Dome of the US Capitol building shot from below against a cloudy sky
Photo via Unsplash

Today's Top Stories:

  • FISA 702 sunsets in 9 days. Former NSA and CIA directors published an open letter begging Congress to renew. The FISC judge renewed procedures anyway, hedging against a lapse. Congress still doesn't have the votes.
  • Oakland County approved drone surveillance at midnight. The Board of Commissioners voted 13-4 to give Flock Safety a $2.5M drone contract, then let residents speak. Boos echoed until nearly midnight.
  • UK plans to fight knife crime with facial recognition. The government's new strategy drops £26M on CCTV upgrades, live facial recognition vans, and AI hotspot mapping. Privacy? Not in the budget.
  • Chrome's fourth zero-day this year could deliver spyware. CVE-2026-5281 is an exploit chain component: a renderer escape via WebGPU. CISA deadline to patch: April 15.
  • Immigration software breach exposed 116,000 passport numbers. DocketWise, used by thousands of immigration law firms, leaked SSNs, passport scans, and asylum case files to an attacker who cloned their repos.
  • Facial recognition wrongful arrests hit 13 dismissals. A Tennessee grandmother spent five months in jail for crimes in a state she'd never visited. Clearview AI made the match.

FISA 702: 9 Days and Counting

Section 702 of the Foreign Intelligence Surveillance Act expires April 20. Nine days from now. And the people who built the surveillance state are getting nervous.

On April 10, a group of former national security officials (including ex-NSA and ex-CIA directors) published an open letter urging Congress to renew the authority before it lapses [1]. Their argument: Section 702 is "indispensable" for detecting foreign threats. They want a clean extension. No reforms. No warrant requirements for searching Americans' data.

The math still doesn't work for Speaker Johnson. The Congressional Progressive Caucus (98 Democrats) is a hard no on anything without major reforms. A dozen-plus GOP holdouts want the same. The SAVE Act fight is eating floor time. April 19 is a Sunday.

Meanwhile, the FISC judge quietly renewed surveillance procedures on April 9, despite the looming lapse [2]. The judiciary is hedging. If Congress fails to act, the intelligence community wants the plumbing in place for the moment it comes back.

The Brennan Center launched a dedicated Section 702 resource page. EPIC is running a "Reform or Sunset" campaign. The Washington Times ran the showdown as a front-page story on April 10 [3].

Nine days. No deal. No votes. No clear path.

Related: 19-Day Countdown | SAFE Act Analysis | Wyden-Lee Reform Bill | Democrats vs. 702

Oakland County Shoves Through Flock Drone Surveillance at Midnight

The Oakland County Board of Commissioners voted 13-4 on the night of April 8-9 to approve "Project Prove It," a nine-month pilot letting Flock Safety deploy autonomous drones to respond to 911 calls alongside sheriff's deputies [4].

Here's the part that enraged residents: commissioners voted before taking public comment. When they finally opened the floor, people spoke until nearly midnight. Boos and taunts filled the room. Multiple residents pointed to other communities (including Berkeley and Seattle) that have pulled back from Flock contracts after pushback.

The deal:

  • 7 autonomous drones plus Flock911 dispatch integration
  • Nine months free. Then $2.5 million over two years if they keep it.
  • An amendment was added: drone data stays county property, not Flock's

The "free trial" model is Flock's playbook. Get the hardware deployed. Get officers used to it. Then charge $2.5 million when the "trial" ends. We've tracked this pattern before.

The core question residents kept asking: "Who owns the data?" The amendment says the county does. But Flock's standard contracts have historically given the company broad data access rights. Whether the amendment actually changes that depends on the fine print nobody at the meeting had read.

Related: Our Full Coverage | The Flock Rebellion

Sources: [4] Click on Detroit, [5] Fox 2 Detroit

UK's Knife Crime Fix: More Cameras, More Facial Recognition

The UK government unveiled its "Protecting Lives, Building Hope" strategy to halve knife crime over the next decade. The plan relies heavily on surveillance technology [6].

