Two bullet surveillance cameras mounted on a concrete wall
Photo via Unsplash

Today in Surveillance:

  • FISA 702: 48 hours to expiration. No deal. The Senate failed 47-52 on cloture last Friday. Democrats won't vote while Bill Pulte is acting DNI. Seven Republicans want a warrant requirement. Sens. Cotton and Grassley asked Rubio to plan a "fallback executive order." Even if the statute lapses Friday, FISA Court certifications keep collection running until March 2027. The expiration is political leverage, not an operational shutdown [1][2][3].
  • Democrats hold "Tracked and Targeted" hearing today. Ranking Member Bennie Thompson and Homeland Security Democrats are examining how the Trump administration has expanded surveillance, collected Americans' personal data, and targeted individuals for political retaliation. The hearing starts Wednesday morning [4].
  • Meta strips NameTag facial recognition from smart glasses app. Less than 48 hours after WIRED found the dormant code on June 4, Meta released an update removing it. EFF's Threat Lab had confirmed the code contained face detection, "Person recognized" alerts, and biometric signature storage. The code had shipped to millions of phones since January 2026 without any user notification [5][6][7].
  • Homan admits using facial recognition on Delaney Hall protesters. Border czar Tom Homan said federal investigators used FR and "other investigative tools" to identify anti-ICE demonstrators at the Newark detention facility, claiming facial recognition matched protesters to demonstrations in Portland and Minnesota [8][9].
  • Yoti age verification reportedly flags GrapheneOS users to authorities. A user trying to verify their age through Sony PlayStation's Yoti integration was told their device was "automatically reported to both the authorities and our security team" for running GrapheneOS. Yoti denies the claim, calling the screenshots fabricated. GrapheneOS called it "fearmongering" by a customer support agent making things up [10][11].
  • ServiceNow breach: two months of inaction, then an emergency patch. Attackers exploited an unauthenticated API endpoint to query customer data. ServiceNow knew about the flaw since April 7 and classified it "non-urgent." The emergency fix shipped June 5, three days after active exploitation began [12][13].
  • FTC fines Cox Media Group $930K for fake "active listening" service. Cox Media marketed an AI-powered service that claimed to listen through consumers' smart devices to target ads. It didn't listen to anything. The service was just repackaged email lists from data brokers, sold at a markup [14].

FISA 702: 48 Hours to Expiration. The Senate Has No Deal.

FISA Section 702 expires at midnight on Friday, June 12. The Senate has no path to reauthorization. The math has not changed since the 47-52 cloture vote on Friday, June 5 [1][2][3].

The three-way deadlock is simple: Democrats refuse to hand warrantless surveillance authority to Bill Pulte, a former Federal Housing Finance Agency director with zero intelligence experience who is serving as acting Director of National Intelligence. Seven Republicans (the same bloc that revolted Friday) want a warrant requirement before they vote yes. The Trump administration will not accept a warrant requirement and will not withdraw Pulte [1][2].

The new variable since Sunday: Sens. Tom Cotton (R-Ark.) and Chuck Grassley (R-Iowa) sent a letter to Secretary of State Marco Rubio asking the State Department to plan a "fallback executive order" for a "potential significant gap in foreign intelligence collection." That is Republican leadership openly preparing to bypass Congress on Section 702 [1][3].

The legal reality: an executive order cannot create new FISA Court certifications or extend existing ones. Those require statutory authority. What it can do is direct the intelligence community to continue collection under other authorities (Executive Order 12333, National Security Letters) with looser minimization rules. The "gap" Cotton and Grassley are planning for is a gap in oversight, not a gap in collection [1][2].

Here is the timeline for the rest of the week:

  • Today, June 10: Negotiations. Democrats' ultimatum is clear: remove Pulte or no vote. The White House is standing by Pulte and accusing Democrats of holding the spy power "hostage." House Minority Leader Hakeem Jeffries confirmed Democrats have coalesced behind the Pulte removal demand [3][4].
  • Thursday, June 11: Last realistic day for a clean vote. After this, the math forces either a weekend session or a last-minute short-term extension.
  • Friday, June 12: Statutory expiration. But the FISA Court's March 2026 certifications keep ongoing 702 collection running until March 2027. The "expired" headline is political, not operational. It is the lever that reformers have been building toward for two years [1][2].

Related: FISA 702: Senate Vote Fails 47-52 | What Actually Stops When FISA Expires | FISA 702: The Complete Guide

Democrats Hold "Tracked and Targeted" Hearing on Trump Surveillance State

Ranking Member Bennie G. Thompson (D-MS) and House Homeland Security Democrats are holding a hearing today titled "Tracked and Targeted: The Unconstitutional Surveillance State." The forum examines how the Trump administration has expanded government surveillance, collected Americans' personal data, and targeted individuals for political retaliation [4].

The timing is not coincidental. Two days before FISA 702 expires, Democrats are making the public case that handing warrantless surveillance tools to an administration that is already using facial recognition on protesters (see below) and running DOGE data grabs on Social Security records is a non-starter [4].

Thompson's framing: "The Trump Administration is expanding its surveillance powers with no real oversight. Congress has a responsibility to use its oversight and legislative power to shine a light on what's happening and protect Americans' Constitutional rights" [4].

Expert witnesses are discussing the dangers of a growing federal surveillance apparatus, its impact on citizens and lawful residents, and legislative solutions to safeguard civil liberties. This is the first formal congressional hearing to frame the DOGE data access, ICE facial recognition deployments, and FISA 702 reauthorization as parts of a single surveillance expansion [4].

Victory: Meta Strips Facial Recognition Code From Smart Glasses App

Meta removed the dormant NameTag facial recognition system from its Meta AI app on June 5, less than 48 hours after WIRED discovered the code on June 4. EFF is calling it a victory. It is one, with caveats [5][6][7].

The timeline matters. In January 2026, WIRED first reported that Meta had embedded facial recognition code in the companion app for its Ray-Ban smart glasses. EFF's Threat Lab confirmed the findings: the code contained face detection algorithms, "Person recognized" alert systems, and biometric signature storage that converted faces into 2,048-number faceprint arrays. All of it shipped to millions of phones without a word to users [5][6].

For six months, Meta sat on it. Then WIRED found it again on June 4 in a routine app update check, and the story went wide. By June 5, the code was gone. Meta VP of communications Andy Stone told WIRED the feature was "only a pilot effort" and that the company had not made "a final decision on what to do here, if anything" [6][7].

More than 75 advocacy groups had urged Meta to abandon the technology, warning that smart glasses with built-in facial recognition could become tools for harassment, tracking, and unwanted surveillance at scale [5].

The caveat: Meta can re-add the code at any time. The removal was a PR decision, not a policy commitment. The infrastructure to ship facial recognition to every Meta AI user still exists. The only thing that changed is public attention [5][6].

Related: EFF: Move Fast, Surveil Things

Homan Admits Using Facial Recognition to Track Delaney Hall Protesters

Border czar Tom Homan said on Fox & Friends Monday that federal investigators used facial recognition and "other investigative tools" to identify individuals at anti-ICE protests outside the Delaney Hall detention facility in Newark, New Jersey [8][9].

"We've got facial recognition of people from Portland, they're at Portland riots, and many from Minnesota. This is a well-planned, established thing they're doing," Homan said, claiming that most demonstrators were not New Jersey residents [8].

More than 80 people have been arrested following weeks of protests at Delaney Hall, where demonstrators showed up in solidarity with detainees who began a hunger and labor strike on May 22. Federal agents and protesters have clashed repeatedly outside the facility [9].

The admission is significant. Using facial recognition to identify and track people exercising their First Amendment rights at protests is exactly the kind of surveillance that the ACLU, EFF, and civil liberties groups have been warning about for years. Homan framed it as a law enforcement tool for identifying "rioters." Civil liberties organizations see it as proof that government FR is being used to chill political dissent [8][9].

This is happening the same day House Democrats hold a hearing called "Tracked and Targeted." The overlap is not subtle [4].

Use a Privacy Phone? This Age Verification Company Reportedly Flags You to Authorities

A user attempting Sony PlayStation's age verification through Yoti, a London-based identity verification company, received a customer support message stating that their device had been "automatically reported to both the authorities and our security team." The reason: they were running GrapheneOS, a privacy-focused open-source Android fork [10][11].

"These instances are automatically reported to both the authorities and our security team," read the alleged Yoti support message, which also stated the company flags "multiple verification attempts and any devices running GrapheneOS" [10].

The story gets complicated. Yoti denied the claims, saying they believe the screenshots of the exchange to be fabricated. "We would never report any user to the police or any other third party based on their choice of operating system or device," a senior Yoti representative said. GrapheneOS also pushed back, calling the support messages "fearmongering" and saying the customer support agent was "nearly certainly making it all up to get the person to go away so the ticket can be considered closed" [10][11].

True or fabricated, the story resonated because it reflects a real dynamic. Age verification systems treat privacy tools as suspicious. Yoti was fined $1.1 million by Spanish regulators in March 2026 for mishandling biometric data. The companies that build "child safety" infrastructure are the same companies collecting biometric data at scale, and the infrastructure they are building can be pointed at anyone, for any reason [10][11].

Yoti is used by Sony, Facebook, TikTok, and a growing list of platforms. If you use GrapheneOS, CalyxOS, or any hardened Android fork, age verification is going to be a recurring friction point. The broader question: should your choice of operating system be treated as a risk signal? [10][11]

Related: Age Verification as Surveillance Infrastructure | Yoti Fined $1.1M by Spanish Regulators

ServiceNow Breach: Known Since April, Exploited in June, Fixed After the Damage

ServiceNow confirmed that attackers exploited an unauthenticated API endpoint to query customer instance tables, accessing transaction records, names, and contact information. The company applied an emergency security update to hosted instances on June 5 [12][13].

The timeline is damning. ServiceNow documented the vulnerability internally on April 7 and classified it as "non-urgent," planning to fix it in a future release cycle. The root cause: a Scripted REST Resource shipped with requires_authentication set to false, meaning the endpoint accepted requests with no session, token, or credential check. Attacker activity began June 2-3, hitting the endpoint from a foreign IP [12][13].

ServiceNow is not a small company. It processes IT workflows for government agencies, Fortune 500 companies, and critical infrastructure operators. An unauthenticated API endpoint sitting open for two months, classified as "non-urgent," is the kind of negligence that turns routine vulnerabilities into headline breaches [12][13].

Affected customers were notified directly. If your organization uses ServiceNow, check whether you received a case notification and review your instance logs for the June 2-5 window [12].

FTC Fines Cox Media $930K for Faking an "Active Listening" AI Service

The FTC settled with Cox Media Group and two smaller marketing firms for a combined $930,000 over charges that they deceived customers by claiming to offer an AI-powered service that listened through consumers' smart devices to target localized ads [14].

The service, marketed as "Active Listening," did not listen to anything. It did not use voice data. It did not have access to consumers' microphones. What it actually did: repackage email lists bought from data brokers and resell them at a significant markup. Cox Media told potential customers that consumers had "opted in" by accepting app terms of service. The FTC said that clicking through mandatory terms of service does not constitute opt-in consent for voice surveillance [14].

Cox Media pays $880,000. MindSift and 1010 Digital Works pay $25,000 each. All three are barred from future misrepresentations about voice data collection, consumer consent, and geographic targeting [14].

The irony: for years, the "your phone is listening to you" theory has been a popular conspiracy. It turns out the companies claiming they could listen were lying about that too. They didn't need to listen. They already had your data from brokers [14].

Google Patches 124 Android Flaws, Including One Already Used for Targeted Surveillance

Google's June 2026 Android security bulletin patches 124 vulnerabilities, including CVE-2025-48595, a privilege-escalation flaw with a CVSS score of 8.4 that is under "limited, targeted exploitation" on Android 14, 15, and 16 devices [15].

CISA added CVE-2025-48595 to its Known Exploited Vulnerabilities catalog on June 2, requiring federal agencies to patch by June 5. "Limited, targeted exploitation" is Google's standard language for state-sponsored or commercial spyware vendors. If you are running an unpatched Android device, this is the one that matters [15].

Update your phone. Settings, System, Software Update. If your manufacturer has not pushed the June patch yet, that is the manufacturer's problem, and it is also your problem [15].

Surveillance Pricing: Connecticut Signs Ban, New York Awaits Governor's Signature

Connecticut Governor Ned Lamont signed HB 5563 on June 4, making Connecticut the second state to ban surveillance pricing after Maryland. The law requires any business using a "price setting device" to display: "THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA." It takes effect July 1, 2027 [16].

New York is right behind. The state legislature passed the One Fair Price Act on June 4, making it the third state to move on surveillance pricing. The bill bans companies from using AI and algorithmic tools to analyze browsing histories, location, demographics, and mouse movements to set individualized prices. It is now on Governor Hochul's desk. The Chamber of Progress, a tech industry coalition, is pushing for a veto [17].

