LIVE · cybersecurity feed
Live wire
OpenAI Announced $1B in Defensive Tools for Water UtilitiesAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsCVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeCVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesHackers Leak Millions of Airport Passenger Records After Ransom RefusalUsing a VM to Contain an AI AgentCVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CXCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update release
security

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]

zeroday.news ·

TikTok and its parent company, ByteDance, have agreed to a $400 million settlement with the U.S. Department of Justice (DoJ) to resolve allegations of violating the Children’s Online Privacy Protection Act (COPPA). The agreement, announced by the DoJ, addresses a lawsuit filed in 2024 concerning the social media platform's handling of user data.

The DoJ's lawsuit alleged that TikTok knowingly permitted children under the age of 13 to create standard accounts, bypassing its restricted "Kids Mode." Furthermore, the company was accused of collecting and retaining personal information from these underage users without obtaining parental consent. The allegations also included claims that TikTok failed to delete accounts and associated data when requested by parents and maintained insufficient procedures for identifying and removing underage accounts from its platform.

This settlement follows a previous enforcement action against TikTok's predecessor, Musical.ly. In 2019, Musical.ly settled with the Federal Trade Commission (FTC) for $5.7 million over similar allegations of illegally collecting personal data from children under 13 without parental consent. Last year, the FTC referred a new investigation to the DoJ, asserting that TikTok continued to breach COPPA rules despite its prior commitment to compliance.

Under the terms of the new settlement, TikTok will immediately pay $300 million. An additional $100 million will be paid if a court vacates the earlier consent decree involving Musical.ly. This combined $400 million figure represents one of the largest settlements ever reached in COPPA cases.

The DoJ acknowledged that TikTok has implemented significant changes since 2024, specifically noting improvements in its ownership structure, data management practices, and legal compliance operations. The U.S. government also recognized TikTok's efforts to enhance its privacy retention policies, strengthen age-related controls, and improve parental oversight features on the platform.

Assistant Attorney General Brett A. Shumate emphasized the importance of companies adhering to laws governing the collection of children's personal information. He stated that the resolution secures a substantial monetary recovery and underscores the Department's commitment to ensuring children receive the full protections mandated by Congress.

It is important to note that the announcement clarifies that this settlement resolves only the allegations, and there has been no judicial determination that TikTok or ByteDance is liable for the alleged violations.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

CVE-2026-81578

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

breachcritical

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

CVE-2026-59346critical

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

patch

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

breach

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets