Microsoft Tightens Corporate Windows Activation with TPM-Bound KMS Servers
Microsoft has decided to tighten controls in its corporate Windows activation system, prompting some media outlets to declare the end of pirated Windows 11. In reality, the hunt for home users has not begun: the new requirement will only affect organizations that maintain their own KMS servers.
KMS allows companies to activate computers inside their network through a single server without sending each machine directly to Microsoft. The problem is that attackers have learned to create fake and cloned KMS hosts that distribute licenses to devices for which no one has paid.
The new KMS Hardware-Secured technology will bind such a server to TPM. The chip must confirm the hardware identity to Microsoft and prove that the platform has not been modified after registration. If the check fails, activation of the corporate fleet will be blocked.
In August 2026, Windows Server 2025 will begin displaying warnings about readiness for the new requirements. They will become mandatory with the release of the next LTSC version of Windows Server, whose date has not yet been announced. Until then, existing KMS systems will continue to work as usual.
Administrators of physical servers can already check support for TPM attestation using the command Get-TpmSupportedFeature -FeatureList "Key Attestation". For virtual KMS hosts, Microsoft is still preparing separate recommendations.
The innovation is not directly related to pirated copies of Windows on home PCs. It does not check the user computer and does not affect popular illegal activation methods that do not rely on corporate KMS servers. Even the KMS38 method closed in November 2025 was a different story: it faked the activation period through a system file and had nothing to do with TPM or real KMS infrastructure.
Thus, Microsoft is indeed strengthening license protection, but so far only where Windows is activated in bulk. Home pirates can breathe easy, while corporate administrators should check their TPM support.
Related articles
Multiple Ozon Apps Removed from Google Play Following Sanctions on Ozon Bank
Several Ozon applications have been removed from the Google Play store, affecting Android users who can no longer download the main Ozon client along with Ozon Fresh, Ozon Seller, Ozon Job and Ozon Travel. Ozon stated that the company did not violate Google Play rules, yet the exact reasons for the removals remain undisclosed. The action follows the earlier disappearance of the Ozon Bank app after the bank was placed under European Union sanctions, although no official connection has been confirmed. Apple users continue to access Ozon services through the App Store, while Android users are directed to alternative stores including RuStore, AppGallery and Galaxy Store. The company also warned against downloading APK files from unverified sources due to security risks. The removals come amid a broader wave of app store purges that also affected Yandex Pay on the App Store. Already installed applications generally continue to function, but users may face difficulties with future updates and reinstalls.
Ruthenium: Custom Chromium Build for Android Adds Russian Trusted Root CA Support
A developer has released Ruthenium, a modified Chromium browser for Android that embeds the Russian Trusted Root CA certificate issued by the Ministry of Digital Development. The build restricts trust to .ru and .рф domains only, avoiding changes to the system-wide Android certificate store. The project patches four Chromium source files to include the root with DNS constraints via CertWithConstraints, disables Google sign-in by default, and removes XR-related code for successful compilation. Ruthenium uses the official Chromium TLS verification logic without introducing a custom verifier. The APK is distributed with SHA-256 checksums, build metadata, and reproducible release tags tied to the exact Chromium revision and certificate digest. Users can install it alongside stock Chrome and use it selectively for Russian government and banking sites that rely on the state root.
US Federal Judge Orders Google to Simplify Installation of Third-Party App Stores on Android
A federal judge has directed Google to remove extra warnings and confirmation steps when users install competing app stores through Google Play on Android devices. The ruling stems from the ongoing antitrust litigation between Epic Games and Google, where a jury previously found that Google illegally maintained a monopoly over Android app distribution and in-app payments. Judge James Donato criticized the current multi-screen process as an intentional barrier designed to discourage ordinary users from choosing alternatives. Google must implement the changes within one week, making the installation of third-party stores as straightforward as any other Android application. The decision acknowledges that while Android has long permitted sideloading, the layered security prompts and hidden permission toggles effectively steered most users back to Google Play. Aptoide has already appeared in the US Google Play store as the first third-party marketplace to benefit from the eased process. Google argued the warnings protect users from malware, but the court rejected the notion that security should serve as a shield for market dominance.
Why Russia Needs Specialized Circumvention Tools Beyond Standard VPNs
The developers of Tunnel Kitten explain why another circumvention project is necessary despite the availability of numerous VPN services and solutions like AmneziaWG. A prolonged outage affected many long-term users, damaging trust and requiring ongoing fixes. Standard VPNs do not address the core issue: creating and maintaining tools to bypass internet blocks has been criminalized in Russia. This legal asymmetry makes public VPN services and self-hosted solutions risky or insufficient for users facing state-level censorship. Tunnel Kitten positions itself as a project focused on a different task that accounts for these legal realities. The team emphasizes that the problem is not merely technical but tied to the criminalization of circumvention efforts.