Visualização normal

Antes de ontemSecurity Affairs
  • ✇Security Affairs
  • Trump Targets Foreign Technology in New U.S. Power Grid Security Order Pierluigi Paganini
    Trump targets foreign-made power grid equipment, citing cyber, sabotage and supply-chain risks to U.S. national security. Executive Order 14420, signed on August 26, targets equipment and technologies that could expose the power grid to sabotage, unauthorized access, malicious remote activity or supply-chain disruption. The timing matters. The White House points to the rapid expansion of data centers, artificial intelligence, advanced manufacturing and defense production as reasons why th
     

Trump Targets Foreign Technology in New U.S. Power Grid Security Order

28 de Agosto de 2026, 15:00

Trump targets foreign-made power grid equipment, citing cyber, sabotage and supply-chain risks to U.S. national security.

Executive Order 14420, signed on August 26, targets equipment and technologies that could expose the power grid to sabotage, unauthorized access, malicious remote activity or supply-chain disruption.

The timing matters. The White House points to the rapid expansion of data centers, artificial intelligence, advanced manufacturing and defense production as reasons why the United States now depends even more heavily on reliable electricity. A disruption that might once have been treated primarily as an energy problem can now affect defense operations, critical infrastructure, emergency services and large parts of the economy.

The order frames the problem in two ways. Foreign-made equipment can introduce a direct cybersecurity risk, including the possibility of hidden digital access mechanisms, while dependence on overseas suppliers can create a second vulnerability if geopolitical tensions or trade disruptions suddenly cut off critical components.

The White House’s language is unusually broad when describing the scope of the concern.

“NOW, THEREFORE, I, DONALD J. TRUMP, President of the United States of America, find that the situation with respect to the foreign supply of bulk-power system electric equipment constitutes an unusual and extraordinary threat, which has its source in whole or substantial part outside the United States, to the national security, foreign policy, and economy of the United States and hereby declare a national emergency with respect to that threat.” reads the Executive Order 14420. “This threat exists both in the case of individual transactions and when transactions are considered as a class. To deal with this threat, additional steps are required to protect the security, integrity, and reliability of bulk-power system electric equipment used in the United States.”

That definition matters because the order isn’t aimed only at a specific piece of hardware from a specific country. It creates a framework under which the Energy Secretary can determine whether particular foreign entities, suppliers, countries or equipment present an unacceptable risk and then restrict transactions involving them.

The restrictions apply to the acquisition, importation, transfer or installation of foreign-produced bulk-power equipment when the relevant transaction involves a designated Covered Foreign Entity and meets one of the risk conditions set out in the order. Those conditions include the possibility of sabotage, subversion, unauthorized access, malicious remote action or disruption of the power system and its supply chain.

The order also reaches beyond the physical equipment itself. Its scope includes critical components, software, firmware, digital services, maintenance services and remote-access capabilities associated with covered equipment.

“the transaction involves bulk-power system electric equipment — or any critical component, software, firmware, digital service, maintenance service, or remote-access capability associated with such equipment — designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of a Covered Foreign Entity; and” continues the order.

In practical terms, the government isn’t treating a transformer, an industrial controller and the software that manages it as completely separate security questions.

That is particularly relevant to industrial control systems. The definition of covered equipment includes remote terminal units, programmable logic controllers, intelligent electronic devices, distributed control systems and safety instrumented systems, alongside transformers, generators, inverters, battery storage systems, protective relays, metering equipment and high-voltage circuit breakers. The order also allows agencies to consider software, firmware, remote access, update mechanisms and other supply-chain dependencies when deciding whether equipment falls within its security concerns.

The geographical scope is also worth noting. The order defines the bulk-power system around interconnected transmission infrastructure and generation resources needed for grid reliability, including transmission lines rated at 69 kV or higher. Local electricity distribution facilities fall outside that definition.

This isn’t only about equipment that companies might buy tomorrow. The Energy Secretary can also impose conditions on foreign-manufactured or foreign-operated equipment already installed before the order took effect. Depending on the risk, those measures could require operators to identify, isolate, monitor, secure, disconnect, replace or remove equipment. The order specifically requires officials to consider reliability, safety, the availability of secure replacements and continuity of essential services before demanding isolation or replacement.

That last point is important because securing a power grid isn’t as simple as unplugging a suspicious device. Removing a component without a suitable replacement can itself create an operational problem. The order therefore leaves room for phased compliance and negotiated mitigation measures rather than assuming that every risky component can disappear overnight.

The government also wants to avoid turning security screening into a permanent procurement bottleneck. The Energy Secretary can establish criteria for pre-qualified equipment and vendors, creating a list of products and suppliers that can receive exemptions from the baseline restrictions. At the same time, the order makes clear that pre-qualification doesn’t prevent the government from scrutinizing or restricting a transaction later if circumstances warrant it.

The order doesn’t name a specific country as the target. Instead, it defines a Covered Foreign Entity broadly enough to include governments under certain U.S. arms embargoes or sanctions regimes, as well as entities that the relevant U.S. authorities determine are engaged in conduct detrimental to national security or foreign policy. SecurityWeek also noted that the structure resembles earlier Trump-era restrictions on foreign bulk-power equipment, including measures that previously focused on entities associated with China.

The order does not mention any country by name. However, its structure is very similar to a 2020 Trump-era order on the U.S. power grid, which later led the Department of Energy to ban companies linked to China.

The next phase will be regulatory rather than rhetorical. Within 120 days, the Energy Secretary is expected to issue rules or regulations needed to implement the order, including procedures for identifying covered entities, equipment and countries and for licensing transactions that would otherwise be prohibited. The administration also wants recommendations for changes to federal procurement rules that would give greater weight to national security risks and favor U.S.-manufactured energy infrastructure.

Those procurement changes have their own timetable. The Energy Secretary has 180 days to develop recommendations for revisions to the Federal Acquisition Regulation, while the FAR Council would then have 90 days to consider proposing corresponding amendments for public comment.

The policy fits into a wider push by the administration to reduce dependence on foreign supply chains for strategically important infrastructure. The Department of Energy said earlier this month that it is working to increase domestic production and availability of critical grid components, pointing to rapid growth in electricity demand and the need to strengthen the grid supply chain.

For cybersecurity professionals, however, the most interesting part of the order isn’t the preference for domestic manufacturing. It’s the decision to treat supply-chain exposure, remote access and embedded technology as part of the attack surface of the power grid.

That changes the question organizations need to ask about critical equipment. It’s no longer enough to know whether a device has a vulnerability today; operators also need to understand who made it, who controls the supplier, where critical software and firmware come from, who can remotely access the equipment, how updates reach it and what happens if that supply chain suddenly becomes unavailable.

The uncomfortable reality is that a power grid compromise doesn’t necessarily begin with someone breaking through the perimeter of a utility network. It can begin much earlier, when an organization buys a component it can’t fully inspect, relies on a remote maintenance channel it doesn’t control, or becomes dependent on a supplier it can’t replace quickly.

That’s the security problem Executive Order 14420 is trying to address. The White House has effectively moved part of the grid’s cyber defense line back into procurement, manufacturing and supply-chain decisions. And for critical infrastructure operators, that’s a much harder problem to solve than simply finding another firewall.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, power grid)

  • ✇Security Affairs
  • Meta to Pay Up to $18B Over Teen Social Media Use Pierluigi Paganini
    Meta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety. Meta will pay up to $18 billion over the next decade and impose real usage limits on teenagers using Facebook and Instagram, settling claims that the company deliberately designed its platforms to addict children. The deal ended a federal trial mid-stream, right as Instagram head Adam Mosseri had begun testifying and Mark Zuckerberg was expected to take the s
     

Meta to Pay Up to $18B Over Teen Social Media Use

27 de Agosto de 2026, 05:15

Meta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety.

Meta will pay up to $18 billion over the next decade and impose real usage limits on teenagers using Facebook and Instagram, settling claims that the company deliberately designed its platforms to addict children. The deal ended a federal trial mid-stream, right as Instagram head Adam Mosseri had begun testifying and Mark Zuckerberg was expected to take the stand next.

The timing made sense given the huge potential penalties. Four states, California, Colorado, Kentucky, and New Jersey, were seeking up to $200 billion in damages. Before the trial, Meta said they could demand as much as $1.4 trillion. Against those figures, the $18 billion settlement looks relatively small, although it still equals about three to four months of Meta’s profits.

The most important part of the deal is what Meta agreed to change. Teenagers will be limited to two hours a day on Facebook and Instagram. Meta will also block access between midnight and 6 a.m. unless a parent gives permission, and it will turn off most push notifications during school hours.

“The focus of this case was to protect our kids,” Colorado Attorney General Phil Weiser said in a statement reported by Reuters. “The relief we are getting in this settlement is very meaningful and well beyond what any court has ordered or is likely to order.””

What the settlement leaves unchanged matters too. Meta does not have to stop using personalized recommendations or targeted ads for teenagers. It also does not have to remove specific types of content that researchers have linked to negative effects, such as posts that can make users feel worse about their bodies. A two-hour limit is still a meaningful restriction, but Meta can continue trying to maximize engagement during those two hours.