What's in the strategy:

  • £26.25 million through the Knife Crime Concentrations Fund, targeting 27 "hot spot" areas covering 90% of knife crime in England and Wales
  • New CCTV cameras with upgraded connectivity to "minimize blind spots"
  • Expanded use of live facial recognition (LFR) vans in hotspot areas
  • AI-powered micro-geography mapping that pinpoints knife crime to 0.1 square kilometer precision: specific streets, specific times [7]
  • £17 million for railway CCTV improvements over three years

This drops on top of an already expanding UK facial recognition push. The British Transport Police launched a six-month live facial recognition pilot at train stations in January. The Home Office's policing white paper proposes expanding from 10 to 50+ facial recognition vans. Essex Police already had to suspend their FR system over bias concerns.

The pattern repeats: real problem, surveillance solution. Knife crime is devastating: the victims are disproportionately young men of color in deprived areas. But the surveillance tools being deployed to "protect" them are also the tools most likely to misidentify them, profile them, and track their movements long after any knife crime investigation ends.

Related: UK Policing White Paper: 50+ FR Vans | Norfolk & Merseyside FR Expansion

Sources: [6] Biometric Update, [7] The Register

Chrome's Fourth Zero-Day of 2026 Could Deliver Surveillance Payloads

Google patched CVE-2026-5281 on April 1: a use-after-free vulnerability in Dawn, Chrome's WebGPU implementation. It's actively exploited in the wild. It's the fourth Chrome zero-day this year [8].

Why this matters for surveillance: This isn't a standalone exploit. CVE-2026-5281 is part of an exploit chain. An attacker first compromises the renderer process through a separate vulnerability, then uses this Dawn bug to escape Chrome's sandbox. The end result: full system access via a crafted HTML page [9].

That's the exact delivery mechanism for commercial spyware. Companies like NSO Group, Paragon, and Intellexa use browser exploit chains to deploy zero-click surveillance tools. Visit a webpage (or get redirected to one), and your device is compromised. No interaction required beyond loading the page.

Timeline:

  • April 1: Google patches Chrome versions before 146.0.7680.177/178
  • April 1: CISA adds to Known Exploited Vulnerabilities catalog
  • April 15: Federal agencies must patch (4 days from now)

Four Chrome zero-days in four months. Every one of them actively exploited before Google could patch. Browser security is in a losing arms race.

What to do: Update Chrome now. Check chrome://settings/help for version 146.0.7680.177 or later.

Related: Our Full Coverage

Sources: [8] The Hacker News, [9] SOCRadar

Immigration Software Breach: 116,000 Passport Numbers, SSNs, Asylum Files

DocketWise (a cloud-based case management system used by thousands of immigration law firms across the US) disclosed a breach affecting 116,666 people. The exposed data includes passports, Social Security numbers, financial accounts, medical records, and full asylum case files [10].

How it happened: On September 1, 2025, an attacker used valid credentials to clone third-party partner repositories containing a data migration pipeline. That pipeline held unstructured data from law firms, including their clients' most sensitive information. DocketWise didn't discover the breach until February 19, 2026. They didn't notify anyone until April 3 [11].

Think about what's in an immigration case file: country of origin, persecution claims, family member identities, home addresses in potentially dangerous countries. For asylum seekers, this data isn't just personally identifiable, it's life-threatening if it reaches the wrong hands.

DocketWise is offering 24 months of credit monitoring through IDX. Enrollment deadline: July 3, 2026. Edelson Lechtzin LLP is investigating a class action [12].

Related: Our Full Coverage

Facial Recognition Wrongful Arrests Hit 13 Case Dismissals

Angela Lipps, a 50-year-old Tennessee grandmother, spent more than five months in jail after Clearview AI matched her face to a bank fraud suspect in North Dakota, a state she says she'd never visited [13].

She was arrested on July 14, 2025 while babysitting. The West Fargo Police Department used Clearview AI to generate the match. Investigators later proved it was wrong.

