LIVE · cybersecurity feed
Live wire
Cisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEV
security

European Commission set to push social media restrictions, safety requirements into law

The proposal, known as the EU KIDS Act, would block social media platforms from offering accounts to children younger than 13 and establish a bloc-wide minimum age of 15 for account creation.

zeroday.news ·

The European Commission (EC) has unveiled a comprehensive proposal, dubbed the EU KIDS Act, aimed at significantly restricting social media access for minors and mandating design changes to enhance child safety online. The initiative, announced on a Thursday, seeks to bar children under 13 from social media platforms entirely and establish a minimum age of 15 for independent account creation across the bloc.

Under the proposed legislation, children between 13 and 15 would only be permitted to access social media through "mini accounts" linked to a guardian's account. These mini accounts would be subject to strict regulations, including limitations on social contacts and a daily screen time cap of one hour. For children under 13, access to social media would be completely blocked, with the exception of parent-controlled tools designed to restrict an adult's device use to child-friendly video-sharing services. Service providers would be responsible for developing and ensuring the ease of use of these tools.

The EC's proposal is part of a broader global trend, with countries like Australia, Spain, France, China, Turkey, and the UK either having implemented or planning similar measures due to growing concerns about technology's impact on children. Commission President Ursula von der Leyen highlighted that current technologies were not designed with children's well-being in mind.

A core tenet of the EU KIDS Act is the requirement for online services to be "safe by design" and appropriate for children. This extends to social media platforms, online games, video-sharing services, and AI chatbots. The proposal specifically bans "addictive features" such as profiling-based recommender feeds that can lead minors into "rabbit holes of harmful content." Other prohibited features include infinite scroll without stopping points, reward tricks, push notifications during sleeping hours, and unsolicited contact from strangers.

For AI companions and chatbots, the proposal mandates that they be turned off by default and requires protocols to prevent them from simulating relationships that could foster emotional dependency. Minors' profiles would be private by default, with geolocation, microphone, and camera access blocked. Platforms would also need to provide simple methods for teens to block and mute users, as well as "safe recommender" systems that minors can reset or control.

To ensure privacy protection, the KIDS Act would require online services and app stores to deploy an EU age verification app, which was introduced in April. This app is designed not to store identity documents or biometric data, adhering to high privacy standards. Additionally, social media and video-sharing platforms would be required to implement age verification tools for new accounts and estimate ages for existing accounts using methods like creation date or credit card information.

Enforcement of the EU KIDS Act would involve "very large" providers submitting compliance plans to the EC and a third-party auditor. The EC would review auditor reports and address any identified deficits. The Commission noted that existing Digital Services Act and Artificial Intelligence Act restrictions provide a foundation for enforcement. Investigations into suspected violations would be accelerated, aiming for completion within 90 days. Non-compliant online providers could face fines up to 6% of their global annual sales and would be required to contribute to regulators' oversight costs.

However, enforcing social media bans has proven challenging. Research commissioned by the Australian government indicated that their ban has not prevented 61% of Australian children aged 12 to 15 from accessing major platforms. Australia recently increased maximum fines for non-compliant tech platforms to AU$99 million ($68 million) and strengthened investigative powers for its eSafety Commissioner. Experts suggest that the technological landscape, including VPNs and age assurance technologies, along with privacy concerns related to data collection, will present complexities for lawmakers and implementers.

The proposal has drawn criticism from tech lobbyists and digital rights advocates. Concerns have been raised regarding the lack of specified technical, security, or accreditation standards for the KIDS Act's implementation, leaving critical decisions for future acts. Digital freedoms advocates argue that mandating age verification for all users, including adults, by requiring ID documents and smartphone use for the EU age verification app, could imperil privacy and disproportionately affect marginalized individuals without IDs. They contend that platforms should be required to prove their safety rather than demanding users prove their age to exercise online rights.

Despite the backlash, the European Commission cited strong public support, referencing a Special Eurobarometer on the Digital Decade 2026 survey which found that 92% of Europeans consider improved online safety for children a "top policy priority." The proposal now requires support from the European Parliament and member states to become law, with broad support for social media bans for young teens suggesting a significant chance of enactment.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilityhigh

Cisco alerts customers to second actively exploited zero-day in as many days

The latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025. The post Cisco alerts customers to second actively exploited zero-day in as many days appeared first on CyberScoop.

security

Researchers find way to listen in on headphones from afar

Eve's dropping in on Alice and Bob

security

[Virtual Event] Cybersecurity Outlook 2027

ai

Should you care about an “AI slowdown?”

In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.

malware

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

Beware the SparroWocky, my son! The backdoor that bites…

patch

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS said it can no longer recover customer data and resources stored in its Middle East (Bahrain) region, known as me-south-1, or in one availability zone of its Middle East (UA