Children's Commissioner also furious with Ofcom over a string of failures

Children in the UK report that the Online Safety Act (OSA) has had no discernible impact on their ability to encounter harmful content online, more than a year after its key child protection provisions became active. Dame Rachel de Souza, England's Children's Commissioner, conveyed this feedback to Members of Parliament and peers, noting that young people largely do not understand the legislation or its intended effects on their online experiences.
De Souza's comments were made during the initial evidence session of the House of Lords Communications and Digital Committee's inquiry into the OSA's implementation and effectiveness. A central point of her criticism was the Act's emphasis on moderating harmful content, rather than addressing potentially harmful design features of online platforms.
Despite calls from UK politicians for controls on such platform features, no specific legislation or OSA provisions have materialized to address them. De Souza expressed significant frustration over the lack of concrete evidence demonstrating that the OSA has meaningfully altered social media platform operations. She drew a contrast with the United States, where recent legal pressures have prompted significant child safety concessions from Meta.
Concerns regarding addictive platform design have resurfaced following Meta's proposed $18 billion settlement in a US child safety case. While not admitting wrongdoing, the proposed settlement would require Meta to implement two-hour daily limits for users under 18 on Facebook and Instagram, introduce prompts to discourage endless scrolling, and address usage during school hours and at night. Additionally, the proposal would allow children to opt out of algorithmically ranked feeds, directly addressing concerns raised by De Souza and other UK lawmakers.
De Souza suggested that the OSA has not been flexible enough to keep pace with current developments, citing the Meta settlement as an example of results that Ofcom and UK lawmakers should strive to achieve, even if it necessitates evolving the legislation.
The Children's Commissioner also announced her intention to use her statutory powers to compel Ofcom, the OSA's regulator, to provide copies of safety risk assessments submitted by technology companies. De Souza stated that Ofcom had refused to share these assessments with her, despite her role as the "most senior safeguarding person in this country for children," and indicated resistance even if she invoked her powers. She highlighted the difficulty of assessing the efficacy of safety mechanisms without access to these risk assessments.
Ofcom's ability to disclose such information is restricted by section 393(1) of the Communications Act 2003, which governs information obtained through its regulatory functions. Disclosure is permissible only with the consent of the business concerned or if one of the statutory gateways in section 393(2) applies.
When asked if compelling tech companies to complete risk assessments was sufficient for meaningful change or if further legislation was needed, De Souza emphasized the need for Ofcom to "use its teeth." While acknowledging Ofcom's increased presence in tech regulation over the past year, including investigations into pornography companies for age verification violations and its involvement in the Grok "nudifying" controversy, she argued that the regulator had not been forceful enough.
De Souza accused Ofcom of reacting to harms rather than anticipating them, stating that children are concerned about emerging issues like AI and "nudifying apps." She called for UK politicians to empower Ofcom to pursue offending organizations more strongly, concluding that the regulator's effectiveness has been insufficient.
The commissioner also criticized Ofcom's child safety codes under the OSA, describing them as technical documents for companies rather than protections designed for children. She urged Ofcom to fully utilize its powers, impose substantial fines, and act proactively before new harms become entrenched.
In response, an Ofcom spokesperson stated that the organization works closely with the Children's Commissioner and shares her objectives for online child safety. They noted the publication of their analysis of risk assessments from the OSA's first year in December, outlining expected improvements from platforms. Ofcom confirmed that their actions have led to material improvements in risk assessments, ensuring tech companies implement necessary measures to address identified risks. The spokesperson reiterated that Ofcom is subject to legal restrictions regarding the disclosure of business-related information.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets