LIVE · cybersecurity feed
Live wire
Hackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
security

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]

zeroday.news ·

TikTok and its parent company, ByteDance, have agreed to a $400 million settlement with the U.S. Department of Justice (DoJ) to resolve allegations of violating the Children’s Online Privacy Protection Act (COPPA). The agreement, announced by the DoJ, addresses a lawsuit filed in 2024 concerning the social media platform's handling of user data.

The DoJ's lawsuit alleged that TikTok knowingly permitted children under the age of 13 to create standard accounts, bypassing its restricted "Kids Mode." Furthermore, the company was accused of collecting and retaining personal information from these underage users without obtaining parental consent. The allegations also included claims that TikTok failed to delete accounts and associated data when requested by parents and maintained insufficient procedures for identifying and removing underage accounts from its platform.

This settlement follows a previous enforcement action against TikTok's predecessor, Musical.ly. In 2019, Musical.ly settled with the Federal Trade Commission (FTC) for $5.7 million over similar allegations of illegally collecting personal data from children under 13 without parental consent. Last year, the FTC referred a new investigation to the DoJ, asserting that TikTok continued to breach COPPA rules despite its prior commitment to compliance.

Under the terms of the new settlement, TikTok will immediately pay $300 million. An additional $100 million will be paid if a court vacates the earlier consent decree involving Musical.ly. This combined $400 million figure represents one of the largest settlements ever reached in COPPA cases.

The DoJ acknowledged that TikTok has implemented significant changes since 2024, specifically noting improvements in its ownership structure, data management practices, and legal compliance operations. The U.S. government also recognized TikTok's efforts to enhance its privacy retention policies, strengthen age-related controls, and improve parental oversight features on the platform.

Assistant Attorney General Brett A. Shumate emphasized the importance of companies adhering to laws governing the collection of children's personal information. He stated that the resolution secures a substantial monetary recovery and underscores the Department's commitment to ensuring children receive the full protections mandated by Congress.

It is important to note that the announcement clarifies that this settlement resolves only the allegations, and there has been no judicial determination that TikTok or ByteDance is liable for the alleged violations.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly

A Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers.

phishing

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek.

iran

Iran-linked cyberattack shut down a UK power plant

A suspected Iran-linked cyberattack recently disrupted a small-scale UK power plant, causing it to shut down for four days. While the government confirmed the incident, it emphasized that the wider energy system remained unaffected and highly resilient. This event follows a series of similar cyber intrusions targeting water utilities in the United States, which cybersecurity analysts also suspect are linked to Iran.

gta 6high

Fake GTA 6 Extended Look and demo sites deliver an infostealer

Cybercriminals are exploiting the hype surrounding the upcoming Grand Theft Auto VI release by distributing fake demo websites that deliver an information-stealing malware. These sites impersonate Rockstar Games and trick users into downloading a malicious executable disguised as a game installer. The malware, identified as belonging to the Vidar family, is designed to steal passwords, session cookies, and other sensitive data from browsers and applications, potentially bypassing two-factor authentication through the reuse of stolen session tokens.

CVE-2026-63520critical

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)

Rapid7 has published a technical analysis of CVE-2026-63520, a critical remote code execution vulnerability in Microsoft SharePoint. The vulnerability allows an authenticated attacker to execute arbitrary code on a vulnerable server by uploading a malicious BDC model file. When combined with another vulnerability, CVE-2026-55040, it can lead to unauthenticated RCE.

cloud

NIST Warns of Unique Security Risks in Multi-Cloud Environments

NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutions