AntiMalwareJuly 15, 2026🇷🇺Translated from Russian

UK Plans Nighttime Social Media Curfew and Addictive Feature Restrictions for Teens from 2027

The United Kingdom is preparing to introduce strict nighttime restrictions on social media for teenagers as part of a broader effort to protect young users from excessive screen time and harmful online content.

Starting in spring 2027, users aged 16-17 will be blocked from accessing social networks between midnight and 6 a.m.. This curfew will apply to home internet connections through mandatory content filtering systems.

Beyond the time restriction, platforms will be required to disable the most engaging features by default for this age group. These include infinite personalized feeds, automatic video playback, Reels, and similar short-form video content on TikTok and other services.

The nighttime and feature restrictions are intended to serve as a gradual transition before a full ban on social media for children under 16, which is also scheduled to begin in spring 2027. Officials describe the approach as a phased model: complete prohibition for younger children, followed by limited access, and eventual unrestricted use only for adults.

The government references an experiment involving 300 participants that showed nighttime restrictions quickly became habitual and led to measurable improvements in sleep quality and concentration levels.

Additional measures target AI chatbots. Services aimed at minors will be required to implement mandatory breaks, while platforms distributing dangerous or unverified mental health advice may face outright prohibition.

Schools will also update their curricula to include training on safe interaction with artificial intelligence, recognition of deepfakes, disinformation, and violent or misogynistic content as part of expanded digital literacy programs.

Related articles

AntiMalwarePolicy & Regulation

Over 20 VPN Services Hit by Outages After Russian Regulators Block Hosting Provider Subnets

Users of multiple VPN services reported widespread connection problems throughout the day as IP addresses belonging to several large hosting providers were placed under restrictions. The blocks targeted infrastructure used by VPNs to reroute traffic around content filters, causing entire ranges of servers to become inaccessible when whole subnets were affected. The Telegram channel Exploit reported that more than 20 VPN services of varying sizes experienced disruptions, though Roskomnadzor has not issued an official statement on the scope or origin of the measures. The affected providers indicated they are shifting customers to backup servers, noting that the restrictions appear selective yet still force frequent address changes during the day. The incidents coincide with ongoing discussions of new rules that would require hosting providers to independently detect and report masked VPN IP addresses to regulators. Similar large-scale subnet blocks occurred in late May, impacting numerous MTProto-based proxies and VPNs simultaneously.

安全客Policy & Regulation

HackerOne Ends Anonymous Era for Bug Bounty Hunters with Mandatory ID Verification

HackerOne has introduced compulsory identity verification for all researchers submitting reports to paid bug bounty programs, effective August 1. The policy requires users to complete KYC checks through Estonian firm Veriff by uploading government-issued ID and performing a live selfie, with annual renewals. Vulnerability Disclosure Programs remain open to anonymous participants, but any researcher seeking monetary rewards must now reveal their identity. The move follows similar steps by Bugcrowd and Intigriti and is driven by anti-money laundering and cross-border payment regulations. Researchers in high-surveillance regions and newcomers face new barriers, while the platform argues the change improves report quality and enterprise trust. H1 Clear adds an extra criminal background check layer for elite participants.

AntiMalwarePolicy & Regulation

Telegram Briefly Removed from App Store After Apple Detects Child Sexual Abuse Material

Telegram was temporarily pulled from the App Store in multiple countries after Apple moderators identified content linked to child sexual abuse. The removal lasted roughly 20 minutes before the app was reinstated following Telegram's quick removal of the prohibited material and blocking of the responsible user. Apple cited strict App Store rules as the reason for the action. During the outage, already-installed copies continued to function normally while the app remained available via the Mac App Store and Google Play. Telegram responded on X with the quote “Rumors of my death have been greatly exaggerated” before Apple issued its official explanation. This marks at least the third documented instance of Telegram facing App Store removal, including a 2018 incident over unacceptable content and a 2024 removal from the Chinese store at the request of local regulators.

AntiMalwarePolicy & Regulation

Russia's MinTsifry Proposes Hosting Providers Detect and Report Disguised VPN Services

The Russian Ministry of Digital Development is discussing measures to strengthen oversight of VPN services that mask themselves as legitimate websites and hide their IP addresses from official blocklists. Hosting providers would be required to independently identify suspicious IP addresses and report them to regulators for potential blocking. The proposal also introduces a tiered trust system for hosting clients based on the strength of their identity verification. Users authenticated only via phone or bank card could have services terminated within 30 minutes upon violations, while those verified through Gosuslugi or biometric systems would receive more time to resolve issues. Non-compliant hosting providers risk being labeled as unreliable, resulting in restrictions that limit client access to a narrow whitelist of approved resources such as government portals, banks, and marketplaces. Industry participants warn that these restrictions could worsen IPv4 address shortages and drive legitimate businesses toward foreign hosting providers.