryptoPro

Cryptocurrency exchange Bybit has notified users that transfers to or from entities on its Restricted Counterparties list are prohibited, regardless of amount or whether conducted directly or through intermediaries. The list includes the North Korean state-sponsored Lazarus group and Russian cryptographic software developer CryptoPro due to their presence on sanctions lists from the United States, European Union, and United Kingdom. Bybit will automatically reject outgoing transfers to listed counterparties and may freeze incoming funds from them or related addresses, with potential account suspension or closure for users involved. The exchange emphasizes that blockchain transparency allows tracing of funds without user confessions and reserves the right to block transactions even with counterparties not yet explicitly listed. These measures are embedded in Bybit's terms of service to ensure compliance with international sanctions regimes.

AntiMalware•Policy & Regulation

Russia's MinTsifry Flags Google Android Developer Verification Rules as Risk to Domestic Apps

Russia's Ministry of Digital Development is assessing new Google policies that will require developer registration for Android apps distributed outside Google Play. The changes, starting in select countries in 2026 and expanding globally in 2027, could block sideloading of Russian applications previously removed from official stores due to sanctions. Minister Maksut Shadaev described the scenario as a potential barrier where users may no longer freely install APK files from third-party sources. Google plans to retain advanced modes and ADB installation options with extra warnings for unverified apps. Custom firmware projects such as LineageOS have stated their devices will remain unaffected by the verification system. Russian banks, marketplaces, and other services that rely on direct APK distribution are viewed as the most exposed.