Security surveillance cameras mounted on a concrete wall
Photo via Unsplash

Today in Surveillance:

  • FISA 702, take three. Mike Johnson unveiled another reauthorization bill on April 24, three-year extension, no warrant requirement, "penalties for abuse" that restate existing law. The April 30 deadline is four days away.
  • Massie and Boebert want warrants for everything. The Surveillance Accountability Act (H.R. 8470) would ban warrantless facial recognition, license plate tracking, and location data purchases by federal agencies.
  • Bitwarden CLI got backdoored. A supply chain attack compromised the password manager's CLI tool for 90 minutes on April 22. Malware targeted developer secrets, GitHub tokens, and even AI coding tool credentials.
  • UK court says police facial recognition is fine. The High Court ruled the Met Police's live facial recognition system is lawful. The government plans to expand from 10 to 50 facial recognition vans.
  • Lovable exposed every project for 48 days. The vibe-coding platform left source code, database credentials, and customer data accessible to any authenticated user.

Johnson's Third Swing at FISA 702: Same Bat, No Warrant

Four days. That's what's left before Section 702 of the Foreign Intelligence Surveillance Act expires on April 30. And Speaker Mike Johnson is hoping the third time's the charm [1].

After two failed House votes, a five-year extension crushed by 20 Republicans who sided with Democrats, and a shorter version that also collapsed. Johnson unveiled a new bill on April 24. It extends Section 702 for three years. It includes "criminal penalties for willful abuse." It requires the FBI to submit monthly explanations for querying Americans' data.

What it doesn't include: a warrant requirement.

That's the line in the sand. The bill lets FBI agents search Americans' communications collected under 702 without going to a judge. Elizabeth Goitein of the Brennan Center called it "a straight reauthorization with eight pages of words" [2]. Rep. Jamie Raskin (D-MD) put it more bluntly: agents can still "collect, search, and review Americans' communications without any review from a judge."

Even among Republicans, it's not a done deal. Rep. Scott Perry (R-PA) told reporters "we're not there yet," demanding stronger accountability measures. Trump, meanwhile, posted that he's "willing to risk the giving up of my Rights...for our Great Military", a remarkable statement from someone the FBI surveilled using FISA in 2016.

The House Rules Committee is expected to advance the bill early next week. If it passes, the Senate would need to act before April 30 or the program lapses.

Related: Johnson's Third Attempt: Full Analysis | Vote Stalls, Trump Summons Holdouts

Massie-Boebert Bill: If You Want to Surveil Americans, Get a Warrant

While Johnson was recycling the same reauthorization, Reps. Thomas Massie (R-KY) and Lauren Boebert (R-CO) went the other direction entirely. On April 23, they introduced the Surveillance Accountability Act (H.R. 8470), a bill that would require warrants for all government surveillance [3].

What it does:

  • Mandates judicial warrants based on probable cause for all government surveillance
  • Bans warrantless facial recognition in public spaces, schools, and places of worship
  • Blocks automated license plate readers from building persistent location databases without court orders
  • Prohibits federal agencies from purchasing commercial location data to dodge warrant requirements
  • Lets government employees be sued personally for privacy violations

"The Bill of Rights is not a suggestion," Massie said at a joint press conference streamed on C-SPAN. Boebert added: "For years, the federal government has treated the Fourth Amendment like a suggestion."

Massie indicated he's considering a discharge petition to bypass House leadership and force a floor vote. That's a bold move, discharge petitions need 218 signatures and are rarely successful. But with Johnson's warrantless FISA extension drawing fire from both flanks, the timing is strategic.

The bill directly targets the data broker loophole that lets agencies like ICE buy Americans' location data from commercial brokers instead of getting a warrant. It's the same loophole the EFF's "Google Broke Its Promise" story exposed in the ICE context.

Related: Surveillance Accountability Act: Full Coverage | Google's Broken Promise to ICE Data Subject

Bitwarden CLI Backdoored for 90 Minutes

Your password manager's command-line tool was compromised on April 22. For 90 minutes, anyone who installed @bitwarden/[email protected] from npm got malware instead of a password manager [4].

The attack was part of a broader supply chain campaign targeting the Checkmarx ecosystem. Here's how it worked: attackers compromised a GitHub Action in Bitwarden's CI/CD pipeline, injected a malicious payload into the npm package, and published it with Bitwarden's own metadata intact. The rogue package contained a file called "bw1.js" that ran via a preinstall hook, before you even used the tool, it was already stealing.

What it stole:

  • Developer secrets and environment variables
  • GitHub tokens and SSH keys
  • Shell history
  • Credentials for AI coding tools (Claude, Cursor, Aider, Codex CLI)

The stolen data was encrypted with AES-256-GCM and exfiltrated to "audit.checkmarx[.]cx" and backup GitHub repositories. The malware also injected malicious GitHub Actions workflows into victim repos for persistent access, meaning one infected developer could compromise every downstream project their tokens touched.

