Today in Surveillance:
- ICE plans to pay LexisNexis $6.7 million for a 82-billion-record database that feeds Palantir. The procurement documents, reported by 404 Media on August 10, require the database to API into Palantir, support an AI-driven identity-inference system, and perform bulk facial recognition against large-scale image sources [1][2].
- Norman, Oklahoma's mayor walked a full nine-member vote to a unanimous no on Flock. Mayor Stephen Tyler Holman told 404 Media that every member of the council voted against the ALPR contract after two years of public debate over retention, data sharing, and surveillance scope [3][4].
- Wetherspoons told Meta Ray-Ban wearers to switch off their cameras. The UK pub chain stopped short of an outright ban and the UK Information Commissioner's Office opened a probe into Meta's cross-border footage flow after Kenyan reviewers reported seeing intimate moments from wearers [5][6].
- A long-dormant flaw in Apple's iCloud Private Relay is exposing users' real IP addresses. 404 Media's August 5 investigation found that issues in the browser engine underlying every iOS browser let a malicious site, or many ordinary sites incidentally, capture the IP address Private Relay was supposed to hide [7][8].
- Framework confirmed a Metabase zero-day hit customer data across all orders. The laptop maker told TechCrunch the breach affected all customers after Metabase discovered the attack on August 3 and notified Framework at 9 a.m. Pacific on August 6 [9][10].
- EFF urged the Senate to vote no on four internet bills. The Electronic Frontier Foundation lined up against KOSA, the SCREEN Act, the Youth AI Privacy Act, and the CHATBOT Act, citing age-verification databases, expanded surveillance, and one-size-fits-all parenting rules [11][12].
- EFF called on Meta to stop silencing reproductive-health content. EFF's public comment to Meta's Oversight Board catalogued Instagram restrictions on the Miscarriage and Abortion Hotline, Red River Women's Clinic, and Emory's RISE research center [13][14].
- Levi Strauss disclosed a voice-phishing breach of three employees. The 8-K filing dated August 7 described "certain corporate information" as taken. Google's Mandiant tracks the broader cluster as UNC6671, which Reuters says targeted more than 200 organizations in five weeks [15][16].
Also today: Mark Zuckerberg's 6,500-word "personal superintelligence" essay drew a 404 Media rebuttal for treating AI-agent ubiquity as inevitable while ignoring current agent-enabled harms [17][18]. Knightscope's pivot back to human guards made the case that the "roboguard revolution" is short-circuiting [19]. DEF CON's Franklin project launched a Water Watch Center funding managed-security providers for the roughly 150,000 US water utilities serving fewer than 10,000 people, with The Register noting suspected Iranian targeting of small water systems as the backdrop [20]. The Register reported North Korean Kimsuky operators running local LLMs to draft phishing and malware offline [21]. The Royal Navy's Kraken unmanned surface vessels were caught phoning home to a Chinese IP address during a routine cyber-vulnerability sweep, sending a camera "heartbeat" to a third-party-supplier endpoint [22].
ICE Plans to Spend $6.7 Million on LexisNexis Records to Feed Palantir
Immigration and Customs Enforcement plans to pay LexisNexis $6.7 million for continued access to commercial records the agency intends to pipe into Palantir systems, according to procurement records 404 Media published on August 10. LexisNexis's LexID and Accurint Virtual Crime Center draw on more than 82 billion public and proprietary records from more than 10,000 sources, the company's website says. The procurement documents say the data is to support "all aspects of ICE screening and vetting, lead development, and criminal analysis activities," including identifying what ICE perceives as fraud "before crime and fraud can materialize" [1][2].
The most consequential requirement is structural. The procurement document specifies that "the database must be able to application programming interface (API) with ICE applications, such as but not limited to, Palantir platform, PenLink, and ICE Data Analytics." PenLink is the social-media monitoring vendor 404 Media has previously reported on, including its Webloc tool for tracking mobile phones in entire neighborhoods. Palantir's role is to be the integration layer. Whether the LexisNexis pipeline lands in ELITE specifically, the Palantir-built "Enhanced Leads Identification & Targeting for Enforcement" system that maps potential deportation targets with a confidence score, is not clear from the record [1][2].
