Visualização de leitura

New Instagram and Facebook rules set a default two-hour limit for teens

Meta decided that discretion was the better part of valor on Wednesday, agreeing to settle a landmark child safety case for up to $17 billion. The agreement would introduce a default two-hour daily limit for teens on Instagram and Facebook, overnight restrictions, and a range of other protections.

It also brings the trial to an early end before Mark Zuckerberg, who was listed as a witness, could testify.

The company reached the settlement with a bipartisan coalition of 51 state attorneys general, after four days of proceedings in a federal trial in Oakland.

California, Colorado, Kentucky and New Jersey led the case, which they filed in 2023. It alleged that Meta broke state laws by designing addictive products for young users without warning them of the risks. It also accused the company of violating the federal Children’s Online Privacy Protection Act (COPPA) law, which protects the privacy of children under 13.

Because violating these laws carries potentially hefty fees for each violation, Meta’s liability could reportedly have run to $1.4 trillion had it lost at trial. The states had proposed a penalty of $193 billion. By settling, Meta reduced that potential bill considerably.

Meta denies the allegations, and we should point out the settlement does not constitute an admission of wrongdoing.

What Meta will have to do in the US

Under the agreement, Meta must introduce a default two-hour daily limit for Facebook and Instagram users under 18 in participating US states and territories that only a parent can lift.

Meta must also block access between midnight and 6:00 am unless a parent intervenes. Most notifications will be silenced between 10:00 pm and 7:00 am, and during the school day from 8:00 am to 3:00 pm between August 15 and June 15.

The social media giant must also hide likes and reaction counts from users under 18 by default. Teens will also be banned from applying filters that imitate cosmetic procedures, although ordinary makeup, skin-smoothing, fantasy, and parody effects are excluded.

Teens can opt into a chronological feed populated by accounts they follow or have friended, rather than content selected by Meta’s recommendation algorithm. Meta must also provide its decision within six hours in at least 90% of English- and Spanish-language reports from teens about specified categories of potentially harmful content.

An independent auditor will be checking all of this and reporting directly to a bipartisan committee of attorneys general. Public summaries of its findings will also be published. This is the piece of the agreement that most looks like ongoing regulation rather than a one-off payment.

Payment and conditions

Meta won’t pay all the money at once. It must pay more than $12 billion, mostly in installments over the next decade, with another $5 billion dependent on changes across the wider social media industry.

Meta only has to make the conditional payments if Snap, YouTube, and TikTok adopt equivalent time limits, overnight restrictions, and age-assurance measures. Rival companies with annual profits above $10 billion must also face comparable payments to the states.

If those conditions are met, Meta will move to a 60-minute daily limit on each platform, with a maximum of two hours across its platforms, and expand the overnight restrictions from midnight–6:00 am to 10:00 pm–7:00 am.

Damning testimony in court

A 2021 internal survey found that 51% of teen Instagram users said “yes” to having a bad or harmful experience on the app within the previous seven days , according to former Meta safety engineer Arturo Béjar, who testified at the trial.

The same survey found the harmful content was taken down just 0.02% of the time.

Béjar said he sent the findings to Zuckerberg but didn’t get a response, and testified that the company operated a “don’t ask, don’t tell” strategy toward the safety of children on its platforms.

Other legal woes for Meta

This lawsuit isn’t the first that Meta has dealt with out of court. In May it settled a case brought by a Kentucky school district that accused social media platforms of creating a mental health crisis in its schools. Snap, YouTube, and TikTok had already settled the case, which was seen as a test for a much larger group of lawsuits—what’s called a “bellwether case”.

Meta has fared poorly in the cases that have reached a verdict. In March, Meta and Google lost another bellwether case in Los Angeles, brought by a 20-year-old user who accused it them of creating an addictive product that affected her mental health from an early age.

Meta also lost a recent child safety case in New Mexico, resulting in almost $942 million in penalties after the judge accused it of creating “a public nuisance” with its platform design.

This settlement doesn’t end Meta’s legal problems. There are roughly 3,000 addiction lawsuits against Meta, Google, TikTok, and Snap currently underway.  More than 1,000 school districts also have cases pending.

