Week of October 5 to 11, 2026:

  • Denmark's Central Population Register leaked roughly 8.8 million records through authorized-access misuse. The Register reported the CPR administration noticed irregular activity in September and confirmed the breach scale on October 2; the digitisation ministry issued a public statement on the weekend of October 4 to 5. Denmark's population sits near 6 million, with the full register holding roughly 11 million records, so the spill is bigger than the country. Cybersecurity specialist Jan Kaastrup told The Register the CPR system is "broken" because it treats a single identifier as proof of identity [1].
  • Senator Ron Wyden asked ONDCP director Sara Carter to release a 2024 MITRE privacy review of the HIDTA license-plate-reader program. Wyden's October 9 letter cites MITRE's completed-but-not-public review and names Flock, Axon, and "other vendors" ALPRs as the data sources the HIDTA program aggregates. The letter is the first concrete federal disclosure pressure on the program since the October 2 ruling in United States v. Kyle calling a Flock search "indiscriminate mass surveillance" [2][3].
  • EFF published "When No ID Means No Internet," arguing mandatory age-verification gates exclude roughly 850 million people globally. Jillian C. York and Sheila B. Lalwani frame the laws as "less about confirming the age of a user and more about creating barriers to online participation that many people cannot reliably scale," and cite the US figure: roughly 15 million adult US citizens lack a driver's license, and a further 2.6 million lack any government photo ID [4][5].
  • EFF separately mapped "two years" of federal data consolidation in three waves: DOGE, DHS-ICE, and SAVE voter-roll purges. Adam Schwartz and F. Mario Trujillo catalogued active litigation including American Federation of Government Employees v. U.S. Office of Personnel Management, California v. Trump (24 states), and EPIC v. USCIS, and reported the federal government has sued 30 states over voter data, with courts dismissing 25 of those suits [6][7].
  • The FBI seized seven web domains tied to Integrity Technology Group and the Flax Typhoon botnet. The Register reports FBI special agent Adam James's filings name a US power company in South Carolina as a scanned target, add five CVEs to CISA's Known Exploited Vulnerabilities Catalog, and document a 260,000-device botnet "infecting devices from 2021 until the FBI stepped in." The takedown is the first time the United States, UK, Australia, Canada, Japan, New Zealand, and Spain jointly attributed the activity [8].
  • Florida, Iowa, Montana, and Nebraska sued TP-Link Systems, alleging the router giant hid its China ties. The Register puts the market footprint at 36.6% of US unit share in 2024 and cites former NSA cybersecurity director Rob Joyce's 2025 estimate of roughly 60% retail-market share. Iowa AG Brenna Bird: "Iowans' sensitive data and our national security is at risk because of TP-Link and their connection to the communist Chinese government" [9][10].
  • A 404 Media podcast covered a leaked video showing police can defeat the iPhone's automatic inactivity reboot. Joseph Cox and Lorenzo Franceschi-Bicchierai discussed forensic tooling that re-enters a locked iPhone after Apple's After First Unlock reload, the security feature Apple shipped specifically to keep a seized phone in a hardened state [11][12].

Continuing threads: EFF separately published a global age-verification brief calling national ID systems a structural exclusion. A 42-state bipartisan AG coalition's January 16 ultimatum on AI chatbot safety expired with most recipients silent. LastPass disclosed a master-password phishing wave timed to the MLK weekend. Gunra ransomware listed more than 30 victims on its leak site. The FBI continued investigating the IDScan breach that surfaced 153 million driver's-license scans on a dark-web service called Nexus. The Arizona Court of Appeals ruled an AI-generated victim-impact statement carries "undue emotional weight." arXiv rate-limited submissions to fight AI-generated paper floods. The HiddenLayer Muse VM-escape disclosure added a Meta pre-launch patch to the agent-misalignment series. The Anthropic Glasswing three-tier threat-hunting program consolidated the AI-red-team side. EFF flagged two new Congressional site-blocking bills (DEFEND IP and ACPA) that explicitly target VPN providers. A federal court rejected the government's motion to dismiss the UAW, CWA, and AFT lawsuit over AI-driven social-media monitoring of noncitizens. A Northeastern University and Consumer Reports study called modern connected cars a "surveillance platform."