The same procurement adds two capabilities that read like the rest of the day's headlines. It requires "an artificial intelligence (AI) driven identification system" that can "infer the identity of the end user." It also requires a facial recognition system that draws on "large-scale image databases to perform high accuracy facial matching across diverse sources, including open-source media" and do it in bulk. LexisNexis, Palantir, and ICE did not immediately respond to requests for comment. 404 Media reported ICE arrested more than 51,000 people in July, many at airports [1][2].
This is a commercial data broker turned into an immigration-enforcement backbone. The LexisNexis product is a service law enforcement agencies have used for years to link data points together. The new piece is the mandate to do it inside Palantir, at the scale of bulk matching, with an AI identity-inference layer on top. The data is no longer about a specific person of interest. It is about who the inference says the person is. Read the DHS Palantir shopping-spree vessel and the ICE ImmigrationOS Palantir vessel for the procurement history that led here.
Norman, Oklahoma's Mayor Walked Nine Council Members to a Unanimous No on Flock
Mayor Stephen Tyler Holman told 404 Media on August 10 that every member of Norman's nine-member city council voted against the proposed Flock Safety automatic license-plate-reader contract, after two years of public debate over retention periods, drone cameras, and what surveillance does to a town. The Cleveland County Sheriff's Office had installed 20 Flock cameras countywide, but the city vote was separate [3][4].
Holman's framing is direct. He told 404 Media that Flock "gather[s] data on every single car vehicle that goes in and out," and that "30 days seemed like a long time to sit on that much data." Asked about the worst-case surveillance deployment, he asked: "what life are we living then." On data retention, he said some of it "should only be an hour. Thirty minutes." On whether opposing Flock is a partisan position, Holman said: "It is neither liberal nor conservative. In Norman it is a big deal and people can lose re-election." The previous mayor lost re-election to Holman, with the Bearcat armored vehicle purchase Holman ran against having earlier passed 5-4 [3][4].
The mechanics matter. A unanimous nine-member council vote is the cleanest possible local outcome, and Holman's walk-through is the playbook other cities have asked for. The pattern here tracks the existing Flock Safety cancel wave and the DeFlock revolt vessel. The political lesson is that opposition works when the data-retention question is on the table, and a sitting mayor can carry it.
Wetherspoons Told Meta Ray-Ban Wearers to Switch Cameras Off
Wetherspoons, the UK pub chain, told customers wearing Meta Ray-Ban smart glasses to switch the cameras off, the company's spokesperson told The Register. The full quote: "Meta glasses seem to breach this code, and common sense, by enabling surreptitious surveillance, so our instinct is to say turn off the cameras." The chain declined to say whether someone who refuses would be ejected, and it already polices audible playback of phone video. Recording, not wearing, is what draws the line [5][6].
Other UK venues have moved faster. DEF CON 2026, held the week before the article, told delegates to pack "non-violating eyewear." Monopoly Events, which runs UK Comic Cons, has banned the devices. Scottish ferry operator CalMac temporarily suspended unplanned bridge visits after a June crossing. Restaurateur Jeremy King's venues (Arlington, The Park, Simpson's in the Strand) ban them, as do Soho House, Brighton's Yellow Book Bar, and ATG and Trafalgar Entertainment theatres [5].
The other half of the story is the UK Information Commissioner's Office probe into Meta's cross-border footage flow. Kenyan reviewer teams reported seeing wearers' more intimate moments. The investigation closes a loop this publication has covered on the US side, where the Meta Kenya contractors lawsuit and the EDPB Kenya-scandal vessel are still active. Read the Meta Ray-Ban class-action vessel for the US track.