And the law doesn’t seem to be on its side. In early August, the US Court of Appeals for the Ninth Circuit ruled that Section 230 offers “a defense against liability,” rather than immunity from being sued in the first place .

Advice for parents right now

In January, the American Academy of Pediatrics issued a policy statement arguing that parents shouldn’t have to govern their kids’ welfare in a digital world by relying on screen time limits alone. Tech companies and governments should focus on healthy platform design themselves, it added.

This settlement seems to take a step toward that, although it took 51 attorneys general and a federal trial to get Meta there.

Big tech companies have repeatedly shown that parents cannot rely on them to put children’s interests first. With this in mind, read the Malwarebytes research and guide to keeping your kids safe online.


From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Popular school apps may be sharing student data with advertisers

A two-year investigation into educational technology (EdTech) apps used by Utah schools found that many were collecting and sharing student data in ways that appeared inconsistent with their privacy commitments.

EdTech is a massive commercial industry and some argue that it functions much like traditional big tech by prioritizing profits, scalable software, and user data collection over proven learning outcomes.

The project, published by the Utah State Board of Education in partnership with Brigham Young University and Internet Safety Labs, examined network traffic from 100 EdTech apps between 2023 and 2025. Rather than relying only on privacy policies or vendor assurances, researchers looked at what the apps actually transmitted while in use.

What they found was concerning. Of the 85 tested apps with relevant data privacy agreements, 52% reportedly collected at least one student-data element that was not permitted under the agreement. Across all the apps tested, researchers found that 61% shared data with third parties, while 36% transmitted data to advertisers.

A school district may have a signed data privacy agreement with an EdTech provider specifying what information the company can collect, why it can use it, and who it may share it with. But contractual promises are not always reflected in how an app behaves. An app can include third-party analytics software, advertising-related services, or other embedded components that send information elsewhere without the school or district having a clear view of those transfers.

This shows how technical testing, including examination of live network traffic, can reveal behavior that paper-based assessments miss. The report concluded that such investigations could expose potential non-compliance not be found through traditional review processes.

The state’s response extended beyond publishing the findings. Vendors with potential issues were asked to explain or remedy them. Companies that addressed concerns could have their identities redacted in the public report, an approach designed to encourage corrective action while holding vendors that failed to respond to account.

Following the investigation, Utah passed H.B. 55, Privacy Compliance for Education Technology Vendors (2026), which took effect on July 1. It amends Utah Code § 53E-9-309. Among other changes, the law requires education entities to include specified student-data protections in vendor contracts, notify vendors of unauthorized use of student data, and terminate contracts when a vendor does not remedy a confirmed privacy violation after being notified.

Since we don’t all live in Utah, the more important question for every school system is: How are your apps behaving?

Protecting student data requires more than trusting a privacy policy. Schools need accurate inventories of the tools in use, clear contractual limits, and access to the technical expertise needed to test whether those limits are being observed.


By the way, did you know about the Malwarebytes Student Protection program?

ChatGPT for Teens tackles risky chats and homework shortcuts

OpenAI has addressed complaints around teens’ use of its ChatGPT system by introducing ChatGPT for Teens, a version of the AI assistant designed specifically for users aged 13 to 17. But will it prevent determined kids from bucking the system?

It brings together several protections OpenAI has introduced over the past year, along with new features intended to encourage healthier and safer use.

What ChatGPT for Teens does

The system brings together various protections that OpenAI has built into ChatGPT over the last year into a more unified experience. For example, last September it added parental controls that enabled parents to set Quiet Hours, when kids couldn’t use the chat system, and turn off memory so it won’t use previous conversations when responding. It also built a notification system to warn parents if chats with teens took a bad turn. ChatGPT for Teens adds extra notifications for parents around eating disorders.

Study Mode, one of the main features, is designed to stop teens simply using ChatGPT to do their homework for them. Instead of giving direct, easy answers, it uses guiding questions and step-by-step prompts to encourage them to think through the problem themselves. OpenAI introduced Study Mode in July 2025.

