Google Chrome Blocks Over 7 Billion Unwanted Notifications Daily on Android
Google stated that Chrome protection systems blocked more than 7 billion unwanted notifications daily on Android throughout the first quarter of 2026. Websites have increasingly turned to browser notifications to push phishing pages, fraudulent payment requests, malware downloads, and other unsolicited content.
Chrome employs a layered "Swiss cheese" defense strategy in which multiple protective mechanisms overlap to cover gaps left by any single filter. If a suspicious notification bypasses one layer, subsequent filters are designed to catch it. The browser can automatically revoke notification permissions from sites that have not been visited for a long time or that frequently trigger security warnings. When permission is withdrawn, Chrome can also cancel any active subscription associated with the site.
Users who wish to restore access can do so through the Safety Hub section. Protection mechanisms evaluate not only individual sites but also related networks and coordinated activity involving service workers. Key signals include message volume, frequency of permission requests, user dwell time, and actual engagement levels.
Resources classified as overly intrusive face a strict limit of 1,000 messages per minute; any traffic exceeding this threshold receives an HTTP 429 response. Repeat offenders encounter tighter restrictions that are lifted only after a sustained period of compliant behavior. On Android, Google also redesigned permission request dialogs to be less intrusive, resulting in lower background activity and reduced battery consumption.
Users can review which sites are allowed to send notifications in desktop Chrome via Settings β Privacy and security β Site settings β Notifications. On Android the equivalent controls are located under Settings β Notifications.
Related articles
Mail.ru Blocks Phishing Wave Using Password-Protected RAR Archives
Mail.ru's antispam team has stopped a new phishing campaign that relies on password-protected RAR archives. These messages accounted for 13% of all blocked emails over the past month. The attackers impersonate business correspondents by sending contracts, signature requests, and tax-related notifications during the reporting season. Each email contains the archive password in plain text, allowing the recipient to open a malicious executable hidden inside. The malware is designed to steal credentials, grant remote access, or exfiltrate personal and corporate data. Mail.ru's filtering system uses more than 30 machine-learning models and antispam checks to detect such threats. Users are advised to verify senders carefully and avoid launching files from unexpected attachments even when a password is supplied.
Kaspersky Adds Call Filtering to Kaspersky Secure Mobility Management for Android Devices
Kaspersky has introduced call control capabilities into the expanded version of Kaspersky Secure Mobility Management. The new feature allows corporate Android devices running Kaspersky Endpoint Security for Android to check incoming call numbers against both local offline databases and global online reputation sources. Depending on company policy, the system can display warnings to employees or automatically block suspicious calls. Administrators gain the ability to define rules by call category, maintain black and white lists, and apply different policies to specific employee groups. The update targets risks from telephone fraud and social engineering attempts that aim to extract confidential corporate information or funds. It also helps reduce unwanted spam calls that disrupt staff who handle high volumes of incoming communications. Kaspersky Secure Mobility Management provides full lifecycle control over corporate mobile devices, applications, data, and security policies.
Behavioral Anti-Fraud: How Systems Analyze User Actions Beyond Device and Browser Fingerprints
Anti-fraud systems are shifting from static device and browser fingerprinting toward continuous behavioral analysis powered by machine learning. The article explains why matching User-Agent strings with Canvas or font rendering is no longer sufficient, as bot developers can easily synchronize these static signals. Modern defenses now record dozens of micro-events during a session, including keystroke timing, mouse trajectories, scroll speed, and focus changes, to build a dynamic Trust Score. These models are trained on large clusters of real-user behavior and flag sessions whose patterns fall outside legitimate clusters even when fingerprints appear realistic. The text details dwell time, flight time, error-correction patterns, natural hand tremor, and acceleration curves governed by Fittsβs law as key biometric markers. It also covers browser-level signals such as Event.isTrusted, CDP artifacts, and navigator.webdriver flags that reveal automation frameworks. The discussion extends to mobile sensors and concludes that perfectly error-free, mathematically smooth input is itself a strong indicator of synthetic activity.
Free Online Panel Examines Rising Omnichannel Scams and Multichannel Fraud Tactics
The Brazilian human risk management firm Eskive is hosting its third free online panel on August 18 at 11 a.m. to address the growing threat of omnichannel cyber fraud. Experts will discuss how attackers combine multiple channels such as email, SMS, and other vectors to create more convincing social-engineering narratives that bypass traditional single-channel defenses. The event will feature CEO Priscila Meyer as moderator along with cyber threat intelligence specialist Thiago Bordini and Santa Catarina Civil Police investigator Elias Edenis. Participants will gain practical insights from real client simulations, live Q&A sessions, and interactive quizzes designed to improve organizational preparedness. The panel aims to highlight why users accustomed to recognizing basic phishing or smishing attempts remain vulnerable when fraudsters deploy coordinated, multi-channel campaigns.