The Throughline: The Identity Layer Is the Surveillance Layer

Read the week's stories in isolation and you see a pile of disconnected news. Read them as one beat and the picture sharpens. This week's surveillance stories all ran through identity systems. Denmark's CPR register treats a single national identifier as the proof of who you are for tax, healthcare, banking, and government services, and a private firm with legitimate access walked out roughly 8.8 million records [1]. EFF's age-verification brief argues the same logic in policy form: a national ID is becoming the gate to the internet, and roughly 850 million people globally do not have one [4]. EFF's federal data consolidation piece argues the same logic across agencies: federal departments route benefits, tax, immigration, and voter data through shared identifiers [6]. Wyden's HIDTA letter cites the same logic across jurisdictions: a license plate is treated as a per-vehicle identifier and aggregated into a national database through grant-conditioned MOUs [2]. Across six independent stories, the common move was identifying the identity system as the place where surveillance architecture hides [1][2][4][6][8][9].

The second throughline is the disclosure timing. Denmark's digitisation ministry waited more than a month from the irregular activity it noticed in September to the public statement on October 4 to 5. The MITRE 2024 HIDTA privacy review was completed and is being withheld. The voter-roll consolidation EFF maps has 25 of 30 DOJ suits already dismissed, with the disclosure battles now being decided on the shadow docket. The 153 million driver's-license scans surfaced through a dark-web service rather than through a corporate breach disclosure. In every case the audit and disclosure layer is being assembled after the data has already moved. The week's legal moves all push toward forcing the disclosure layer upstream of the data, in court filings, in congressional letters, in public grant documents [1][2][6].

The third throughline is the endpoint. The FBI seized seven Flax Typhoon domains tied to a 260,000-device botnet that ran from 2021 until the disruption [8]. Four state AGs sued TP-Link Systems, the router vendor whose 36.6% US unit-share figure means a compromised home router sees everything the household touches [9]. A 404 Media podcast discussed leaked video showing police can defeat the iPhone's automatic inactivity reboot, the security feature Apple shipped specifically to harden seized phones [11]. The endpoint is the place where the surveillance layer now lives. The surveillance infrastructure that cannot survive disclosure at the endpoint cannot survive at all.

Wyden Presses ONDCP to Release the 2024 MITRE HIDTA Privacy Review

Jason Koebler reported on October 9 in 404 Media that Senator Ron Wyden sent a letter to Sara Carter, director of the White House Office of National Drug Control Policy (ONDCP), demanding the public release of a 2024 MITRE privacy review of the HIDTA license-plate-reader program. Wyden's letter cites MITRE's completed-but-not-public review and 404 Media's reporting that the HIDTA program aggregates location data on Americans derived from Flock, Axon, and "other vendors" ALPRs [2].

Wyden's letter puts three statements in the public record. First, the MITRE review was commissioned by ONDCP and "should be released to the public." Second, "this review was conducted by MITRE and completed in 2024, but ONDCP refused to provide it to my office and has subsequently not made that report public. I urge you to make this review public." Third, "there is currently limited transparency into these HIDTA-funded surveillance programs, but ONDCP has commissioned an assessment into the privacy practices of these programs that should be released to the public." Wyden also requests a separate "analysis of automated license plate reader systems and practices" [2].

The letter lands in the same week EFF's federal data consolidation brief and 404 Media's HIDTA investigation are in the public record, and three weeks after the October 1 ruling in United States v. Kyle, in which U.S. District Judge Sara Hill of the Northern District of Oklahoma called a single Flock search "a type of indiscriminate mass surveillance" and suppressed the evidence [3]. The structural argument is straightforward: when a federal grant program concentrates plate reads from local agencies into a federal database, the privacy bargain is moved from the city council to the White House, with no public review of the budget. The site's Flock federal-court ruling vessel and the Ban Flock Act vessel track the parallel federal response [2][3][13].