The deal also creates an interesting financial incentive. Of the roughly $16.7 billion going to 47 states, Washington D.C., Puerto Rico and other territories, about $12.7 billion is guaranteed. The remaining $5 billion depends on whether Snapchat, TikTok and YouTube introduce similar protections for teenagers. This gives Meta a financial reason to push its competitors to adopt the same rules, which is why the company reportedly plans to use newspaper ads to encourage TikTok and YouTube to follow suit.

Separately, Wednesday’s settlement also resolved lingering state privacy claims tied to the Cambridge Analytica scandal, with Meta agreeing to pay $459 million on top of everything else. That’s an old wound getting stitched up alongside a much newer one, in the same afternoon.

Not every state joined the settlement. New Mexico stayed out after winning a $567 million public nuisance ruling against Meta earlier this month, on top of a separate $375 million jury verdict. Attorney General Raul Torrez said the settlement didn’t include some changes his case had pushed for, including stronger protection against adults targeting children and a ban on sexualized AI chatbot interactions with minors. Still, he called the deal a step forward.

Florida rejected the settlement altogether. Attorney General James Uthmeier said the payouts amount to “peanuts” compared with the harm caused and said Florida would take Meta to trial instead.

Legal experts already see the settlement as a possible model for future cases. Northwestern law professor James Speta said Meta and other tech companies faced growing pressure to change anyway, from Congress, state lawmakers and the public. That makes the settlement more than a single case: it could set a standard that courts and regulators use when judging other platforms.

Thousands of similar lawsuits from individuals, school districts and municipalities are still moving through courts across the U.S. If those cases follow the same pattern, we haven’t seen the last of these headlines.

“Today, we are announcing an agreement with a bipartisan group of 52 attorneys general across US states, territories, and the District of Columbia, building on our longstanding efforts to empower parents and support teens.” reads the statement published by Meta.

“Over the years, we have consistently partnered with parents and experts — listening, learning, and building. That’s why we launched Teen Accounts in 2024, to bring automatic protections to teens, and more control for parents.”

The agreement aims to push YouTube, TikTok and other platforms to adopt similar protections for teenagers.

“While this is an important step, the fact is that teens move fluidly between dozens of apps a day. All platforms should empower parents and support teens by putting the same measures in place, because we know that when teens are restricted on one app, they simply move to another.” concludes Meta. “For meaningful progress to happen, we urge TikTok and YouTube to join us and state attorneys general in adopting this new standard, to ensure teens use social media in a healthy and responsible way.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Facebook)

  • ✇Security Affairs
  • When the Algorithm Fires You: Uber Faces €825M Fine Pierluigi Paganini
    Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over Uber’s use of fully automated software to suspend driver accounts, sometimes permanently, with no human ever reviewing whether the sys
     

When the Algorithm Fires You: Uber Faces €825M Fine

25 de Agosto de 2026, 14:02

Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers.

The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over Uber’s use of fully automated software to suspend driver accounts, sometimes permanently, with no human ever reviewing whether the system got it right.

The violation is clear under EU law. The GDPR limits fully automated decisions when they can significantly affect a person’s life. An algorithm that can take away someone’s ability to earn a living, without any human review, falls directly into this category. The regulator also found that Uber failed to properly tell drivers when automated systems made these decisions, which the GDPR requires companies to disclose.

“The Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, imposes a fine of 824,990,000 euros on Uber. The reason for this is that the AP has ruled that Uber made fully automated decisions about drivers. In case of suspicions of fraud or customer reviews that were too low, drivers’ accounts were automatically temporarily deactivated or, in case of persistent low customer reviews, permanently deactivated. As a result, their income was lost via Uber during the deactivation.” reads the statement published by the Dutch data protection authority. “According to the AP, Uber has violated the prohibition of fully automated decision-making under the General Data Protection Regulation (GDPR). The AP also found that Uber did not sufficiently inform drivers about automatic decision-making. Uber has now stopped the violations.”

The fine covers Uber’s practices from 2018 to 2022, so it concerns systems the company has already discontinued. Uber highlighted this point in its response, arguing that the regulator examined old policies rather than practices still in use today.

“Uber used software to track drivers’ (driving) behaviour and to track customer reviews. If that software detected a suspicion of fraud or customer reviews were too low, the accounts of the drivers concerned were automatically deactivated.” continues the Dutch authority. “There was no human assessment here. This occurred between 2018 and 2022.”

Uber also said it takes decisions that affect drivers’ income seriously. The company pointed to human reviews, safeguards and an appeals process for drivers who believe the system made a mistake. The appeal will have to determine whether these protections existed during the period covered by the fine or came later.

And Uber is appealing. The company has stated it disagrees with both the decision and the size of the fine, setting up another round in what’s become a recurring pattern between Uber and Dutch regulators specifically.

This is the fourth time the Dutch authority has fined Uber, which on its own says something about the relationship here. The previous record holder was a 290 million euro fine in 2024 over transferring European drivers’ personal data to the US without adequate protections, a case Uber also appealed at the time. Four fines from a single regulator isn’t really a pattern of bad luck anymore; it’s a pattern of a company and a privacy regulator that keep disagreeing about the same basic question, how much human judgment has to sit between an algorithm’s decision and a person’s actual income.

The case goes beyond Uber. Many gig-economy platforms in Europe use algorithms to manage workers, routes and account status. This ruling shows the cost of relying on automated decisions without human oversight. For companies that use algorithms to make decisions affecting people’s accounts or income, saying “the algorithm decided” is no longer enough. The €825 million fine makes that lesson very clear.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

  • ✇Security Affairs
  • TikTok Settles U.S. Child Privacy Case for $400 Million Pierluigi Paganini
    TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy. “Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities (TikTok) resolving litigation concerning compliance with the Children’s Online Privacy Protection Act and its implementing
     

TikTok Settles U.S. Child Privacy Case for $400 Million

24 de Agosto de 2026, 04:23

TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13.

The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy.

“Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities (TikTok) resolving litigation concerning compliance with the Children’s Online Privacy Protection Act and its implementing regulations (COPPA).” reads the press release published by DoJ. “Under the settlement, TikTok will pay $300 million immediately and an additional $100 million upon entry of an order vacating a prior consent decree entered against TikTok’s predecessor, Musical.ly. The settlement represents one of the largest recoveries ever obtained in a COPPA case.”

TikTok will pay $300 million immediately and another $100 million after a court order removes an earlier consent decree involving Musical.ly. The 2024 case, brought by the DoJ and FTC, accused TikTok of knowingly allowing children under 13 to create accounts and illegally collecting data from children using Kids Mode.

Since the Justice Department filed its lawsuit against TikTok in 2024, the company has made major changes to its ownership, management, compliance, and privacy practices. It has also introduced stronger safeguards for younger users, improved age controls, and expanded parental oversight.

The DOJ said these measures have advanced the goals of its case and strengthened protections for millions of U.S. families. The settlement reflects a focus on practical results, securing a significant recovery while recognizing TikTok’s compliance improvements. The case was filed in California and handled by the DOJ’s Civil Division following a referral from the FTC.

“This settlement is a major victory for American children and parents,” said Associate Attorney General Stanley E. Woodward Jr. “The Department’s priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations. This resolution secures a substantial recovery while reinforcing the protections that families expect and deserve.”

TikTok has faced regulatory scrutiny over children’s privacy before. In September 2023, Ireland’s Data Protection Commission fined the company €345 million for breaching the GDPR through its handling of children’s personal data.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, privacy)

  • ✇Security Affairs
  • US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks Pierluigi Paganini
    Trump authorizes vetted US cybersecurity firms to conduct government-approved cyber operations against transnational criminal networks. President Trump signed a national security memorandum on August 13 establishing a formal program that allows vetted private US cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations under government direction and oversight. The program, managed by the National Coordination Center, covers both intelligence c
     

US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks

14 de Agosto de 2026, 04:14

Trump authorizes vetted US cybersecurity firms to conduct government-approved cyber operations against transnational criminal networks.

President Trump signed a national security memorandum on August 13 establishing a formal program that allows vetted private US cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations under government direction and oversight. The program, managed by the National Coordination Center, covers both intelligence collection, described as Cyber Surveillance Operations, and active disruption of criminal infrastructure, described as Cyber Effects Operations. It’s the formal implementation of what the White House’s Cyber Strategy for America promised in March: unleashing the private sector as an offensive cyber instrument.

“The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States. Yet, American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace. Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime.” states the memorandum.

“By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.”

The program targets what the memo defines as Cyber-Enabled Transnational Criminal Organizations, any foreign group conducting cyber-enabled crime against US interests, explicitly excluding entities that are institutional parts of foreign governments or wholly operated under foreign government direction. That carve-out matters: this program is aimed at criminal networks, not nation-state adversaries. The line between the two is often blurry in practice, but the memo establishes the presumption that a group is not government-directed unless clear intelligence says otherwise.

““Cyber Effects Operation” means activity conducted in or through the interdependent network of information technology infrastructure that includes the Internet, telecommunications networks, computers, information systems, industrial control systems, networks, and embedded processors and controllers that results in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon.” continues the memorandum.

Program executive directors from the Department of Justice and the Department of Homeland Security must co-approve every operation in writing before any action is taken. Operations that could produce those Critical Outcomes require additional authorization beyond the program executive directors, an explicit acknowledgment that some cyber actions cross into territory governed by the laws of armed conflict.

Companies wanting to participate must clear rigorous vetting, demonstrate technical capability, submit to annual evaluations, and maintain a bond or escrow of at least $1 million that is forfeited if they violate their contract terms. The operational procedures are to be finalized within 60 days, and the Justice Department will review any operation that touches a US person or raises domestic constitutional questions. The legal question hovering over the whole program is whether the CFAA exemption for lawfully authorized government investigative activities extends to private companies acting under government contracts, a question no US court has yet answered. Jenner & Block lawyers noted the exemption likely applies when companies operate under direct government direction, but wouldn’t cover independent offensive operations without that oversight. That’s precisely why the memo makes government control explicit at every step: every operation needs written approval before action, every unintended contact with a US person or system must trigger an immediate stop and notification, and the Justice Department stays in the loop throughout.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Transnational Criminal Networks)

  • ✇Security Affairs
  • Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case Pierluigi Paganini
    Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M. Meta ‘s child-safety legal bill just got another half-billion dollars heavier. A New Mexico state judge ruled that company’s platforms constitute a “public nuisance,” the BBC reports, ordering $567 million into a fund meant to address harm the company caused to children. Combined with an earlier $375 million penalty from the same case, Meta now owes New Mexico $942 million
     

Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case

7 de Agosto de 2026, 08:42

Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M.

Meta ‘s child-safety legal bill just got another half-billion dollars heavier. A New Mexico state judge ruled that company’s platforms constitute a “public nuisance,” the BBC reports, ordering $567 million into a fund meant to address harm the company caused to children. Combined with an earlier $375 million penalty from the same case, Meta now owes New Mexico $942 million total.

“Judge Bryan Biedscheid said the social media giant is a “public nuisance” akin to air pollution and that it must put the money in a fund aimed at reducing future harms.Thursday’s ruling is in addition to $375m in fines Meta was already ordered to pay in the case, for a total of $942m.” BBC reports. “Judge Biedscheid compared Meta to a factory, with advertising and content as its product and “the psychological harm and sexual exploitation of children to be the pollution that must be abated”.”

Judge Bryan Biedscheid didn’t hold back on the framing. He compared Meta to a factory, with advertising and content as its output and the psychological harm and sexual exploitation of children as the pollution that output produces. It’s the kind of comparison a judge doesn’t reach for lightly, and according to CNN, it’s the first time any social media company has been legally labeled a public nuisance.

“The court found that “just as noxious pollution produced by the factory can harm the common public right to reasonably clean air, the harmful effects of Meta’s platforms on children do not stay contained by its platforms and, instead, migrate to the internet as a whole and, perhaps most concerning, to the real world and create a common, societal burden on and harm to the affected children and their families and schools, as well as hospitals and law enforcement.”” CNN reports.

The case traces back to a 2023 lawsuit from state attorneys general, and it unfolded in two phases. A March jury verdict already found Meta had repeatedly violated New Mexico’s Unfair Practices Act, largely because its recommendation algorithms steered young users toward harmful content and predatory contacts. This second phase, decided by the judge alone rather than a jury, existed specifically to answer one question: did that harm rise to the level of a public nuisance affecting the broader community.

According to CNBC’s reporting, Biedscheid’s written ruling didn’t pull punches on causation either.

“Expert testimony supports a causal link between social media and the youth mental health crisis in New Mexico,” the ruling states, closing off Meta’s usual argument that any correlation is just correlation.

Most of the money has a specific destination. $420 million goes toward direct treatment, funding clinical and behavioral health programs for young people already affected. The remainder covers prevention training for teachers and healthcare workers, plus broader awareness efforts, all running over roughly the next five years, according to PBS.

Cash isn’t the only thing Meta has to hand over. The judge ordered a list of concrete platform changes: no recommending accounts of users under 18 to adults, no adults messaging minors, a ban on sending or receiving nudity for underage accounts, and elimination of “like” counts for teen users. Push notifications get blocked overnight and during school hours on weekdays, and total monthly usage for minors gets capped at 90 hours across Instagram and Facebook combined, roughly three hours a day.

Meta’s response was predictable and brief. A company spokesperson said Meta disagrees with the ruling and will appeal, adding that the company has worked hard to keep people safe and remains confident in its record protecting teens online.

“We disagree with the ruling and will appeal.” a company spokesman told BBC. “We work hard to keep people safe on our platforms and have been transparent about the challenges of identifying and removing bad actors and harmful content,” he added.

“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”

That’s the same basic line the company used after the March verdict, and it’s likely to stay the company line through however many appeals this takes.

New Mexico is far from the only front in this fight. Nearly three dozen state attorneys general are pursuing a separate case against Meta over child privacy violations, with another major trial starting next week in California, and Meta already lost a Los Angeles case earlier this year that found it could be held liable for building deliberately addictive platforms. Add in the EU’s ongoing preliminary findings against Meta over underage users on Instagram and Facebook, and the pattern stops looking like isolated lawsuits and starts looking like a coordinated reckoning across multiple jurisdictions at once.

Former Twitter executive Bruce Daisley put the number in context on BBC Radio 4, calling it “a drop in the ocean” against Meta’s finances; the company posted $61 billion in quarterly revenue this year, up 28% from the year before. The fine is real money by any normal measure. Whether it’s real money by Meta’s measure is a different question entirely, and it’s the one regulators worldwide are now racing to answer with policy rather than just penalties.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Meta)

  • ✇Security Affairs
  • FCC Restricts New Foreign Robots and Inverters Over Security Risks Pierluigi Paganini
    The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029. The FCC just widened its Covered List again, this time adding foreign-produced advanced robotic devices and power inverters. In plain terms, that means new models in those categories generally can’t get the equipment authorization they need for import, marketing, or sale in the US, although already authorized devices can still be sold and used.
     

FCC Restricts New Foreign Robots and Inverters Over Security Risks

30 de Julho de 2026, 07:10

The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029.

The FCC just widened its Covered List again, this time adding foreign-produced advanced robotic devices and power inverters. In plain terms, that means new models in those categories generally can’t get the equipment authorization they need for import, marketing, or sale in the US, although already authorized devices can still be sold and used.

“The Federal Communications Commission’s Office of Engineering and Technology (OET) announces that certain prohibitions contained in 47 CFR §§ 2.932(b) and 2.1043(b) will not apply for now to certain foreign-produced advanced robotic devices and power inverters. All advanced robotic devices and power inverters authorized for use in the United States may continue to receive software and firmware updates that mitigate harm to U.S. consumers at least until January 1, 2029.” reads the FCC public notice. “These include all software and firmware updates to ensure the continued functionality of the devices, such as those that patch vulnerabilities and facilitate compatibility with different operating systems.”

The FCC Covered List is a registry of communications equipment and services considered potential national security or public safety risks in the United States. Created under the Secure and Trusted Communications Networks Act of 2019, it targets foreign-produced technologies that may raise concerns over espionage, cyber vulnerabilities, foreign influence, or supply-chain risks. Devices added to the list may face restrictions, including limits on FCC authorization for new products, additional approval requirements for hardware or software changes, and greater scrutiny for companies using these technologies.

That waiver matters because the FCC’s default rules would otherwise block permissive changes on covered equipment, including software and firmware updates that fix vulnerabilities or keep devices working with different operating systems. The agency is trying to avoid a stupid outcome where security updates get trapped behind a rule meant to cut off risky gear.

“OET finds that special circumstances warrant a deviation from the general rules and the public interest would be better served by waiving prohibitions on these Class I and Class II permissive changes in these circumstances.” continues the notice.

The notice is narrow, though. It only covers already authorized devices, and grantees still have to follow the rest of the FCC’s rules, including the normal requirements for Class II permissive changes, test results, minimum performance, and certification statements. So this is relief, not a free pass.

The FCC also drew a line around what counts as covered hardware. For robots, the definition is broader than just “mobile robots” and excludes connected road vehicles, rail-only equipment, uncrewed aircraft, underwater vehicles, FDA-regulated medical and mobility devices, and fixed industrial arms like SCARA, gantry, and delta systems. For inverters, the rule covers systems that convert DC to AC or the reverse and include remote communication, control, sensing, data collection, or monitoring features.

“OET believes that analogous concerns regarding the continued safe operation of existing models of UAS, UAS critical components, and routers that OET described in the prior UAS Waiver and Router Waiver also apply equally to foreign-produced power inverters and advanced robotic devices.” states FCC. “Therefore, OET concludes that waiving our prohibitions with regard to software and firmware Class I and II permissive changes that mitigate harm to U.S. consumers for Covered Power Inverters and Covered Advanced Robotic Devices through at least January 1, 2029, is warranted and in the public interest.”

The FCC’s move is preventive, not reactive. It doesn’t name a confirmed active campaign against deployed robots or inverters, but it does rely on prior security research and supply-chain concerns to justify the action. That includes cases where researchers found exposure of camera feeds, microphone audio, maps, BLE attack paths, API-driven remote control, and inverter risks tied to remote access and grid instability.

“We clarify that this waiver only applies to the prohibitions on Class I or Class II permissive changes for already-authorized devices. Grantees whose devices are subject to this waiver must still comply with other relevant FCC rules.” concludes the notice.

