Ad visibility narrows without a warning, identity checks open up to biometrics, a fake verification box spreads across 5,400 sites
Today's 3 verified headlines: Google's Limited Ad Serving, which arrives with no suspension, no strike and no disapproval, cut one account's monthly average impressions from 800,000 to 350,000 in a documented case; the Central Bank of the Republic of Türkiye published a communiqué amendment adding a biometric option to remote identity checks at payment and electronic money institutions in the Official Gazette of 4 September 2026; and Netskope found the same injected script on more than 5,400 compromised sites, pulling its payload from smart contracts on the BNB Smart Chain testnet. Each story's full analysis, sources and business impact live on its own page.
Limited Ad Serving in Google Ads: visibility lost without a suspension
Search Engine Land published an analysis by John Horn on 4 September 2026. It examines Limited Ad Serving, introduced by Google for Search and YouTube in 2023: no suspension, no strike, no disapproval, only a restriction on how often the account's ads can run in auctions. The areas flagged most often are affiliates, insurance, consumer services, third-party lead generation, travel and franchise models. In the case study an authorized retailer account saw monthly average impressions fall from 800,000 to 350,000, the appeal was rejected almost immediately, and the restriction lifted after seven months. Google extended the policy to Gmail, Play Store and Discover in 2026, with the rollout expected to continue through 2028.
Türkiye's central bank adds a biometric option to remote ID checks
The Central Bank of the Republic of Türkiye published an amendment to its information systems communiqué for payment and electronic money institutions in the Official Gazette of 4 September 2026, issue 33360. Biometric data was added to the first paragraph of Article 22, and a definition of identity document based on the Turkish Republic Identity Card Regulation entered the text. Document authenticity will be tested primarily through near field communication, and where that fails, at least one of optical character recognition, a card reader, or a method set after consulting MASAK applies. Foreign nationals may be identified remotely with an ICAO 9303 compliant passport that supports near field communication. The communiqué took effect on the date of publication.
Blockchain-hosted malware spreads across 5,400 sites
Netskope found the same injected script on more than 5,400 compromised sites, most of them built on WordPress or PrestaShop. The script pulls its next stage payload from smart contracts on the BNB Smart Chain testnet, a technique called EtherHiding. Visitors are shown a fake CAPTCHA and asked to paste a PowerShell command into the Windows Run box. More than 300 infected sites stay active per day, and daily endpoint contact peaked at 536 during August 2026. How the sites were first breached is still unknown.
Quiet losses surface late.
Let's review your ad visibility, your remote identity verification flow and your site's security together, and clarify which step fits your business.