Denmark's CPR Register Spilled More Records Than Denmark Has People

Jude Karabus reported on October 6 in The Register that an unauthorized party pulled roughly 8.8 million records from Denmark's Central Population Register (CPR) by abusing a private Danish firm's legitimate access. Denmark's population sits near 6 million; the register also holds deceased residents, people who moved abroad, and Greenland enrollees, and tops out around 11 million records. The Register reports the CPR administration became aware of irregular activity in September and confirmed the breach scale on October 2, with the digitisation ministry issuing a public statement on the weekend of October 4 to 5 [1].

Denmark's civil-identification system runs on Section 38(1) of the Danish Civil Registration System Act, which restricts legitimate CPR access to companies, foundations, other legal entities, and individuals conducting business, and requires that "access concerns a defined group of people identified individually in advance." A private-sector partner is exactly the kind of entity that holds that access in normal course, which makes the spill a misuse case rather than a front-door hack. The Register reports the ministry "blocked the unnamed company's access," is "working with specialists and relevant authorities," has notified the Danish Data Protection Agency, and that police are investigating. Names and addresses of persons who registered with name and address protection were not exposed [1].

Cybersecurity specialist Jan Kaastrup told The Register: "We live in a digitalized society, and therefore we should have much better identification systems." He also described treating CPR numbers as secrets as a "broken" approach and argued that a number alone should not be accepted as proof of identity [1]. The Register reports digitisation minister Christina Egelund said it was too soon to say whether the country would issue all-new CPR numbers. The Register's framing as a "surveillance-scale" leak is correct: the CPR system is "essentially broken" because it anchors tax, healthcare, banking, and government services to a single identifier. Roughly 55,000 Greenland residents also use CPR numbers for healthcare, tax services, and banking, which is how far a single national ID can carry across borders [1]. The site's age-verification ID-system explainer is the parallel US-side piece on the same architectural problem [1][5].

EFF's "No ID, No Internet" Brief Frames Age Verification as Exclusion Infrastructure

Jillian C. York and Sheila B. Lalwani, a doctorate student and recent COMPASS Fellow hosted by EFF, published "When No ID Means No Internet: Age Verification and the Right to Access Information" on October 8. The piece argues mandatory age-verification rules are exclusion infrastructure rather than child-safety tools: roughly 850 million people globally do not have ID, "most of these individuals exist in primarily low and middle income countries in Sub-Saharan Africa and South Asia," and "women are particularly vulnerable and are 8% less likely than men to have an ID" [4].

The US-side numbers anchor the global frame. Roughly 15 million adult US citizens lack a driver's license, and a further 2.6 million lack any government photo ID. Australia's under-16 social media ban, in place since late 2025, is the running case the piece circles back to, and the UK Online Safety Act is the European parallel. The piece also names the differential impact: in Egypt, the lack of ID cards has created challenges for minority groups such as the Baha'i; the Rohingya, the world's largest population of stateless people, often lack IDs; Kuwait's Bidoon population also lacks proper identification materials. Nigeria launched a national program in 2007 and has registered 64.4 million, "but that represents just over 30% of the national population" [4].

EFF's framing: "Age verification laws provide quick tech solutions but overlook longstanding structural challenges and undermine the universality of the internet." The piece lands the same week as Denmark's CPR spill, the inverse failure mode: in Denmark the problem is that everyone is on a single national ID system; in the global age-verification frame, the problem is that the global internet is being gated on whether they are on one. Both stories sit on the same architectural choice. The site's age-verification as surveillance piece and the Doctorow frame carry the broader pattern [4][5][14].

EFF Maps Two Years of Federal Data Consolidation in Three Waves

EFF's Adam Schwartz and F. Mario Trujillo published "Resisting the Menace of Federal Data Consolidation" on October 9, mapping three waves of federal data amalgamation: the Department of Government Efficiency (DOGE) created on January 20, 2025 and its "prompt access to all unclassified agency records" mandate, agency-to-agency sharing that routes benefits and tax data to ICE, and SAVE-Act voter-roll purges. The piece links the three waves together as a sustained threat to the 1974 Privacy Act framework [6][7].