What is new is the ability to set specific hours for Study Mode, along with responsible homework reminders. The system will spot when a teen appears to be using AI answers to shortcut an assignment and redirect them towards Study Mode.

OpenAI also says ChatGPT won’t use romantic language or encourage emotional dependence, and neither will it pretend to have feelings or to be conscious. It is introducing reminders not to upload sensitive images, and there will be an onboarding user interface for teens.

The record that forced the changes

That all seems positive, if long overdue. The parents of 16-year-old Adam Raine filed a lawsuit claiming that ChatGPT walked their son through suicide methods and offered to draft his goodbye letter before he took his own life.

Families in Tumbler Ridge, British Columbia, sued OpenAI in April this year after a school shooting there. The teenage shooter had allegedly held extensive gun-violence conversations with ChatGPT after reopening a banned account. In a controlled test where researchers posed as 13-year-old boys planning attacks, ChatGPT offered help 61% of the time, including specific advice on which shrapnel would be most lethal in a synagogue attack.

The lawsuits are stacking up. Florida Attorney General James Uthmeier sued OpenAI in June 2026, alleging that the company knowingly released an unsafe product.

The gap the launch does not close

Our Head of Consumer, Mark Beare, says ChatGPT for Teens is a positive step, but parents need to understand where the controls begin and end.

“[This is] directionally a good move, and more proactive than most social platforms were at a comparable stage. There is a clear adjacency to the parental controls space here. The controls are useful, but only when a parent configures them correctly, and only on a linked account.

“This is a bigger deal when you factor in how tech-savvy kids of this age are. The default teen protections lean on age prediction, and the stronger parent-set controls like Quiet Hours and safety notifications only apply once accounts are linked. Kids in this band are smart and tech-savvy, and they will look for the seams.”

The simplest loophole is an account that isn’t linked to a parent. OpenAI’s age-prediction system may still identify the user as under 18 and apply teen protections automatically, but parent-set controls such as Quiet Hours and parental safety notifications only work once the accounts are linked.

Last November, testers from the Family Online Safety Institute concluded that account protections in ChatGPT were “optional, easy to bypass, and inconsistent in blocking harmful content.”

Since then, OpenAI has rolled out age prediction on ChatGPT, which will check a user’s behavior to try and guess whether they are under 18. It will then move them to a ChatGPT for Teens account.

Adults will be able to present proof of their identity if they think they have been incorrectly categorized.

Beare says that still leaves parents with something to think about:

“Age verification exists as a backstop, but it runs on ID and selfie checks that carry their own privacy questions, and a teen who confirms as an adult moves out of teen mode entirely.”

As OpenAI acknowledged in its parental controls announcement, “guardrails help, but they’re not foolproof and can be bypassed if someone is intentionally trying to get around them.”

Safeguards around what content ChatGPT delivers to teens are also unlikely to be foolproof. OpenAI has admitted that its safety guardrails become less reliable the longer a conversation runs and says it is working to improve them.

What parents can do

By all means use ChatGPT for Teens as an assistive technology in a broader effort to protect your kids. Link their account to yours and set the Quiet Hours schedule. You can also set Study Mode as the default for new conversations to encourage children to use it responsibly. Make it your job to understand what the alerts do and don’t cover.

But be aware that parental controls need configuring and only apply while the parent and teen accounts are linked.

Most importantly, keep talking to your kids about how they use AI and what they use it for. No parental-control system can cover every account, conversation, or AI service they might encounter.


From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Trusting your kids online isn’t enough (Lock and Code S07E14)

This week on the Lock and Code podcast…

There is a lot going on right now regarding the safety of kids online.

In the United States, the majority of state legislatures have passed age verification laws requiring a variety of websites to more rigorously verify the age of their visitors. In the United Kingdom, Canada, Norway, Spain, and Germany, lawmakers are considering bans on social media access for anyone under the age of 16—Australia passed its ban in 2025. In schools across the world, smartphones have been removed from classrooms, hallways, and cafeterias. And online, some of the most popular apps and video games with children, such as Discord and Roblox, have implemented default restrictions on what young users can find and who they reach.

But all this activity comes after rising crises at home, as an increasing number of behavioral researchers connect increased social media use with increased rates of depression, isolation, and suicidal thoughts. So, until real, societal change takes place, what is a concerned parent to do?

That’s what we’re trying to answer today.

Today, on the Lock and Code podcast with host David Ruiz, we bring back Anna Brading, editor-in-chief of Malwarebytes Labs and director of content and, perhaps most importantly, mother of three. With a long career in cybersecurity—and an equally long time spent reading, writing, and assigning some of the cybersecurity world’s most pressing headlines—Brading has a unique perspective on what is most dangerous to her children online.

Brading’s list of priorities is long, and includes improper image use, “online nastiness,” and Roblox, but she has a few rules and guidelines to help. She sets a one-hour-a-day video game limit on the weekends, restricts YouTube to a communal and monitored activity, and requests that no one share photos of her children online without her express permission. Importantly, she also reminds parents to trust their guts.

“If the norm now is mental health issues or online grooming or non-consensual porn or constant comparison, then I’m okay without my kids fitting in. I would say be radical, buck the trend, don’t do what everybody else is doing. Say no to things you don’t feel comfortable with.”

Tune in today to listen to the full conversation.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)


Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.

Roblox developers are losing entire games to malware attacks

Account theft usually ends with someone losing a password. This one ends with hackers walking off with the entire game.

Developers behind some of Roblox’s millions of games told 404 Media that attackers persuaded them to run a single file. Then they watched their group, their game, and their Robux (in-platform currency) balance vanish into someone else’s account within hours. In several cases, Roblox support didn’t help them get the games back until a reporter called the company for comment.

From beaming to hostile takeover

Roblox attacks used to be opportunistic. “Beamers” targeted individual players to steal rare hats, limited items, and accounts, then resold them. The pattern has shifted. The new targets are developer accounts, and the prize is the game itself.

Ioannis Matziaris told 404 Media that his two 20-year-old sons spent five years building a Roblox game called The Shadow Network. In April, attackers approached one of them with a job offer and convinced him to run a particular file. It was malware. The attackers stole control of the game, the group’s Roblox account, and their Robux balance.

Another developer, Jovan Rai, received the same project-manager job pitch. This time, the attackers were impersonating Cheesy Studios, the Matziaris brothers’ company, to lend the offer credibility. The 15-year-old was earning roughly 10,000 Robux (around $38) per day from his game. He spent more than 30 days trying to recover it through Roblox support before media attention helped move the case forward.

The malware behind the theft

Developer Mohamed Kaparoza described how the attack worked. Attackers contacted him on Discord, dangled a project-manager role, and asked him to install a Python package called “robase,” which they claimed was a database tool. Shortly after installing it, he was logged out of Roblox on both his PC and his phone. His Discord account went with it, and his two-step verification settings and passkey were changed.

This is a case of session-token theft, rather than credential theft. Once an infostealer steals an authenticated browser session, attackers can often bypass security measures such as two-factor authentication (2FA) because they are reusing a session that has already been authenticated.

The technique itself isn’t new. We reported on a similar campaign in January 2025 that targeted Roblox players with offers to beta test new games. The “installer” was actually an infostealer designed to steal data, including Discord and Steam sessions, and cryptocurrency wallet information.

What developers can do

If you build Roblox games, the defensive advice is unglamorous and mostly behavioral.

  • Treat unsolicited Discord job offers with caution. If a stranger asks you to install a “database tool,” a custom installer, or any file at all, do not run it.
  • Developers who need to test unfamiliar software should do so in an isolated environment, such as a virtual machine, rather than on a device where they are signed in to Roblox, Discord, GitHub, or other important accounts.
  • Review active Roblox sessions and signed-in devices regularly, and switch on Roblox’s Enhanced Protection features where available. They won’t stop session-stealer malware, but they can help protect against many other forms of account compromise.
  • If the worst happens, document everything as early as possible. Keep records of messages, screenshots, account changes, and support requests to help with any recovery process.
  • Use security software with real-time protection. Malwarebytes Premium can detect and block infostealers and other malware before they compromise your accounts.