The agency is also making clear that this is part of a wider pattern. The action follows earlier Covered List moves on foreign-produced drones and consumer routers, so the FCC is steadily using the same national-security framework across more device classes. The message is simple: if the device can be reached, updated, or remotely controlled, the supply chain is now part of the threat model.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Covered List)

  • ✇Security Affairs
  • Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices Pierluigi Paganini
    EU fined Google €890M under the DMA for favoring its own services and restricting Play Store competition, with AI search features also under scrutiny. The European Commission hit Google with two fines totalling €890 million on Thursday for violating the Digital Markets Act, one for giving its own services preferential placement in Google Search and one for blocking app developers from directing users to cheaper alternatives outside the Play Store. These are Google’s first DMA fines, but the
     

Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices

24 de Julho de 2026, 17:47

EU fined Google €890M under the DMA for favoring its own services and restricting Play Store competition, with AI search features also under scrutiny.

The European Commission hit Google with two fines totalling €890 million on Thursday for violating the Digital Markets Act, one for giving its own services preferential placement in Google Search and one for blocking app developers from directing users to cheaper alternatives outside the Play Store. These are Google’s first DMA fines, but the fifth and sixth competition penalties against the company overall, bringing the cumulative total to €10.38 billion over nearly two decades. At this pace, Google is basically funding a small member state.

“Today, the European Commission took two decisions finding non-compliance by Google with the Digital Markets Act (DMA) for self-preferencing its own services on Google Search, and for putting in place restrictions on businesses to direct consumers to alternative, often cheaper, purchase channels on Google Play (steering).” reads the press release published by the European Commission. “In this regard, the Commission issued Google a fine of €460 million and a fine of €430 million respectively.”

The search fine covers Google’s handling of shopping, hotels, transport, and sports results, where the Commission found the company systematically promoted its own products over rivals. The Play Store fine targets steering restrictions that prevented developers from telling users they could buy the same app or subscription elsewhere for less.

Despite the scale of the penalties, the Commission signaled that ongoing daily fines for non-compliance are unlikely.

“The Commission notes that, after a constructive dialogue, Google has proposed and started testing changes to how it presents its own services on Google Search for free services such as shopping, hotels and flights.” EU continues. “The Commission will monitor the implementation of these solutions which constitute substantial progress towards compliance.”

The Commission described this as substantial progress and flagged a “constructive dialogue” with Google, which is regulatory language for “we’re not done but we’re not going to war either.”

Google has 60 days to comply with orders to treat rivals fairly and allow developers to redirect users away from the Play Store. The company rejected the findings and didn’t rule out taking the Commission to court. President of Global Affairs Kent Walker argued that complying would force Google to strip out real-time search features like hotel pricing and flight availability, and remove safety protections from the Play Store, framing the decisions as harmful to European users rather than protective of them.

“The Commission also notes that Google has proposed and started testing changes to how it presents shopping ads and content related services, such as sports.” states the press release. “The Commission is currently assessing these changes and will continue its dialogue with Google in light of today’s decision.”

That extension to AI features is the part of this decision that will matter most in the long run, as AI-generated summaries are increasingly becoming the first layer of search results that users interact with. The fines are the third under the DMA after Apple and Meta were penalized in April last year, and the U.S. government’s response was predictable.

Reuters reported that trade Representative Jamieson Greer said the actions are “driving massive uncertainty for U.S. exports.” though no specific retaliatory measures were announced.

“The two non-compliance decisions were adopted after a thorough investigation, including feedback from market participants, and extensive dialogue with Google.” concludes the press release. “When calculating the fines, the Commission has assessed the gravity, duration and recurrence of the breaches and concluded that the level of fines imposed are proportionate and appropriate.

Google may challenge today’s decisions in court.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, EU)

  • ✇Security Affairs
  • Europe Confirms Record €4.1B Penalty Against Google for Android Practices Pierluigi Paganini
    EU’s top court upheld a €4.1B fine against Google, ruling it abused Android’s market dominance through restrictive licensing practices. The Court of Justice of the European Union issued its ruling on July 2, 2026, and Google lost. The court dismissed the appeal brought by Google and its parent company Alphabet against an earlier judgment from the General Court, confirming a fine of €4,125,000,000. Alphabet is jointly and severally liable for €1,520,605,895 of that amount. The case goes ba
     

Europe Confirms Record €4.1B Penalty Against Google for Android Practices

2 de Julho de 2026, 14:29

EU’s top court upheld a €4.1B fine against Google, ruling it abused Android’s market dominance through restrictive licensing practices.

The Court of Justice of the European Union issued its ruling on July 2, 2026, and Google lost. The court dismissed the appeal brought by Google and its parent company Alphabet against an earlier judgment from the General Court, confirming a fine of €4,125,000,000. Alphabet is jointly and severally liable for €1,520,605,895 of that amount.

