LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
security

UK's Online Safety Act has made 'absolutely no difference,' kids say

Children's Commissioner also furious with Ofcom over a string of failures

zeroday.news ·

Children in the UK report that the Online Safety Act (OSA) has had no discernible impact on their ability to encounter harmful content online, more than a year after its key child protection provisions became active. Dame Rachel de Souza, England's Children's Commissioner, conveyed this feedback to Members of Parliament and peers, noting that young people largely do not understand the legislation or its intended effects on their online experiences.

De Souza's comments were made during the initial evidence session of the House of Lords Communications and Digital Committee's inquiry into the OSA's implementation and effectiveness. A central point of her criticism was the Act's emphasis on moderating harmful content, rather than addressing potentially harmful design features of online platforms.

Despite calls from UK politicians for controls on such platform features, no specific legislation or OSA provisions have materialized to address them. De Souza expressed significant frustration over the lack of concrete evidence demonstrating that the OSA has meaningfully altered social media platform operations. She drew a contrast with the United States, where recent legal pressures have prompted significant child safety concessions from Meta.

Concerns regarding addictive platform design have resurfaced following Meta's proposed $18 billion settlement in a US child safety case. While not admitting wrongdoing, the proposed settlement would require Meta to implement two-hour daily limits for users under 18 on Facebook and Instagram, introduce prompts to discourage endless scrolling, and address usage during school hours and at night. Additionally, the proposal would allow children to opt out of algorithmically ranked feeds, directly addressing concerns raised by De Souza and other UK lawmakers.

De Souza suggested that the OSA has not been flexible enough to keep pace with current developments, citing the Meta settlement as an example of results that Ofcom and UK lawmakers should strive to achieve, even if it necessitates evolving the legislation.

The Children's Commissioner also announced her intention to use her statutory powers to compel Ofcom, the OSA's regulator, to provide copies of safety risk assessments submitted by technology companies. De Souza stated that Ofcom had refused to share these assessments with her, despite her role as the "most senior safeguarding person in this country for children," and indicated resistance even if she invoked her powers. She highlighted the difficulty of assessing the efficacy of safety mechanisms without access to these risk assessments.

Ofcom's ability to disclose such information is restricted by section 393(1) of the Communications Act 2003, which governs information obtained through its regulatory functions. Disclosure is permissible only with the consent of the business concerned or if one of the statutory gateways in section 393(2) applies.

When asked if compelling tech companies to complete risk assessments was sufficient for meaningful change or if further legislation was needed, De Souza emphasized the need for Ofcom to "use its teeth." While acknowledging Ofcom's increased presence in tech regulation over the past year, including investigations into pornography companies for age verification violations and its involvement in the Grok "nudifying" controversy, she argued that the regulator had not been forceful enough.

De Souza accused Ofcom of reacting to harms rather than anticipating them, stating that children are concerned about emerging issues like AI and "nudifying apps." She called for UK politicians to empower Ofcom to pursue offending organizations more strongly, concluding that the regulator's effectiveness has been insufficient.

The commissioner also criticized Ofcom's child safety codes under the OSA, describing them as technical documents for companies rather than protections designed for children. She urged Ofcom to fully utilize its powers, impose substantial fines, and act proactively before new harms become entrenched.

In response, an Ofcom spokesperson stated that the organization works closely with the Children's Commissioner and shares her objectives for online child safety. They noted the publication of their analysis of risk assessments from the OSA's first year in December, outlining expected improvements from platforms. Ofcom confirmed that their actions have led to material improvements in risk assessments, ensuring tech companies implement necessary measures to address identified risks. The spokesperson reiterated that Ofcom is subject to legal restrictions regarding the disclosure of business-related information.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

breach

FBI Probes Possible Breach of 153 Million Driver’s Licenses

The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web

nation-state

Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms

Most of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone leaves a bitter taste in the mouth. A team from the Korea Advanced Institute of Science and Technology (KAIST), working with the National University of Singapore and Singapore Management University

patch

Windows memory integrity switches on automatically for eligible devices in October 2026

Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too. Memory integrity is the layer that allows only trusted kernel-mode code and drivers to run, which is how it stops an attacker who is tr

ai

Smashing Security podcast #483: This AI helps thieves steal your iPhone

You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees