Google Chrome Blocks Over 7 Billion Unwanted Notifications Daily on Android
Google stated that Chrome protection systems blocked more than 7 billion unwanted notifications daily on Android throughout the first quarter of 2026. Websites have increasingly turned to browser notifications to push phishing pages, fraudulent payment requests, malware downloads, and other unsolicited content.
Chrome employs a layered "Swiss cheese" defense strategy in which multiple protective mechanisms overlap to cover gaps left by any single filter. If a suspicious notification bypasses one layer, subsequent filters are designed to catch it. The browser can automatically revoke notification permissions from sites that have not been visited for a long time or that frequently trigger security warnings. When permission is withdrawn, Chrome can also cancel any active subscription associated with the site.
Users who wish to restore access can do so through the Safety Hub section. Protection mechanisms evaluate not only individual sites but also related networks and coordinated activity involving service workers. Key signals include message volume, frequency of permission requests, user dwell time, and actual engagement levels.
Resources classified as overly intrusive face a strict limit of 1,000 messages per minute; any traffic exceeding this threshold receives an HTTP 429 response. Repeat offenders encounter tighter restrictions that are lifted only after a sustained period of compliant behavior. On Android, Google also redesigned permission request dialogs to be less intrusive, resulting in lower background activity and reduced battery consumption.
Users can review which sites are allowed to send notifications in desktop Chrome via Settings → Privacy and security → Site settings → Notifications. On Android the equivalent controls are located under Settings → Notifications.
Related articles
Why 'Be Vigilant' Is Not Enough: Dissecting Human Psychology During Social Engineering Attacks
A cybersecurity expert with years of SOC and pentest experience explains why traditional awareness training fails against social engineering. The article details how attackers exploit psychological levers such as authority, urgency, reciprocity, social proof, and emotion to bypass conscious decision-making. It emphasizes that people who fall for attacks are often the most helpful and diligent employees, not the careless ones. Instead of relying on willpower in stressful moments, organizations must implement procedures that enforce independent verification and protect the right to pause. The piece also highlights how a blame-free culture dramatically reduces incident impact by encouraging early reporting. Technical measures that reduce reliance on a single human decision are presented as effective supplements to policy.
Scammers Impersonate Gas Workers to Pressure Russians into Overpriced Repairs Before September 1 Deadline
Fraudsters have started visiting apartments and private homes in Russia, posing as employees of gas services or management companies. They claim to have discovered critical issues such as gas leaks, faulty valves, problematic meters, or dangerous chimneys during supposed August inspections. Residents are warned that gas will be disconnected by September 1 unless immediate and expensive repairs are paid for on the spot. In some cases, scammers demand prepayments for urgent work and then disappear with the money. Victims are often charged 5 to 10 times the market price for equipment replacement. The Moshelovka platform of the Narodny Front has reported these incidents and issued safety recommendations. Residents are advised to verify maintenance schedules in advance and never pay cash or transfer money to individuals without confirmation.
VC.ru Blocks Lawyer's Account After Article Exposing In-Platform Phishing Scheme
A Russian lawyer specializing in IT law and cryptocurrency regulation published an article on VC.ru detailing a phishing operation that abused the platform's own articles. The scheme involved posting seemingly legitimate content that later had links altered to redirect users to fake services stealing crypto assets. Within an hour of publication, the author's four-year-old account was automatically blocked under rules prohibiting multiple accounts to evade bans, despite the author having no prior restrictions or secondary accounts. After formal complaints citing Russian data protection law 152-FZ and consumer protection statutes, the platform reversed the ban but initially reclassified the account as commercial, demanding a monthly fee of 56,000 rubles for indexing. The account status was later restored following further legal correspondence. The incident highlights platform moderation challenges when reporting security threats involving paid accounts on the same site.
Email Graph Analysis Detects Impersonated Suppliers When DKIM and SPF Pass
Security researchers have outlined a practical method to identify business email compromise attempts that bypass traditional authentication checks. The approach relies solely on metadata from mail server logs to build communication profiles between external and internal addresses. By tracking first contact, one-way traffic, dormant periods, unusual sending hours, and domain similarity, analysts can flag high-risk messages requesting payment changes. The technique works against mailbox takeover scenarios where attackers reuse legitimate threads and valid signatures. Implementation uses existing Postfix or Microsoft Exchange logs and requires no new infrastructure beyond daily exports. A simplified version focusing only on lookalike domain detection can be built in a single evening and still catches most supplier impersonation attempts.