The case goes back to 2018, when the European Commission concluded that Google had abused its dominant market position through three categories of restrictions built into its Android licensing arrangements. Device manufacturers who wanted access to Google’s Play Store had to pre-install Google Search and Chrome. To get the licences needed for those apps, they also had to agree not to sell devices running Android versions that Google hadn’t approved. And Google paid manufacturers and mobile operators a share of its advertising revenue on the condition that they didn’t pre-install a competing search engine on a defined set of devices. The Commission concluded all three formed a single, coordinated strategy to protect Google’s search dominance, and fined the company €4,342,865,000.

The General Court reviewed the case in 2022 and agreed that the conduct was a single and continuous infringement. It annulled one piece of the Commission’s decision: the part dealing with revenue share agreements tied to the exclusive pre-installation of Google Search on a predefined device portfolio. That partial annulment led the court to recalculate the fine downward to €4.125 billion. Everything else held.

Google and Alphabet then appealed to the Court of Justice, the EU’s highest court, arguing the General Court had made legal errors in its analysis. The Court of Justice went through those arguments and rejected them all.

“The appeal brought by Google and its parent company Alphabet against the judgment of the General Court is dismissed, thereby confirming the penalty imposed for Google Search’s abuse of a dominant position in the context of the Android operating system.” the court’s press release states. “In 2018, the European Commission adopted a decision in which it concluded 1 that Google had abused its dominant position by requiring, in particular through pre-installation agreements and licensing conditions for certain apps, that its search engine, Google Search, and its Chrome browser be promoted on mobile devices running the Android operating system, which is also provided by Google. 2 It therefore found a single and continuous infringement covering the whole of that conduct and imposed an overall fine on Google of €4 342 865 000, with Alphabet jointly and severally liable as to €1 921 666 000.”

Google’s first argument was that the General Court assessed the anticompetitive effects of the pre-installation conditions incorrectly, in particular, that it should have run a counterfactual analysis to show what the market would have looked like without those conditions. However, the Court of Justice disagreed and confirmed the General Court was entitled to look at the full economic context, including the revenue share agreements, without needing to run a formal counterfactual test. The court also confirmed the finding that pre-installed apps enjoy a status quo bias, meaning users are less likely to switch away from them, and that Google hadn’t shown that user preferences or the quality of its services alone explained its market position.

On the pre-installation conditions specifically, Google argued that proving abuse of a dominant position requires showing the conduct could exclude competitors that are equally efficient. The Court of Justice rejected that too.

“Second, the General Court did not err in law by confirming the Commission’s assessment of the pre-installation conditions laid down by the Android agreements. Demonstrating an abuse of a dominant position is not conditional in any case on proof of a capability to foreclose only as-efficient competitors.” continues the press release. “Given the particular characteristics of the digital markets concerned, the General Court was entitled to conclude that those practices were liable to restrict competition and strengthen barriers to entry without applying that test.”

On the anti-fragmentation agreements, which required manufacturers to avoid selling devices running unapproved Android forks, the Court of Justice again sided with the General Court. Those agreements limited the commercial space for Android versions Google hadn’t blessed, which reinforced its dominant position. A counterfactual analysis wasn’t necessary because the anticompetitive effects were already sufficiently established on the facts.

Google also challenged how the fine was calculated, invoking procedural arguments including rights of defence. The Court of Justice endorsed the General Court’s use of its unlimited jurisdiction to set the penalty amount, ruling that the reasoning was sufficient and the procedural principles were respected.

“The Court of Justice endorses the exercise by the General Court of its unlimited jurisdiction to set the amount of the fine, ruling that its reasons were sufficient and that the procedural principles invoked by Google and Alphabet, including rights of defence, were adhered to.” states the report.

Google is disappointed with the ruling.

“We are disappointed with the ruling. Android has given people more choice, not less, enabling thousands of device makers to build affordable smartphones and giving billions of people access to a wide range of apps and services. We will review the judgment carefully.” the company said in a statement.

This is the end of the road for this particular case. The Court of Justice is the EU’s highest court on points of law. There’s no further appeal. The €4.1 billion fine stands, and the legal framework the Commission used to reach that conclusion has now been validated at every level of the EU court system.

The case also sets a precedent for how digital markets get treated under EU competition law. The court confirmed that the standard test used in traditional markets, whether conduct excludes equally efficient competitors, doesn’t automatically apply in digital contexts. That has implications well beyond Google. Any company with a dominant platform position in the EU now knows that structuring licensing arrangements to steer users toward its own products carries real legal risk, even if it can argue its products are genuinely better.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Google)

❌
❌