Apple Private Relay Is Exposing Real IP Addresses Through iOS Browsers
404 Media reported on August 5 that a series of issues in the browser engine underlying every browser on iOS means Apple's iCloud Private Relay, which is supposed to hide a user's IP address, often does not. The result: a malicious site can be set up to learn a Private Relay user's real IP address, and many ordinary websites have already collected this information incidentally. The same issues impact OnionBrowser, the iOS app that routes through the Tor anonymity network, the researchers told 404 Media [7][8].
404 Media verified the issues do expose IP addresses. The article references a prior 404 Media report that Apple's Hide My Email feature was revealing real email addresses through a bug Apple had known about for more than a year before fixing it. Private Relay is a paid privacy feature. The failure mode here is not "the user did something wrong"; it is "the service did not do what it was sold to do." The product sits in the lane of our "Apple Private Relay vs VPN" comparison guide. The technical reader question is which browser engine issues trigger the leak, and 404 Media's coverage of iOS-specific browser behavior is the thread to watch [7][8].
Framework Lost Customer Data to a Metabase Zero-Day. They Say It Hit Every Order.
Framework told TechCrunch a previously unknown vulnerability in Metabase versions 1.58 and later let an attacker inject arbitrary SQL against its analytics database. Metabase discovered the attack on August 3, 2026, and notified Framework at 9 a.m. Pacific on August 6. Framework's statement to TechCrunch: the breach affected "all customers" [9][10].
The exposed data per The Register: names, email addresses, phone numbers, physical addresses, login IP addresses, and, for business customers, company names, phone numbers, VAT or Employer Identification Numbers (EINs), and billing email addresses. Framework said order and payment details were not affected. Framework told customers: "We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors." Metabase blocked the attack endpoints, patched the bug, and deployed the fix across its cloud service. Framework rotated credentials for every database connected to its Metabase instance and engaged a third-party forensics firm. The company noted that names, email addresses, phone numbers, and physical addresses do not cross mandatory reporting thresholds in many regions, but it is notifying regulators where required and alerting customers regardless [9][10].
The structural lesson is the analytics vendor as the breach. A privacy-focused laptop maker that controls its hardware supply chain still runs its operations dashboards on a third-party analytics tool. The compromise at the analytics vendor becomes a compromise of every customer record the analytics tool can reach. The supply-chain side of the DHS Palantir shopping-spree vessel is the same pattern at a different scale.
EFF Lined Up Against Four Senate Internet Bills
The Electronic Frontier Foundation's India McKinney argued on August 4 that the four bills the Senate Commerce Committee was set to vote on the week of August 5, 2026, all push the internet in the wrong direction. The package: KOSA, the SCREEN Act, the Youth AI Privacy Act, and the CHATBOT Act. EFF's specific objections, by bill [11][12].
KOSA creates age-verification databases that link a real person to specific platform activity, the same structural point our age-verification coverage has made since 2025. The SCREEN Act expands that reach beyond adult websites. The Youth AI Privacy Act creates a "privacy paradox" by mandating parental monitoring that itself becomes surveillance of the family. The CHATBOT Act forces what EFF calls "one parenting model" on every family. EFF's framing: "create sweeping new privacy and data security problems, and force platforms to adopt unconstitutional restrictions." The committee vote advanced the bills on August 5 per the EFF post's update note [11][12].
The through-line is identity verification as the surveillance prize. Each bill solves a perceived child-safety problem by forcing a real-world identity check, and each identity check creates a database that links the verified person to the platform activity the check was meant to gate. Read the EFF action at act.eff.org/campaign/167270 and our KOSA vessel for the long arc.
EFF to Meta: Stop Silencing Reproductive-Health Content
EFF staff Jennifer Pinsof and Jillian C. York filed a public comment to Meta's Oversight Board on August 10 arguing that Meta's moderation systems routinely conflate discussion of reproductive-health medication with prohibited drug transactions, suppressing legitimate content like abortion care information, educational posts, and personal medical experiences. The Miscarriage and Abortion Hotline had its Instagram account restricted and posts removed. Red River Women's Clinic and Emory's RISE research center had accounts locked after posting about mifepristone. EFF's "Stop Censoring Abortion" project collected nearly 100 submissions documenting the censorship [13][14].
EFF's five demands: publish clear, understandable policies; enforce rules consistently and fairly; provide meaningful explanations for enforcement decisions; create a functional appeals system not dependent on insider access; and expand human review for sensitive healthcare and political content. The speech-and-data angle pairs with the data broker loophole explainer and the recurring reproductive-privacy cluster.
Levi Strauss Disclosed a Voice-Phishing Breach. The Cluster Is Broader.
Levi Strauss filed an 8-K dated August 7, 2026 describing a breach of "certain corporate information" after attackers used social engineering to access three employees' work computers. The company activated incident response, brought in outside cybersecurity experts, and cut off the unauthorized access. Consumer data does not appear to be affected, and operations were not disrupted. There is no confirmation that UNC6671 was behind the Levi's intrusion, and the company has not disclosed whether extortion was attempted or what exactly was taken [15][16].
UNC6671 is the Google Mandiant-tracked umbrella group Reuters reports was behind a campaign that targeted more than 200 organizations over five weeks. The pattern: voice phishing on personal mobiles, impersonation of colleagues or IT support, and direction to spoofed login pages that harvest credentials and MFA codes. The Levi's disclosure is a single data point in a much wider wave; the takeaway is that voice phishing is the entry vector of the moment for corporate IT, and the bulk of the public reporting is still catching up to the scale of the campaign [15][16].
What to Watch
Whether Palantir, LexisNexis, or ICE respond to the procurement-record disclosures. 404 Media reported all three "did not immediately respond." The first formal statement will set the public framing of the pipeline [1][2].
The other Norman-style council votes. Norman is the ninth-council headline. Watch Berkeley, Denver, and the cities in the Flock cancel wave for the next unanimous or near-unanimous vote [3][4].
The UK ICO probe into Meta's Kenya footage flow. A formal statement of reasons or a regulatory action is the next milestone. Until then, the venue-by-venue ban list is the operational enforcement layer [5][6].
Apple's fix for the Private Relay IP leak. 404 Media's reporting sits on iOS browser-engine behavior, which means the fix may not be a single setting toggle. Watch the next iOS update for an engine-level change and the first independent confirmation [7][8].
Senate floor votes on KOSA, SCREEN, Youth AI Privacy, CHATBOT. The committee advanced them. The full Senate vote is where the identity-verification and one-size-fits-all-parenting arguments get a public airing [11][12].
The Metabase fix in the wild. Framework's statement is that the fix is deployed in the cloud service. Watch for independent confirmation that the patched version is what the broader market is running [9][10].
Sources
- 404 Media, Joseph Cox: ICE to Pay LexisNexis Millions for Data to Feed to Palantir (August 10, 2026). https://www.404media.co/ice-to-pay-lexisnexis-millions-for-data-to-feed-to-palantir/
- State of Surveillance: ICE Buys LexisNexis Records to Feed Palantir, the briefing on the procurement pipeline and the AI identity-inference requirement. /news/dhs-billion-dollar-palantir-ai-surveillance-shopping-spree-2026
- 404 Media: The Mayor Who Said No When Flock Came to Town (August 10, 2026). https://www.404media.co/the-mayor-who-said-no-when-flock-came-to-town/
- State of Surveillance: Norman Unanimously Rejects Flock, the brief on the council vote and the mayoral playbook. /news/flock-safety-cancel-wave-30-cities-alpr-surveillance-contracts-2026
- The Register, Connor Jones: Wetherspoons bars smart glasses from filming customers (August 10, 2026). https://www.theregister.com/personal-tech/2026/08/10/wetherspoons-bars-smart-glasses-from-filming-customers/5285357
- State of Surveillance: Wetherspoons Tells Meta Ray-Ban Wearers to Switch Cameras Off, the brief on the UK pub chain stance and the ICO probe. /news/meta-ray-ban-smart-glasses-class-action-privacy-march-2026
- 404 Media, Joseph Cox: Apple's "Private Relay" Is Exposing Users' Real IP Addresses (August 5, 2026). https://www.404media.co/apples-private-relay-is-exposing-users-real-ip-addresses/
- State of Surveillance: Apple Private Relay vs a Real VPN, the brief on the IP-leak mechanic and the iOS browser-engine issue. /news/apple-private-relay-vs-vpn-leak-2026
- The Register, Carly Page: Framework loses customer data in Metabase zero-day attack (August 10, 2026). https://www.theregister.com/personal-tech/2026/08/10/framework-loses-customer-data-in-metabase-zero-day-attack/5285302
- State of Surveillance: Framework Metabase Zero-Day Hit Every Order, the brief on the SQL-injection attack and the supply-chain pattern. /news/framework-metabase-zero-day-2026
- EFF Deeplinks, India McKinney: Senate Vote Tomorrow: Four Internet Bills, One Wrong Direction (August 4, 2026). https://www.eff.org/deeplinks/2026/08/senate-vote-tomorrow-four-internet-bills-one-wrong-direction
- State of Surveillance: EFF Lines Up Against Four Senate Internet Bills, the brief on KOSA, SCREEN Act, Youth AI Privacy, and CHATBOT. /news/kosa-kids-online-safety-act-2026-child-protection-censorship
- EFF Deeplinks, Jennifer Pinsof and Jillian C. York: Meta Must Stop Silencing Reproductive Health Information (August 10, 2026). https://www.eff.org/deeplinks/2026/08/meta-must-stop-silencing-reproductive-health-information
- State of Surveillance: EFF Calls on Meta to Stop Silencing Reproductive Health Content, the brief on the Miscarriage and Abortion Hotline, Red River Women's Clinic, and Emory RISE cases. /news/meta-smart-glasses-kenya-contractors-intimate-footage-lawsuit-2026
- The Register: Attackers pick Levi's pockets in social engineering attack (August 10, 2026). https://www.theregister.com/security/2026/08/10/attackers-pick-levis-pockets-in-social-engineering-attack/5285401
- State of Surveillance: Levi Strauss Discloses Voice-Phishing Breach of Three Employees, the brief on UNC6671 and the broader campaign. /news/levi-strauss-voice-phishing-breach-unc6671-2026
- 404 Media, Jason Koebler: Mark Zuckerberg Posts "Deranged" 6,500-Word Essay About Giving Everyone AI Superintelligence (August 10, 2026). https://www.404media.co/mark-zuckerberg-posts-deranged-6-500-word-essay-about-giving-everyone-ai-superintelligence/
- State of Surveillance: Zuckerberg's 6,500-Word Superintelligence Essay, the brief on the personal-AI-agent vision and the agent-enabled harms. /news/mark-zuckerberg-supersmart-6500-essay-2026
- 404 Media: The Roboguard Revolution Is Short-Circuiting (August 10, 2026). https://www.404media.co/the-roboguard-revolution-is-short-circuiting/
- The Register: DEF CON hackers add new muscle to water-utility protection (August 10, 2026). https://www.theregister.com/security/2026/08/10/def-con-hackers-add-new-muscle-to-water-utility-protection/5285715
- The Register: North Korean spies are running local LLMs to cause AI mischief (August 10, 2026). https://www.theregister.com/security/2026/08/10/north-korean-spies-are-running-local-llms-to-cause-ai-mischief/5285632
- The Register: Royal Navy drones caught sending data to China during cyber-vulnerability sweep (August 10, 2026). https://www.theregister.com/edge-and-iot/2026/08/10/cyber-vulnerability-sweep-picks-up-royal-navy-drones-sending-data-to-china/5285430