The filing map is the heart of the piece. The lawsuits named include American Federation of Government Employees v. U.S. Office of Personnel Management, Centro de Trabajadores Unidos v. Scott Bessent, California v. HHS, League of Women Voters v. DHS, Common Cause v. U.S. Department of Justice, California v. Trump (with 24 states as plaintiffs), and U.S. Postal Service v. California. EFF reports more than 60 million voter records run through SAVE with 21,000 flagged as potential noncitizens, that at least 48 states have been asked to hand over voter information, that at least 16 states have complied, and that the federal government has sued 30 states over voter data, with courts dismissing 25 of those suits. The Supreme Court voted six-to-three in DHS v. League of Women Voters and in Trump v. California on stays, and seven-to-two denying a stay in USPS v. California. EFF's prescription: strengthen the 1974 Privacy Act, pass the Fourth Amendment Is Not For Sale Act, and enact a comprehensive consumer-privacy law [6].

The structural reading is the identifier layer. Federal departments route benefits (OPM, SSA, Treasury), tax (IRS), immigration (DHS-ICE), and voter data (DOJ, AAMVA, USCIS) through shared identifiers. EFF frames the consolidation as a Privacy Act rollback: when the act passed in 1974 it set rules for what each federal agency could do with the data it collected, and the consolidation breaks the rule by routing data across departmental boundaries without a fresh collection authority. The site's ICE location-data IG probe vessel and the free-surveillance-tech pipeline vessel are the data-broker end of the same build [6][7][15].

FBI Seizes Seven Integrity Technology Group Domains Tied to Flax Typhoon

Jessica Lyons reported on October 8 in The Register that the FBI seized seven web domains tied to Integrity Technology Group and the Flax Typhoon botnet, in a joint action with the United States, UK, Australia, Canada, Japan, New Zealand, and Spain. The Register reports FBI special agent Adam James's filings name a US power company in South Carolina as a scanned target, list five CVEs added to CISA's Known Exploited Vulnerabilities Catalog, and document a 260,000-device botnet "infecting devices from 2021 until the FBI stepped in." CISA published an advisory, AA26-281A, on the same day as the seizures [8].

The tradecraft is documented in the FBI filings. The actors "exploit vulnerabilities by using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts." The FBI identified a specific scanner the group used, named Microscan, and a phishing helper named FishHub: "based on my training and experience I believe the tool was named FishHub because it facilitated phishing activity." The filings add specific targets: a US power company in South Carolina, a multi-national Non-Governmental Organization, Japanese and Polish airports, and at least two Taiwanese critical-infrastructure companies in the natural gas and power sectors, all scanned by the Microscan tool on or about April 26, 2022 and December 29, 2022 [8].

The five CVEs added to the catalog were CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, and CVE-2023-22894. The Register notes this is the first time seven governments have jointly attributed the activity to a single named threat actor, and the joint action follows a previous takedown of the "Raptor Train" botnet infrastructure run by Flax Typhoon. The seized domains include c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net, with the seventh domain not named in the warrant filing. The site covers the parallel PRC hacking infrastructure in the FBI China FISMAmajor-incident vessel and the Volt Typhoon tracker [8][16].

404 Media Reports Police Can Defeat the iPhone's Automatic Reboot

Joseph Cox and Lorenzo Franceschi-Bicchierai covered on the 404 Media podcast published October 8 an underlying Franceschi-Bicchierai report on a leaked video in which forensic tooling defeats the iPhone's automatic inactivity-reboot, the post-reboot relock Apple designed to keep a seized phone in Apple's Before First Unlock (BFU) state. Cox framed the episode around police "getting around a very important iPhone security feature" [11][12].

The technical surface is the lock-state machine. Apple ships a setting that reloads an iPhone into Apple's Before First Unlock (BFU) state after a period of inactivity, on the logic that a long-disconnected phone in the After First Unlock (AFU) state is the more exploitable target. The leaked video, paired with reporting on commercial tools like GrayKey, shows investigators reconnecting before the timer fires and harvesting data anyway. A reader-level framing: the security feature assumed a phone would be off for days, not minutes; the forensic workflow assumes minutes, not days. The two assumptions no longer match [12].

This is the device-security story that connects to Lockdown Mode and to the West Virginia v. Apple CSAM case: the same Apple security stack that is being litigated in state court is also the stack law enforcement is now working around at the field level. The site's ICE Cellebrite and GrayKey contracts vessel and the Apple Signal-deleted-messages CVE vessel track the parallel device-security angles [11][12][17].

