20M Children Faced Online Sexual Abuse, Plus 4 Stories
A new UNICEF report puts a number on something parents, schools and technology companies have been arguing about for years: across 21 countries, an estimated 20 million internet-using children ages 12 to 17 experienced at least one form of technology-facilitated sexual exploitation or abuse in a single year.
That number is awful. It also needs a little unpacking, because “20 million children were abused online” is the kind of headline that can become both terrifying and useless if we stop there.
The danger isn’t limited to strangers on the internet
UNICEF’s Through Children’s Eyes report draws on nationally representative surveys of about 21,000 internet-using children collected between 2020 and 2025 in 21 countries across Africa, Asia, Latin America and Eastern Europe. The estimate is for those countries, not the entire world. UNICEF says the global total is likely much higher.
The report estimates that more than 15 million children were exposed to unwanted sexual content, about 9 million were pressured into sexual conversations or sharing sexual images, and roughly 4 million had sexual images of themselves shared without consent. In the nine countries where UNICEF collected data on AI-generated sexual imagery, an estimated 1.1 million children said sexual images or videos had been generated depicting them.
Here’s the part I think is especially useful: this is not simply a story about anonymous predators finding children in some dark corner of the internet. UNICEF says 57% of cases involved someone the child already knew — peers, friends, romantic partners or family members. Another 38% involved someone the child first met online. Nearly 60% of the reported experiences happened on mainstream social-media and messaging platforms, with another 14% tied to online games.
And fewer than 1% were reported to police, a social worker or a helpline. More than four in ten weren’t disclosed to anyone at all.
That changes the practical conversation. “Don’t talk to strangers online” is not enough, because sometimes the person applying pressure is already in the child’s contacts, school, friend group or relationship. Parents and schools need children to know that coercion, threats, unwanted sexual content and non-consensual image sharing are things they can ask for help with without first having to prove that they made every perfect decision leading up to it.
For U.S. families, the National Center for Missing & Exploited Children accepts reports through its CyberTipline. Its free Take It Down service can also create a digital fingerprint of nude or sexual images taken before age 18 so participating platforms can detect and remove copies without the image itself leaving the device.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Elementor Pro is being actively exploited
There is also a very straightforward patch-now item for WordPress administrators. Attackers are actively exploiting CVE-2026-32475 in Elementor Pro, and Wordfence says its firewall has already blocked more than 190,000 attempts.
The bug is an unauthenticated arbitrary-file-upload flaw in Elementor Pro’s Form widget. The interesting part is the condition: a vulnerable site needs a published Elementor Pro form with at least one non-required File Upload field. An attacker can submit the upload as an array with an empty first element. Because of a validation mistake, Elementor stops checking the rest of the array; the attacker’s second element can then be an executable PHP file.
Once PHP lands in a web-accessible uploads directory, we’re no longer talking about somebody uploading the wrong kind of attachment. We’re talking about code execution and potentially complete control of the site.
Elementor Pro 4.2.2 fixes the problem. Update to that version or later now. If a site was exposed while vulnerable, Wordfence recommends checking /wp-content/uploads/elementor/forms/ for unexpected PHP files and reviewing web-server logs for suspicious Elementor form submissions. A firewall is useful defense in depth; it isn’t a reason to leave vulnerable software installed.
GPT-6 Astra arrives, and the cyber capability matters
OpenAI released GPT-6 Astra Thursday. It is rolling out first to a limited group of organizations and then, over the coming days, to ChatGPT Plus, Pro, Business and Enterprise users, along with the API and Amazon Bedrock.
There will be plenty of benchmark charts and “look what it built” demos. The part I wouldn’t bury is OpenAI’s own safety classification: Astra is the first model the company says has reached the Critical cybersecurity threshold in its Preparedness Framework.
In plain English, OpenAI says that with the right tools and access, Astra can find previously unknown vulnerabilities and develop ways to exploit them across well-protected systems without a human guiding every step. That is a meaningful jump from “an AI can explain a CVE” or even “an AI can help a penetration tester.” It’s closer to delegating chunks of real vulnerability research and exploitation to an agent.
OpenAI says it delayed parts of Astra’s development while strengthening safeguards, tightened isolation after the Hugging Face incident, added broader monitoring and abuse detection, and will restrict the model’s most advanced cybersecurity capabilities. Those are important claims. They’re also claims from the company releasing the model, so the real test begins as outside researchers and customers get their hands on it.
For a normal business, the immediate lesson isn’t “Astra is coming to hack you.” It’s that agent permissions matter more as the agent gets better. If an AI can use a browser, terminal, cloud account, code repository and password vault, every one of those connections is part of your security boundary. Giving an agent broad authority because clicking Approve is annoying is going to age badly.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
Tesla’s steering-wheel-free Cybercab is carrying riders
Tesla has moved Cybercab from stage presentation to limited public rides in Austin, Texas. That’s worth noting because the two-seat vehicle has no steering wheel, pedals or mirrors. It is designed around the assumption that nobody inside is going to take over and drive it home if the software gets confused.
The National Highway Traffic Safety Administration told Reuters Thursday that it is in contact with Tesla and evaluating the rollout, without yet saying what that evaluation will involve. Federal vehicle rules normally contemplate some of the controls Cybercab omits, which is why the regulatory piece matters as much as the autonomy demo.
Tesla’s own rider guide is now live, including instructions for emergencies and contacting remote Robotaxi Support. Cybercab service is currently limited to parts of Austin. So this is not “self-driving taxis have taken over America,” and it isn’t merely a prototype anymore either. Real passengers are now sitting in a vehicle specifically built without manual controls while regulators work through what that means.
WordPress security & maintenance
Keeping WordPress current is only part of keeping it healthy. Raymond Tec handles updates, backups, security monitoring, compatibility problems, access cleanup, and maintenance — plus the assorted weirdness that accumulates on a site over time.
If you run Plex, update it now
Finally, Plex is doing something security vendors occasionally have to do before the vulnerability write-ups are ready: telling people to patch first and explaining the details later.
In an official security notice, Plex says it fixed multiple security issues in Plex Media Server 1.43.3 and Plex Desktop 1.115.0 and recommends that everybody running the server or desktop app update as soon as possible. Media Server 1.43.2 and earlier are affected. CVE identifiers have been requested, but Plex has not yet published the technical details or severity of the individual flaws.
That’s not a reason to wait. Once a security patch exists, researchers and attackers can compare the old and new code to work backward toward the bug. Plex has already done the useful part for users: it identified the affected version range and shipped fixes.
NAS users should pay particular attention because the latest Plex package may not have reached the NAS vendor’s package manager yet. Plex says those users can install the current package manually. If your media server is one of those appliances that has been quietly doing its job in a closet for three years, Friday is a fine day to remember that it is still a computer connected to your network.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- UNICEF: 1 in 5 children across 21 countries experienced tech-facilitated sexual exploitation and abuse
- UNICEF: Through Children’s Eyes
- Reuters: UNICEF estimates 20 million children suffered online sexual abuse in one year
- Wordfence: Attackers actively exploiting Elementor Pro vulnerability
- OpenAI: GPT-6 Astra
- OpenAI: GPT-6 Astra safety overview
- Reuters: OpenAI launches Astra amid agent-safety scrutiny
- Reuters: NHTSA evaluating Tesla Cybercab rollout
- Tesla: Cybercab Rider Guide
- Plex: Important security update for Media Server 1.43.2 and earlier
