CYBER DELTA FORCESearch

HTTPS by default

One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”.

CDF News DeskGoogle Security Blog29 Oct 2025, 2:46 am
CDF REPORT

One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user's permission before the first access to any public site without HTTPS. The “Always Use Secure Connections” setting warns users before accessing a site without HTTPS Chrome Security's mission is to make it safe to click on links. When links don't use HTTPS, an attacker can hijack the navigation and force Chrome users to load arbitrary, attacker-controlled resources, and expose the user to malware, targeted exploitation, or social engineering attacks.

That gives users no opportunity to see Chrome's "Not Secure" URL bar warnings after the risk has occurred, and no opportunity to keep themselves safe in the first place. In this mode, Chrome attempts every connection over HTTPS, and shows a bypassable warning to the user if HTTPS is unavailable.

Who is affected

That gives users no opportunity to see Chrome's "Not Secure" URL bar warnings after the risk has occurred, and no opportunity to keep themselves safe in the first place.

In this mode, Chrome attempts every connection over HTTPS, and shows a bypassable warning to the user if HTTPS is unavailable.

How organizations are responding

We also previously discussed our intent to move towards HTTPS by default .

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

What remains unknown

The available reporting does not establish who is behind the activity, if an attacker is involved.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Suspected Black Axe gang leaders face cybercrime charges in the USBleepingComputer · 15 Sept 2026, 3:20 pmMicrosoft confirms KB5002914 Excel update breaks copy and pasteBleepingComputer · 15 Sept 2026, 2:10 pmMicrosoft releases emergency Windows updates to fix RDS failuresBleepingComputer · 15 Sept 2026, 2:22 amMembers of ‘Black Axe’ cybercriminal group extradited from South AfricaThe Record · 15 Sept 2026, 1:10 am