Continuing Threads From the Week

EFF mapped a global age-verification brief. The 850-million figure in the Oct 8 piece sits on top of the rolling state-by-state age-verification tracker the site runs. EFF separately named the Privacy Act rollback as the legislative pressure point [4][5][6].

The 42-AG AI chatbot deadline passed with most companies silent. The January 16, 2026 deadline set by Pennsylvania's Dave Sunday and New Jersey's Matthew Platkin passed with Microsoft, Google, Meta, Apple, Anthropic, and Character.AI issuing no public comment. The coalition escalated to xAI on January 23 over Grok's nonconsensual intimate imagery. The Trump administration's Executive Order 14365 preempts state AI rules but carves out child safety [18][19].

LastPass disclosed a master-password phishing wave. Attackers sent emails warning of "24-hour" vault backups through an AWS redirect to mail-lastpass[.]com. LastPass warned that no one at the company ever asks for a master password by email [20].

Gunra ransomware listed more than 30 victims. The August 10, 2026 joint advisory AA26-222A from CISA, the FBI, NSA, USSS, DC3, and the Republic of Korea National Police Agency names ten targeted sectors. The Linux variant has a real recovery path because of a weak PRNG seeded with the predictable system srand(time(NULL)) [21].

The FBI continued investigating the IDScan / Nexus dark-web breach. The breach surface is 153 million US driver's-license scans advertised on a Tor-based identity service called Nexus. KrebsOnSecurity reported the FBI New Orleans field office opened a formal investigation. Four proposed class actions sit in Louisiana federal court [22].

Arizona's Court of Appeals ruled an AI-generated victim-impact statement carries "undue emotional weight." The murder victim's sister used an AI avatar to deliver the statement; the appellate court ordered resentencing. This is the first major ruling on the procedural standing of AI-generated victim testimony [23].

arXiv rate-limited submissions to fight AI-generated paper floods. The canonical scientific preprint server capped researchers at two submissions per month. 404 Media's reporting framed it as a research-integrity story [24].

The Meta Muse VM-escape pre-launch patch. 404 Media reported Meta engineers worked overtime to fix a sandbox-escape vulnerability in its Muse agentic AI product before shipping it to the public [25].

Anthropic consolidated Glasswing and the Cyber Verification Program into a three-tier scheme. The Register reports Anthropic disclosed 33,000+ critical/high-severity vulnerabilities in the same announcement [26].

EFF flagged two new Congressional site-blocking bills. The DEFEND IP Act (H.R. 10575) deputizes ISPs as "copyright cop[s]." The American Copyright Protection Act (H.R. 10364, sponsored by Rep. Darrell Issa) targets VPN providers with broad "piracy site" definitions [27][28].

A federal court rejected the government's motion to dismiss the UAW, CWA, and AFT lawsuit. U.S. District Judge Alvin K. Hellerstein of the Southern District of New York found the threat of adverse immigration action could deter "a person of ordinary firmness" from exercising First Amendment rights. The case moves into discovery [29].

A Northeastern University and Consumer Reports study called connected cars a "surveillance platform." Nearly every automaker transmitted driver data to external companies, and almost a quarter of vehicle apps transmitted personally identifiable information including owners' names, vehicle identification numbers, and precise geographic locations [30].

Sanders, Ocasio-Cortez, and Merkley filed the federal Ban Flock Act. Bernie Sanders' statement: "At a time of growing concern about the unchecked power of artificial intelligence, Flock is eviscerating the very notion of privacy by installing tens of thousands of cameras in communities across America without their consent." Alexandria Ocasio-Cortez: "AI-powered cameras are keeping track of our every move and weaponizing this data against working people to make record profits." Jeff Merkley: "No one should have this unchecked surveillance power at their fingertips" [13].

The Week Ahead

The MITRE 2024 HIDTA privacy review. ONDCP's standard letter-response window runs the public pressure timeline. Watch whether the MITRE 2024 HIDTA privacy review lands on the public docket by October 16, and whether ONDCP publicly names which Hemisphere and ALPR questions the review covers [2].

The Danish CPR misuse case. The Register reported the breach was discovered through September activity and confirmed October 2. Watch for a Digitisation Ministry statement on whether CPR numbers will be reissued, and for the first Danish Data Protection Agency enforcement notice naming the access-misuse private partner [1].

