Today's Top Stories:
- Meta's facial recognition deadline is here. Senators Markey, Wyden, and Merkley gave Zuckerberg until today to explain facial recognition plans for smart glasses. Over 60 groups oppose it. Meta hasn't said a word.
- The White House app is a surveillance sandwich. Security researchers found Huawei SDK code, Russia-founded analytics, and an ICE tip line in Trump's new app. 700,000 downloads in the first week. No privacy disclosures.
- North Korean hackers hijacked Axios. Google attributed the npm supply chain attack to DPRK group UNC1069. The library gets tens of millions of weekly downloads. Malicious code was live for three hours.
- Maine's privacy bill is dead. Corporate lobbying from L.L. Bean and Hannaford flipped five Democrats. The 68-80 House vote killed one of the strongest state privacy proposals in the country.
- FISA 702: 14 days to sunset. Congress is on recess. The clock is ticking.
- Nissan's data is on the dark web. Everest ransomware gang dumped 900GB after Nissan refused to pay. Up to 2.5 million customers affected.
Deadline Day: Meta Owes Congress Answers on Facial Recognition Smart Glasses
Today is the day. Senators Edward Markey (D-Mass.), Ron Wyden (D-Ore.), and Jeff Merkley (D-Ore.) gave Meta CEO Mark Zuckerberg until April 6 to answer pointed questions about the company's plans to add facial recognition to Ray-Ban smart glasses [1].
The questions aren't soft. The senators want to know whether people scanned by someone else's glasses can request deletion of their biometric data. Whether Meta is training machine learning models on facial recognition data. Whether the company has conducted privacy impact assessments. Whether biometric data gets shared with law enforcement. And how exactly Meta plans to get consent from the thousands of people a glasses wearer could scan in a single day [2].
More than 60 civil society groups (led by the Consumer Federation of America and UltraViolet Action) already sent letters to Meta, EssilorLuxottica, the White House, the FTC, and the DOJ calling the technology "a creepy and unacceptable escalation of surveillance" [3].
A leaked internal memo revealed Meta timed the facial recognition launch for a "dynamic political environment," banking on civil society being too distracted by other fights to organize. That calculation backfired spectacularly. The EFF published "Think Twice Before Buying Meta's Ray-Bans." Gizmodo called the calls to regulate "officially deafening." And a Swedish investigation found Meta subcontractors in Kenya labeling bathroom footage and sexual content to train AI [4].
As of this writing, Meta hasn't responded publicly. If the deadline passes in silence, expect the senators to escalate. But don't expect Meta to care much. The company has a long history of treating congressional requests like suggestions.
Related: 64 Groups Oppose Smart Glasses FR | Senator Deadline Coverage
The White House Built an App. It May Be Sending Your Data to China.
The Trump administration's new White House app hit 700,000 downloads in its first week. Security researchers hit the alarm button just as fast [5].
Multiple independent analyses found Huawei Mobile Services Core embedded in the app's code: components from the same Chinese company the U.S. government banned from federal networks for national security reasons. Security researcher Sam Bent confirmed the finding using Exodus Privacy tools. IBTimes and other outlets corroborated it [6].
But that's not all. Cybersecurity researchers at NOTUS and NowSecure found the app shares users' IP addresses, time zones, and device data with commercial third-party services without disclosure. The privacy manifest filed with Apple is blank. And the app incorporates a widget kit built by a Russia-founded software company whose own systems previously exposed staff data [7].
Then there's the ICE tip line. The app includes a button encouraging users to report "suspected criminal activity" that redirects directly to ICE's anonymous tip submission page. Bent described the combination (an app leaking data to Chinese servers while collecting immigration tips from Americans) as a "surveillance sandwich." You're monitored from both sides [8].
The White House says the app doesn't collect location data and has no Huawei integrations. The code says otherwise.
North Korean Hackers Hijacked One of the Internet's Most Popular Libraries
On March 31, Google's Threat Intelligence Group attributed a supply chain attack on the Axios npm package to UNC1069, a financially motivated North Korean hacking group. Axios gets downloaded tens of millions of times every week. Healthcare, finance, crypto, and government systems all depend on it [9].
The attack was textbook social engineering. Maintainer Jason Saayman says the attackers impersonated the founder of a legitimate, well-known company, cloning the person's likeness and the company itself. Once they had Saayman's trust, they compromised his npm account, swapped his email address to lock him out, and pushed two malicious versions of the package [10].
The backdoored code introduced a hidden dependency with a post-install script that automatically downloaded and executed additional payloads from attacker-controlled servers. The malicious versions were live for approximately three hours before detection [11]. It is the latest reminder that your vendors are the weak link.
Three hours doesn't sound like much. But Axios is installed millions of times per week. Any organization that ran npm install during that window could be compromised. Google tracked the attack to the same North Korean apparatus that stole $285 million from Drift Protocol on April 1 and continues looting LastPass breach victims. The pattern is clear: DPRK hackers are funding a surveillance state through crypto theft and supply chain attacks.
Corporate Lobbying Killed Maine's Privacy Bill
Maine's strict data privacy bill died on a 68-80 House vote on Thursday night, April 3. Five Democrats who previously voted yes flipped to no after a massive lobbying blitz from L.L. Bean, Hannaford, Bangor Savings Bank, and dozens of other businesses [12].
The bill, introduced by Rep. Amy Kuhn (D-Falmouth), would have created some of the nation's strictest limits on targeted online advertising and regulated the collection of personal data including race, religion, sexual orientation, gender identity, citizenship, and immigration status [13].