We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Children’s phones must block nude images by September, UK says

Build something that doesn’t exist. Don’t collect any data while you do it. Get it wrong and the CEO could face criminal charges. That’s close to the ultimatum the UK government handed Apple and Google on June 8. The two companies have three months to introduce device-level protections blocking nudity across every smartphone and tablet sold in the UK. If they don’t, the government will legislate—including fines and, as a last resort, criminal liability for tech bosses.

Prime Minister Keir Starmer announced the move at London Tech Week, telling the firms:

“If they choose not to, then we will act and change the law.”

The policy reads cleanly. The execution doesn’t.

What’s already on your child’s phone, and what isn’t

Both companies already do something to prevent children interacting with nudes. Apple’s Communication Safety feature warns children with a Child Account when they send or receive images and videos containing nudity across Messages, AirDrop, FaceTime, and other apps. It updated the feature with new functionality at its Worldwide Developer Conference (WWDC) this week.

Google’s Sensitive Content Warnings blur sensitive imagery in Google Messages for supervised users and signed-in unsupervised teens—though the feature covers images only, not video.

Apple will soon require people to confirm that they are over 18 in the UK and some other countries to access certain features on their phones. That will involve age assurance through government ID, payment information, or other verification methods depending on region.

These measures aren’t enough, according to the UK government. It complains that existing nudity detection isn’t applied to the camera or other apps, third-party messaging services, or search functions. So in other words, the protections miss most of the phone. The camera, WhatsApp, Signal, Safari, and the photo library all sit outside the protective bubble parents may assume already exists.

Is privacy-respecting scanning possible?

The announcement also contains a line that’s hard to reconcile with the rest of it:

“Companies must introduce these measures without threatening privacy or collecting any data.”

Adults can opt out, but only by completing age verification.

That’s a tall order. Privacy advocates argue that age verification inevitably creates new data collection risks, even when companies try to minimize the information they store. Whatever Apple and Google build, some form of record-keeping seems likely. If executives can face personal liability for non-compliance, someone has to be able to demonstrate what the system did and when.

The government’s proof that any of this is achievable rests on a single product: SafeToNet’s HarmBlock, which the Home Office calls “a proven example” of safe-by-default device protection. HarmBlock’s source code (which isn’t public) analyzes images and live streams entirely on-device.

Digital privacy groups were not happy with the announcement. Big Brother Watch pointed out that children could easily access adult-registered devices, and warned that mandatory ID checks for adults would mean “the death of anonymity and internet privacy.”

Private messaging app Signal said promises the scanning would run only on-device were “cold comfort” because wherever the system runs, its reach would ultimately be determined by government, not technology:

“Its scope will be defined by the whims and proscriptions of the government to detect nudity today and political speech tomorrow.”

Apple has been here before. In 2021, it announced a separate plan to detect known child sexual abuse imagery on devices by matching image hashes against a database of known material, and quietly shelved it after sustained backlash from privacy advocates.

What families can do today

September will end in voluntary compliance or hurried legislation. Either way, none of that changes what’s on your child’s phone right now. Today, the messaging channels most heavily used by teenagers aren’t protected. Many grooming and sextortion cases begin on apps that operate outside the operating system’s built-in safety features. Parents and kids can take extra steps for protection:

  • Turn on Communication Safety on iPhones with a Child Account, and Sensitive Content Warnings on supervised Android Messages. They might only blunt the problem at one narrow point, but it’s better than nothing.
  • Talk to your kids about coerced sharing. The Internet Watch Foundation reported that 91% of reports it assessed in 2024 contained self-generated content submitted by children themselves. Children are often coerced into sending explicit material to abusers online. The Internet Watch Foundation has a list of resources for people who are being coerced into sending intimate images online.
  • Cover the basics that outlive any policy: put unique passwords on all accounts, and add multi-factor authentication.
  • Be careful when sharing images of children you know online. Increasingly, criminals can use non-explicit images to create sexual content using AI that can in turn be used for extortion.

