Microsoft Tightens Corporate Windows Activation with TPM-Bound KMS Servers
Microsoft has decided to tighten controls in its corporate Windows activation system, prompting some media outlets to declare the end of pirated Windows 11. In reality, the hunt for home users has not begun: the new requirement will only affect organizations that maintain their own KMS servers.
KMS allows companies to activate computers inside their network through a single server without sending each machine directly to Microsoft. The problem is that attackers have learned to create fake and cloned KMS hosts that distribute licenses to devices for which no one has paid.
The new KMS Hardware-Secured technology will bind such a server to TPM. The chip must confirm the hardware identity to Microsoft and prove that the platform has not been modified after registration. If the check fails, activation of the corporate fleet will be blocked.
In August 2026, Windows Server 2025 will begin displaying warnings about readiness for the new requirements. They will become mandatory with the release of the next LTSC version of Windows Server, whose date has not yet been announced. Until then, existing KMS systems will continue to work as usual.
Administrators of physical servers can already check support for TPM attestation using the command Get-TpmSupportedFeature -FeatureList "Key Attestation". For virtual KMS hosts, Microsoft is still preparing separate recommendations.
The innovation is not directly related to pirated copies of Windows on home PCs. It does not check the user computer and does not affect popular illegal activation methods that do not rely on corporate KMS servers. Even the KMS38 method closed in November 2025 was a different story: it faked the activation period through a system file and had nothing to do with TPM or real KMS infrastructure.
Thus, Microsoft is indeed strengthening license protection, but so far only where Windows is activated in bulk. Home pirates can breathe easy, while corporate administrators should check their TPM support.
Related articles
Bank of Russia Publishes Methodological Recommendations No. 3-MR on AI Security for Financial Market Participants
The Bank of Russia has released methodological recommendations No. 3-MR dated 16 June 2026, providing detailed guidance on ensuring information security during the development and use of artificial intelligence systems in the financial sector. The document builds on the earlier Code of Ethics for AI in finance and integrates with existing risk management, operational resilience, and data protection frameworks already familiar to credit institutions and other market participants. It introduces standardized terminology for AI-specific threats such as hallucinations, data drift, and poisoned datasets while outlining six risk categories and a four-stage AI system lifecycle model. Organizations are advised to apply threat modeling based on FSTEC methodology, implement proportional controls across data preparation, development, training, and operation phases, and maintain human oversight for high-risk automated processes. Special attention is given to supply chain risks involving third-party vendors and open-source components, requiring due diligence, provenance tracking, and contractual safeguards aligned with existing outsourcing standards. The recommendations remain non-binding yet signal clear regulatory expectations that are likely to influence future compliance checks and audits.
Aladdin Obtains New FSB Certificate for CryptoFlash Encrypted USB Drive Valid Until 2029
Aladdin has received a new FSB Russia certificate for its Aladdin CryptoFlash hardware-encrypted USB drive. The certificate number СФ/124-5574 confirms compliance with cryptographic protection requirements for classes KS1 and KS2 and remains valid until 16 July 2029. The device now supports additional Russian Linux distributions including RED OS 7.3 and 8, Alt 8 SP Workstation, Alt Workstation 10, and the OS of the Moscow Electronic School. Read and write speeds have been increased to 11 MB/s while the graphical interface received improvements. The product uses the Magma encryption algorithm in hardware and operates as a clientless solution that requires no additional drivers or software. The previous certificate remains active until December 2028, allowing both versions of the device to be used in parallel for storing and transferring official and confidential information marked DSP.
Russia's Article 10.1 on Personal Data Dissemination: Apparent and Real Contradictions in Federal Law 152-FZ
Part II of the analysis examines how the rushed redrafting of Article 10.1 between the first and second readings created serious interpretive problems in Federal Law 152-FZ. The core issues include undefined terms such as 'disclosure', conflicting definitions of 'access', 'provision' and 'dissemination' between 152-FZ and 149-FZ, and the removal of the legal basis for processing publicly available data while retaining the consent mechanism that was meant to control it. Courts have consistently held that mere openness of data does not constitute a valid processing ground, forcing subsequent operators to find their own basis under Article 6. The article highlights that the mechanism for subjects to set conditions and prohibitions was preserved, yet the underlying legal foundation that would make those rules effective was eliminated. Two possible readings of the special consent are explored, with judicial practice leaning toward the narrower interpretation that leaves conditions and prohibitions as mere additional restrictions rather than a source of authorization.
Why Deep Packet Inspection Overestimates Its Reach in Encrypted Networks
Modern encryption has fundamentally limited the effectiveness of Deep Packet Inspection systems, leaving network monitors with only metadata and behavioral patterns rather than actual content. DPI tools can still classify traffic types and apply policies based on visible flow characteristics, but they cannot read messages, files, or credentials inside properly encrypted sessions without explicit TLS inspection. The article details how TLS 1.3, Encrypted Client Hello, and QUIC further reduce passive visibility while corporate inspection remains possible only when endpoint devices trust an organizational certificate. Russian regulatory requirements around TSPU systems are discussed separately from corporate DPI use, with emphasis on the need for technical confirmation rather than assumptions. The piece also clarifies distinctions between DPI, IDS, IPS, and DLP, and explains why machine learning cannot convert metadata into decrypted payloads. Overall, the analysis shows that DPI remains useful for traffic management and known-threat detection where visibility exists, but it cannot serve as a complete security foundation.