Google's Blogger platform incorrectly locked large numbers of legitimate blogs under its "Malware and Similar Malicious Content" policy after an apparent automated false positive, leaving affected publishers unable to use key dashboard functions and placing some sites in read-only status. Users began reporting the issue in Google's official help forums, where Product Experts said the internal team had been alerted and that some appealed blogs were already being restored, although some publishers said restored sites were later deleted again.
Community reports indicated the misclassification likely came from Blogger's automated scanning systems flagging benign code in third-party templates as malicious, including copyright-protection or encryption scripts used by popular template providers such as Sora Templates and Gooyaabi. Affected users were told to request manual review through the Blogger dashboard, while unresolved cases risk permanent deletion after 90 days if the lock is not cleared.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
In forum responses, Blogger Product Experts said the incident appeared to be a large-scale false positive caused by Google's automated systems rather than a deliberate crackdown on malicious blogs. They also indicated Google's internal team had been alerted and was working on a fix.
After the lockouts began, hundreds to thousands of affected site owners posted complaints in Google's official Blogger Help Community. The volume and similarity of reports indicated the issue was widespread rather than isolated.
Beginning on August 4, 2026, Google's Blogger platform started locking large numbers of legitimate blogs under its "Malware and Similar Malicious Content" policy. Affected publishers lost access to key dashboard functions, and some blogs were reportedly deleted or made read-only pending review.
Some affected publishers who submitted appeals reported that their blogs were restored. Other users said restored blogs were later deleted again, indicating inconsistent remediation during the incident.
Early community analysis suggested Blogger's scanner may have mistaken copyright-protection encryption scripts in third-party templates, including those from Sora Templates and Gooyaabi, for obfuscated malware. This was presented as a suspected technical cause of the false positives.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcescworld.com
Open sourcexakep.ru
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcesupport.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.