Security firms JFrog, Socket, StepSecurity, OX Security, and Endor Labs all confirmed the compromise. Bitwarden says no end-user vault data was accessed and the malicious package was live for about 90 minutes before being pulled. A CVE has been issued [5].

If you used Bitwarden CLI between 5:57 PM and 7:30 PM ET on April 22: rotate every secret, token, and key on your machine. Now.

UK Court Greenlights Mass Facial Recognition

On April 21, the UK High Court dismissed a legal challenge to the Metropolitan Police's live facial recognition system, ruling it lawful and compatible with human rights [6].

The case centered on Shaun Thompson, an anti-knife crime youth worker who was falsely flagged as a criminal suspect by facial recognition cameras in Croydon. Big Brother Watch backed Thompson's case, arguing the tech violated privacy rights under the European Convention on Human Rights.

The court disagreed. Lord Justice Holgate and Mrs Justice Farbey found that the Met's facial recognition policy "does not authorise arbitrary decision-making, has sufficient clarity and foreseeability, and provides adequate safeguards against abuse."

Here's what makes this ruling dangerous: in January, the UK Home Office announced plans to increase facial recognition vans from 10 to 50 and deploy them to police forces across England and Wales. This ruling removed the last legal obstacle. Thompson says he'll appeal, but for now, the expansion is cleared for launch.

Meanwhile, across the Atlantic: 14 known wrongful arrests from facial recognition. Kimberlee Williams spent six months in jail because the software got it wrong. The technology keeps failing, and courts keep approving it.

Related: UK Ruling: Full Analysis

Lovable Left Every Project Wide Open for 48 Days

Lovable, the vibe-coding platform used by companies including Uber, Zendesk, and Deutsche Telekom, exposed every public project's source code, database credentials, AI chat history, and customer data to any authenticated user for 48 days [7].

Security researcher @weezerOSINT reported the Broken Object Level Authorization (BOLA) vulnerability through HackerOne on March 3. HackerOne labeled it a "duplicate submission" and left it open. Lovable did nothing. For 48 days.

When the researcher went public on April 20, Lovable's response was a masterclass in crisis mismanagement. First: it's "intentional behavior." Then: unclear documentation. Then: it's HackerOne's fault. Finally, CEO Anton Osika issued a public apology: "I take accountability." Lovable shipped a fix within two hours of the public disclosure, proving they could have fixed it seven weeks earlier.

The incident is a warning for the entire vibe-coding movement: AI-generated apps with AI-managed infrastructure still need human-level security review. And bug bounty programs that dismiss reports as "duplicates" are a liability, not a safeguard.

Related: Lovable Breach: Full Coverage

Quick Hits

  • Clarifai deletes 3 million OkCupid photos. The AI company certified to the FTC on April 7 that it deleted all 3 million facial recognition training photos it received from OkCupid in 2014, plus any models trained on them. No financial penalty, the FTC doesn't have authority to fine for this type of Section 5 violation [8]. Our Coverage
  • House Republicans introduced two federal privacy bills on April 22 that would preempt state privacy laws. If you're in California, that means CCPA protections could be watered down by a federal floor [9].
  • Vermont debates data broker regulation. The Senate Economic Development Committee is weighing whether a new data broker bill is too broad, with industry lobbyists pushing for exemptions [10].
  • Apple macOS Tahoe 26.4.1 shipped April 9 with security patches targeting social engineering and fake update attacks. If you haven't updated, do it now [11].

What to Watch

This week:

  • April 28-30: EDUCAUSE Cybersecurity & Privacy Conference (Anaheim)
  • April 30: FISA Section 702 expiration deadline. Johnson's bill needs to pass both chambers in four days or the program lapses.
  • April 30: Conduent breach credit monitoring signup deadline

Coming up:

  • May 4: EU CSAR trilogue negotiations resume. This is the permanent chat-scanning law. Voluntary scanning expired April 3, but Big Tech companies are still doing it anyway.
  • May 4: Meta New Mexico $375M verdict Phase 2 begins

References

  1. NPR - After 2 Failed Votes, Johnson Unveils New Plan to Extend U.S. Spy Powers (April 24, 2026)
  2. Washington Post - Warrant Requirement for FISA 702 Is a Good Compromise (April 23, 2026)
  3. Rep. Boebert - Surveillance Accountability Act Press Release (April 23, 2026)
  4. The Hacker News - Bitwarden CLI Compromised in Checkmarx Supply Chain Campaign (April 2026)
  5. Bitwarden - Statement on Checkmarx Supply Chain Incident
  6. The Register - High Court Approves Met Police Facial Recognition (April 22, 2026)
  7. The Next Web - Lovable Security Crisis: 48 Days of Exposed Projects
  8. TechCrunch - Clarifai Deletes 3M OkCupid Photos After FTC Settlement (April 21, 2026)
  9. California Privacy Protection Agency - Announcements
  10. SecureMac - Apple macOS Security Update, April 2026
  11. SecureMac - Apple macOS Tahoe 26.4.1 Update

Last updated: April 26, 2026