The federal data consolidation docket. California v. Trump's 24-state posture, and the EPIC v. USCIS suit, are the leading cases. Watch for the next 6-3 or 7-2 SCOTUS shadow-docket ruling on a data-sharing motion, and for new SAVE-Act voter-roll purge motions in remaining states [6].

Flax Typhoon disruption follow-on. The FBI's October 8 domain seizure is the public-facing action. Watch for the second indictment against Integrity Technology Group personnel, and for a US-CISA advisory on consumer-routers and the MS Exchange CVE scanned by the Flax Typhoon toolkit [8].

Age-verification state tracker. EFF's 850-million global figure lands while a wave of US state-level age-verification bills are still moving. Watch for the next state to enact a major-platform age-verification mandate and the first court challenge under state privacy law [4].

The TP-Link multi-state case. Watch for any preliminary injunction motion, and for the first state-court ruling on whether consumer-protection law reaches a foreign-supply-chain deception claim. The Nebraska complaint is the public docket to watch [9].

The iPhone reboot bypass disclosure cycle. Watch for Apple's next security advisory on the inactivity-reboot feature, and for any congressional letter asking Apple whether the bypass disclosure came through responsible disclosure or through leaked video [11][12].

The Ban Flock Act markup path. The Sanders-Ocasio-Cortez-Merkley bill arrives with companion House work from Reps. Greg Casar and Shontel Brown. Watch whether the bill attaches to a must-pass vehicle and whether Hawley's Stop Flock Abuse Act is bundled with it [13].

