It's the biggest legal challenge yet to addictive social media design and its impact on children.

A collective of approximately 3,000 lawsuits, initiated by state attorneys general and families, is challenging Meta, Google, ByteDance's TikTok, and Snap over allegations that their platforms are intentionally designed to be addictive and detrimental to the mental health of children and teenagers. The tech companies recently experienced a significant procedural setback in their efforts to halt these lawsuits.
The companies had sought to appeal a federal court's decision that permitted the lawsuits to proceed, arguing before the 9th US Circuit Court of Appeals that Section 230 of the Communications Decency Act provided them immunity. This 30-year-old law generally protects platforms from liability for content posted by their users. However, on August 10, the court ruled that Section 230 serves as a defense against liability, not as a barrier to lawsuits themselves, deeming the appeal premature. The core of these cases focuses not on user-generated content, but on the platforms' alleged engineering of their systems to present content in ways that foster addiction.
Techniques cited in the lawsuits, as detailed by the Nebraska Law Review, include the use of unpredictable rewards, such as likes or message responses, to trigger dopamine release and encourage habitual checking. Interface features like the "infinite scroll" are also highlighted as tools designed to maximize user engagement. The inventor of the infinite scroll reportedly described it as "taking [behavioral] cocaine and just sprinkling it all over your interface."
This ruling by the 9th Circuit, while procedurally narrow, carries substantial strategic implications. It establishes that Section 230 is a defense to be argued at trial, rather than a mechanism to prevent lawsuits from reaching court. The Third Circuit has previously gone further, determining that Section 230 does not grant immunity to platforms facing tort lawsuits for injuries caused by their own algorithmic designs, essentially treating the algorithm as a potentially defective product.
Discovery in these cases has already unearthed potentially damaging internal communications. A 2016 email attributed to Mark Zuckerberg reportedly suggested that alerting parents to teens' live videos would "probably ruin the product from the start." A recent court filing also claimed that social media employees have likened their platforms to drugs, with one Meta employee allegedly writing, "we're basically pushers."
Snapchat has also faced scrutiny. A filing in a New Mexico case indicated that by late 2022, Snap employees were receiving approximately 10,000 sextortion reports monthly. An internal investigation reportedly concluded that 70% of victims did not report abuse due to a belief that Snap would not act, and none of the 30% who did report received a response. This information emerged from an unredacted complaint in New Mexico, not from Snap's own disclosures.
The New Mexico case against Meta, which involves similar complaints, recently resulted in a judgment totaling $942 million. The judge added $567 million to the original amount, finding that Meta had "created a public nuisance through its platform design."
Despite the alleged awareness of these issues by executives, effective safety measures have reportedly been lacking. Researchers from NYU and Northeastern University tested 86 youth safety features across various platforms and found that 51 failed their tests. Snapchat's failure rate was 73%, Instagram's 66%, YouTube's 55%, and TikTok's 50%. Nine features could not even be activated during the tests. All tested cyberbullying safeguards reportedly failed, with researchers easily finding bypasses. For example, searching "eating disorder" on Instagram's autocomplete feature reportedly suggested deliberate misspellings used by pro-eating-disorder communities to circumvent platform blocklists.
Parents are advised to independently verify the effectiveness of in-app safety features by creating test accounts and confirming that settings function as advertised. Open family discussions about social media usage and screen time are also encouraged. In cases of online harassment, children should be encouraged to report it immediately, and evidence should be saved. Blocking and reporting accounts are recommended, and involving schools or law enforcement is crucial if threats, blackmail, or sexual exploitation are involved. Reports of sextortion can also be made directly to the National Center for Missing and Exploited Children's CyberTipline, rather than relying solely on platform reporting mechanisms. The coming months are expected to determine whether these lawsuits lead to significant changes in platform design or if settlements are reached.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early