Lipps is now the latest victim in a pattern that AI watchdogs say is accelerating. NBC News reports at least 13 case dismissals nationwide linked to facial recognition misidentification [14]. A Reno casino's system flagged an innocent man as a "100% match." In nearly every known wrongful arrest case, the person falsely identified was Black.

The technology misidentifies Black people and people of color at significantly higher rates than white people. Police departments keep using it anyway. Most have no formal policies governing how facial recognition results should be treated as evidence. No training requirements. No mandatory human review before arrest.

Related: Angela Lipps Full Story | Wrongful Arrests Roundup | RSAC Meta Glasses FR Demo

Sources: [13] CNN, [14] NBC News

Quick Hits

  • New York Senate passed the Facial Recognition Technology Study Act (S3699). Senator James Sanders Jr.'s bill creates a task force to study facial recognition use across New York and recommend regulations. It joins a wave: Virginia's FR law takes effect July 1, and 20+ states now have privacy laws on the books [15]. Related: NYC FR Ban Bills
  • EU Digital Omnibus draws Amnesty International fire. Amnesty published a scathing analysis on April 10 calling the Commission's proposed GDPR/AI Act "simplification" a rollback of digital rights shaped by Big Tech lobbying. The omnibus would let companies use personal data for AI training as "legitimate interest" and delay high-risk AI rules by 16 months [16]. Our Analysis
  • OneDigital HR firm breach exposed 28,000 SSNs. Breach notification letters went out around April 8. ClassAction.org attorneys are investigating. If you used OneDigital for benefits enrollment, check your mail [17].
  • Space Force awarded $1.8 billion for GEO surveillance satellites. The "Andromeda" program selected 14 companies to compete for contracts monitoring activity in geosynchronous orbit [18].
  • Alabama unanimously passed consumer privacy legislation. The opt-out bill includes child protections, adding Alabama to the growing list of states with data privacy laws [19].

What to Watch

Next 9 days:

  • April 15: CISA deadline for federal agencies to patch Chrome CVE-2026-5281
  • April 20: FISA Section 702 sunset. Either Congress acts, or warrantless surveillance authority lapses. Nine days.

Coming up:

  • April 22-24: Elevate 2026 GRC conference (Atlanta): watch for privacy announcements
  • May 4: EU CSAR trilogue negotiations resume: the permanent chat scanning regulation is still alive
  • May 4: Meta's $375M New Mexico verdict enters Phase 2
  • July 1: Virginia Facial Recognition Law takes effect
  • August 2: EU AI Act full enforcement (unless the Omnibus delays it)

References

  1. Nextgov/FCW - Former National Security Officials Urge Congress to Renew Section 702
  2. Nextgov/FCW - Judge Renews 702 Surveillance Procedures
  3. Washington Times - Congress Faces Showdown Over Warrantless Surveillance Law
  4. Click on Detroit - Oakland County Flock Drone Surveillance
  5. Fox 2 Detroit - Oakland County Approves Flock Drone Pilot
  6. Biometric Update - UK Knife Crime CCTV and Facial Recognition Strategy
  7. The Register - UK to Spend £15M on AI Mapping in Knife Crime Crackdown
  8. The Hacker News - Chrome Zero-Day CVE-2026-5281
  9. SOCRadar - CVE-2026-5281 Chrome WebGPU Zero-Day Analysis
  10. ClassAction.org - DocketWise Data Breach
  11. DataBreaches.net - Immigration Law Firm Data Incidents
  12. PR Newswire - Edelson Lechtzin LLP Investigates DocketWise
  13. CNN - Angela Lipps AI Facial Recognition Wrongful Arrest
  14. NBC News - Facial Recognition Policing Errors on the Rise
  15. NY Senate - Facial Recognition Technology Study Act
  16. Amnesty International - EU Simplification Laws Roll Back Digital Rights
  17. ClassAction.org - OneDigital Data Breach
  18. SpaceNews - Space Force $1.8B GEO Surveillance Program
  19. CPPA - Alabama Privacy Legislation

Last updated: April 11, 2026