CNET Editors' Choice Award 2026

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review


TikTok, YouTube, and Roblox face scrutiny, but age gates won’t fix child safety

A damaging new report from Ofcom, the UK’s communications regulator, has delivered a stark verdict: TikTok and YouTube’s content feeds are “not safe enough” for children. This isn’t just another regulatory slap on the wrist. Ofcom is putting out a wake-up call for anyone working in cybersecurity, threat intelligence, and online safety.

In its own words:

“Notably, TikTok and YouTube failed to commit to any significant changes to reduce harmful content being served to children, maintaining their feeds are already safe for children.”

On the positive side, Snap, Meta, and Roblox agreed to adopt further safety measures to protect children from online grooming and “stranger danger.”

The BBC reports that an Ofcom survey found 84% of children aged 8 to 12 were still using at least one major service with a minimum age of 13. We reported earlier about how easy it was to fool some of the age verification methods. Researchers using under-13 accounts also reported encountering sexual content and offensive language shortly after entering specific Roblox games.

Speaking of Roblox, The Guardian reports that US advocacy groups have formally requested the Federal Trade Commission (FTC) investigate Roblox for what they call “unfair and deceptive” practices. The complaint focuses on:

  • In-game purchases pressuring children to spend money
  • Chat functionality exposing children to strangers
  • Features designed to maximize engagement, which critics argue may be addictive

Drew Benvie, CEO of Battenhall and founder of youth safety nonprofit Raise, noted:

 “Although Roblox is implementing new age-based safety measures, young players are adept at circumventing these protections.”

The cybersecurity point of view

What keeps cybersecurity researchers up at night is another angle to this problem. Many proposed age assurance solutions require users to hand over government IDs or biometric selfie data. We already talked about this in our blog, Age verification: Child protection or privacy risk?

Age verification systems create massive data collection opportunities that become prime targets for:

  • Data breaches exposing sensitive personally identifiable information (PII)
  • Identity theft facilitated by centralized ID databases
  • Biometric data theft, which cannot be changed like passwords
  • Malware and scams targeting users on less-secure platforms

When restrictions push young users toward smaller or less secure sites, they encounter:

  • No basic safety protections
  • Higher exposure to malware
  • Increased phishing and scam risks
  • Unmoderated harmful content

This is exactly what we see in threat intelligence: As defenders secure one vector, cybercriminals adapt and move elsewhere.

Safer systems beat stricter age gates

Protecting children should focus on building safer digital experiences overall. This is the only viable path forward because:

  • Stronger moderation actually removes harmful content rather than just blocking access
  • Safer recommendation systems prevent algorithmic amplification of harmful content
  • Better platform accountability means companies can’t prioritize engagement over safety
  • Avoiding invasive data collection prevents creating massive honeypots for attackers

As someone who analyzes malware and threats daily, I can tell you: security through obscurity (age gates) doesn’t work. Security through robust system design (moderation, safer algorithms, accountability) does.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Rental platform unnecessarily collected the data of millions of Australians, privacy commissioner finds

2Apply’s over-collection of personal information adds to the power of the real estate industry in the competitive rental market, Carly Kind says

An online rental platform has been urged to stop collecting users’ personal information after the Australian privacy commissioner found the gathering of “excessive” data compounded the vulnerability of tenants amid the housing crisis.

RentTech platforms are increasingly used by real estate agents in Australia for people applying for rental properties to submit applications and supporting documentation. The Australian Housing and Urban Research Institute has identified 57 different rent platforms operating in Australia.

Continue reading...

© Photograph: Cavan Images/Alamy

© Photograph: Cavan Images/Alamy

© Photograph: Cavan Images/Alamy

A Victorian schoolteacher was applying for ‘heaps of rentals’ online – then someone accessed his bank account

Michael suspects personal information he submitted to rent application platforms was leaked online. And analysis shows millions of documents may also be at risk

Michael* has spent the past two months trying to get his digital identity back.

The 47-year-old Victorian schoolteacher was in the process of moving to a new town and applying for rental properties online. Around this time – and unbeknown to him – his mobile phone number was transferred to someone else.

Continue reading...

© Composite: Getty Images

© Composite: Getty Images

© Composite: Getty Images

❌