The defeat was engineered. Business groups organized a Tuesday letter campaign that flipped the critical votes. The bill had passed the House narrowly the previous week, helped by Republican absences. Once the full chamber showed up, the corporate money talked louder than constituent privacy [14].
Maine joins a growing list of states where privacy legislation dies in the face of industry pressure. The playbook is always the same: companies claim compliance costs are too high, lobby the swing votes, and kill the bill before it reaches the governor's desk. Meanwhile, 20 states have privacy laws. Maine isn't one of them.
Related: Maine Privacy Bill: Political Exemption Controversy
14 Days: The FISA 702 Clock Keeps Ticking While Congress Isn't Here
Section 702 expires April 20. Congress is on recess. Nobody is voting on anything [15].
The math hasn't changed since Friday. House GOP leadership wants a clean extension. Rep. Luna is holding out for the SAVE Act. 98 Progressive Caucus Democrats won't vote yes without warrant requirements and data broker loophole closure. The Government Surveillance Reform Act sits on the shelf [16].
The Deseret News published an op-ed on April 4 making the First Amendment case against surveillance: FBI conducted up to 3.4 million warrantless backdoor searches of Americans' communications in 2021. The Foreign Intelligence Surveillance Court found "persistent and widespread violations." Those queried included BLM protesters, donors to a congressional campaign, journalists, and crime victims [17].
Here's the thing about letting the clock run down: it's the strategy. Everyone who benefits from warrantless surveillance wants a last-minute vote where Congress has to choose between reforms and "letting America go dark." That framing has worked before. Whether it works again depends on whether 14 days is enough time for the reform coalition to hold together.
Related: Yesterday's FISA Analysis | PCLOB Independence Crisis | ODNI Transparency Report | FISA 702: The Math Doesn't Add Up
Quick Hits
- Nissan data dumped on the dark web. Everest ransomware gang followed through on its April 3 threat. 900GB of data from Nissan's dealer network: six years of customer records, auto loan data, repair orders. The gang claims 2.5 million people are affected. Root cause: unrotated, publicly exposed credentials with no multi-factor authentication. Our coverage [18]
- Facial recognition jailed an innocent grandmother for five months. Angela Lipps, 50, was arrested in Tennessee after Clearview AI matched her to bank fraud suspects in North Dakota, a state she'd never visited. Fargo PD never called to question her. She sat in jail 108 days before someone bothered to check. She lost her home, her car, and her dog. Charges dismissed Christmas Eve. Full story [19]
- Seventh Circuit caps BIPA damages retroactively. The April 1 ruling applies Illinois' 2024 amendment retroactively to all pending cases, capping damages at $5,000 per person instead of per-scan. One plaintiff's potential $7.5 million claim just became $5,000. The ruling doesn't bind Illinois state courts but reshapes hundreds of pending federal cases [20].
- Hasbro hit by cyberattack. The company told investors in an 8-K filing it may take "weeks" to recover. No word on whether data was stolen [21].
- COPPA compliance: 16 days. Updated children's privacy rules take effect April 22. Biometric identifiers (fingerprints, voiceprints, facial templates) are now classified as personal information under COPPA. If your platform touches kids' data, the clock is ticking.
What to Watch
- Today: Did Meta respond to the senators? If not, watch for escalation this week.
- April 8: House Judiciary subcommittee hearing on ATF's use of Clearview AI facial recognition on gun owners.
- April 20: FISA Section 702 sunset. 14 days. Congress returns from recess the week before.
- April 22: Updated COPPA Rule compliance deadline.
- May 4: EU CSAR trilogue resumes. Chat Control 2.0 negotiations after scanning framework expired April 4.
- Developing: Nissan breach fallout: class action lawsuits expected. How many of the claimed 2.5 million customers were actually affected?
- Developing: Axios supply chain attack blast radius. How many organizations installed the malicious package during the three-hour window?
References
- Senator Markey - Demand Transparency from Meta on Facial Recognition in Smart Glasses
- Senator Wyden - Demand Transparency from Meta on Facial Recognition in Smart Glasses
- Biometric Update - Meta facial recognition smart glasses plan sees increasing opposition
- Gizmodo - Calls to Regulate Smart Glasses Are Officially Deafening
- Washington Today - White House App Raises Alarm Over Potential Surveillance
- IBTimes - White House App Reportedly Shares User Data With Third Parties
- NOTUS - The White House App Is Riddled With Cybersecurity Vulnerabilities
- Sam Bent - The White House App Has Huawei Spyware and an ICE Tip Line
- TechCrunch - North Korean hackers blamed for hijacking popular Axios open source project
- The Hacker News - UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack
- Help Net Security - North Korean hackers linked to Axios npm supply chain compromise
- Bangor Daily News - Maine Democrats flip their votes to put far-reaching data privacy bill in doubt
- Portland Press Herald - Maine data privacy measure looks doomed after late-night House vote
- WABI - Data privacy bill fails on second House vote
- EPIC - FISA Section 702: Reform or Sunset
- Brookings - A key intelligence law expires in April and the path for reauthorization is unclear
- Deseret News - The First Amendment problem with government surveillance
- Cybernews - Everest ransomware gang turns up the heat on Nissan
- CNN - Police used AI facial recognition to arrest a Tennessee woman for crimes in a state she never visited
- Duane Morris - Seventh Circuit Holds BIPA Amendment Applies Retroactively
- This Week in Security - April 5, 2026 Edition
Last updated: April 6, 2026