Sources

  1. The Register, Jude Karabus: Denmark's ID register spills more people's details than the country has residents (October 6, 2026). https://www.theregister.com/security/2026/10/06/denmarks-id-register-spills-more-peoples-details-than-the-country-has-residents/5301307
  2. 404 Media, Jason Koebler: Following 404 Media Investigation, Senator Demands Info About White House's License Plate Surveillance Program (October 9, 2026). https://www.404media.co/following-404-media-investigation-senator-demands-info-about-white-houses-license-plate-surveillance-program/
  3. State of Surveillance: Federal Judge Rules Flock ALPR Search Unconstitutional (October 9, 2026). /news/flock-alpr-search-unconstitutional-federal-judge-2026
  4. EFF Deeplinks, Jillian C. York and Sheila B. Lalwani: When No ID Means No Internet: Age Verification and the Right to Access Information (October 8, 2026). https://www.eff.org/deeplinks/2026/10/when-no-id-means-no-internet-age-verification-and-right-access-information
  5. State of Surveillance: Age Verification as Surveillance: The ID System Behind Every Check (2026). /news/age-verification-surveillance-infrastructure-id-system-2026
  6. EFF Deeplinks, Adam Schwartz and F. Mario Trujillo: Resisting the Menace of Federal Data Consolidation (October 9, 2026). https://www.eff.org/deeplinks/2026/10/resisting-menace-federal-data-consolidation
  7. State of Surveillance: ICE Location Data IG Probe: 70 Lawmakers Demand Answers (2026). /news/ice-location-data-ig-probe-70-lawmakers-illegal-purchases-2026
  8. The Register, Jessica Lyons: US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide (October 8, 2026). https://www.theregister.com/security/2026/10/08/us-disrupts-chinese-hacking-tools-as-7-govts-warn-of-prc-spies-stealing-sensitive-data-worldwide/5302107
  9. The Register, Connor Jones: US states sue popular kitmaker TP-Link over China risks (October 7, 2026). https://www.theregister.com/security/2026/10/07/us-states-sue-popular-kitmaker-tp-link-over-china-risks/5301653
  10. State of Surveillance: Texas AG Sues TP-Link Over CCP Ties (February 2026). /news/texas-ag-paxton-ccp-lawsuits-temu-shein-tp-link-surveillance-2026
  11. 404 Media, Joseph Cox (host): Podcast: Leak Show Cops Can Break into Locked iPhones (October 8, 2026). https://www.404media.co/podcast-leak-show-cops-can-break-into-locked-iphones/
  12. 404 Media, Lorenzo Franceschi-Bicchierai: Cops Can Bypass iPhone's Automatic Reboot to Get Into Locked Phones, Leaked Video Claims (October 2026). https://www.404media.co/cops-can-bypass-iphones-automatic-reboot/
  13. State of Surveillance: Ban Flock Act: Sanders, Ocasio-Cortez, Merkley Introduce Federal ALPR Ban (October 7, 2026). /news/ban-flock-act-sanders-ocasio-cortez-merkley-alpr-federal-2026
  14. State of Surveillance: Cory Doctorow on Age Verification as Mass Surveillance (June 25, 2026). /news/cory-doctorow-age-verification-is-mass-surveillance-2026
  15. State of Surveillance: Free Surveillance Tech Pipeline: How Police Hand Data to ICE (2026). /news/free-surveillance-tech-pipeline-police-ice-data-2026
  16. State of Surveillance: FBI China Hack Major Incident FISMA (2026). /news/fbi-china-hack-major-incident-fisma-surveillance-2026
  17. State of Surveillance: Apple iPhone Signal Deleted Messages FBI Notification Bug CVE-2026-28950 (2026). /news/apple-iphone-signal-deleted-messages-fbi-notification-bug-cve-2026-28950
  18. TechCrunch: State attorneys general warn Microsoft, OpenAI, Google to fix "delusional outputs" (December 2025). https://techcrunch.com/2025/12/10/state-attorneys-general-warn-microsoft-openai-google-and-other-ai-giants-to-fix-delusional-outputs/
  19. State of Surveillance: 42 State AGs AI Chatbot Safety Ultimatum (2026). /news/42-state-ags-ai-chatbot-safety-ultimatum-2026
  20. State of Surveillance: LastPass Master Password Phishing Campaign (2026). /news/lastpass-phishing-campaign-master-password-2026
  21. State of Surveillance: Gunra Ransomware Tracker, Methods and Victim Sectors (October 7, 2026). /articles/corporate/gunra-ransomware-2026-tracker
  22. State of Surveillance: FBI Probes Dark Web Sale of 153 Million License Scans (2026). /news/idscan-153-million-drivers-license-breach-fbi-2026
  23. 404 Media, Samantha Cole: Her AI-Generated Video Swayed the Judge, the Court Said It Carried Undue Emotional Weight (October 6, 2026). https://www.404media.co/her-ai-generated-video-swayed-the-judge-the-court-said-it-carried-undue-emotional-weight/
  24. 404 Media: arXiv Is Rate-Limiting Submissions Because It Can't Keep Up With AI Slop (October 5, 2026). https://www.404media.co/arxiv-is-rate-limiting-submissions-because-it-cant-keep-up-with-ai-slop/
  25. 404 Media: Meta Rushed to Fix "VM Escape" Vulnerability Immediately Before Launch (October 5, 2026). https://www.404media.co/meta-rushed-to-fix-muse-vm-escape-vulnerability-immediately-before-launch/
  26. The Register: Anthropic Reconfigures Its "Cool Kids" Security Program (October 7, 2026). https://www.theregister.com/security/2026/10/07/anthropic-reconfigures-its-cool-kids-security-program/5301509
  27. EFF Deeplinks, Katharine Trendacosta and Joe Mullin: Site-Blocking Will Not Defend IP, No Matter the Bill's Name (October 2, 2026). https://www.eff.org/deeplinks/2026/10/site-blocking-will-not-defend-ip-no-matter-bills-name
  28. EFF Deeplinks, Joe Mullin: Congress Has Another Site-Blocking Bill, and One Targets VPNs (October 2, 2026). https://www.eff.org/deeplinks/2026/10/congress-has-another-site-blocking-bill-and-one-targets-vpns
  29. EFF: Victory: Court Rejects Government Effort to Dismiss Social Media Surveillance Lawsuit (October 2, 2026). https://www.eff.org/press/releases/victory-court-rejects-government-effort-dismiss-social-media-surveillance-lawsuit
  30. Schneier on Security: Connected Cars Are a Surveillance Platform (October 1, 2026). https://www.schneier.com/blog/archives/2026/10/connected-cars-are-a-surveillance-platform.html