The momentum is real. Three states in a matter of weeks, with 24 total considering legislation. The grocery chains, retailers, and data brokers that built the surveillance pricing infrastructure are watching Maryland's October 1 effective date as the first real compliance test [16][17].

Related: Surveillance Pricing: 24-State Ban Tracker | Maryland's Grocery Pricing Ban: Shopper Guide

Evertec Breach: Payment Card Data Stolen Through Third-Party Platform

Financial technology company Evertec filed a Form 8-K with the SEC on June 9 disclosing that an unauthorized party accessed financial institution client data through a third-party support platform. The breach exposed transaction records, payment card numbers, and in some cases customer names and contact information. The incident primarily impacted Evertec's financial institution clients in Puerto Rico [18].

Evertec activated its incident response protocols, notified federal law enforcement, and engaged external cybersecurity experts. If you bank with an Evertec-connected institution in Puerto Rico or the Caribbean, watch your statements [18].

EFF to Congress: Federal Agencies Are Deploying AI With Zero Constitutional Guardrails

EFF Senior Policy Analyst Dr. Matthew Guariglia testified to the House Homeland Security Subcommittee on June 4 that federal agencies are deploying AI without constitutional safeguards. His core argument: generative AI used for mass government surveillance would "supercharge unconstitutional violations of civil liberties" [19].

Guariglia also flagged the black-box problem. Government secrecy combined with proprietary for-profit AI systems means the public and lawmakers cannot know when AI models make mistakes, including errors that impact critical infrastructure and individual lives. The testimony connects directly to today's FISA 702 debate and the broader question of who gets to wield these tools without oversight [19].

What to Watch

  • Today, June 10: "Tracked and Targeted" hearing from House Democrats. Watch for specific revelations about federal surveillance deployments and data collection programs under the current administration [4].
  • Thursday, June 11: Last realistic day for a clean FISA 702 vote. If no deal materializes, expect a short-term extension request or preparation for Friday's statutory lapse [1][2][3].
  • Friday, June 12: FISA Section 702 statutory expiration. FISA Court certifications keep collection running regardless. The headline is the lever. The policy fight starts the day after [1][2].
  • Governor Hochul's desk: New York's One Fair Price Act awaits signature. Tech industry coalition pushing for veto. A signature makes New York the third surveillance pricing ban [17].
  • Colorado AI Act: The original June 30 effective date has been pushed to January 1, 2027 after Governor Polis signed SB 189 on May 14. The law has been significantly scaled back under federal pressure [20].
  • ServiceNow fallout: Watch for class action filings and regulatory scrutiny. A two-month-old known vulnerability left open until active exploitation is a textbook negligence case [12][13].

References

  1. CBS News: Senate fails to extend FISA surveillance program as deadline nears (June 5, 2026)
  2. Brennan Center: Section 702 FISA 2026 Resource Page
  3. Senate Blocks FISA 702 Reauthorization Before Expiration (June 2026)
  4. House Homeland Security Democrats: "Tracked and Targeted" Hearing Advisory (June 10, 2026)
  5. EFF: Victory: Meta Strips Facial Recognition Code From Smart Glasses App After Public Outcry (June 8, 2026)
  6. Engadget: Meta quietly removes face-recognition code from its smart glasses app (June 2026)
  7. PetaPixel: Meta Removes Facial Recognition Code from Ray-Ban Smart Glasses App (June 9, 2026)
  8. Washington Examiner: Homan says most anti-ICE protesters at New Jersey's Delaney Hall are not state residents (June 2026)
  9. PBS NewsHour: What to know about the protests and arrests outside a New Jersey detention center (June 2026)
  10. Cybernews: Age checker Yoti tells GrapheneOS users they're getting reported (June 2026)
  11. GrapheneOS Discussion Forum: User reported to authorities for using GrapheneOS (June 2026)
  12. BleepingComputer: ServiceNow discloses security incident exposing customer data (June 2026)
  13. Anavem: ServiceNow API Flaw Exposes Customer Data in Security Breach (June 2026)
  14. FTC: Cox Media Group Settlement Over "Active Listening" AI-Powered Marketing Service (May 21, 2026)
  15. The Hacker News: Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited (June 2, 2026)
  16. Consumer Reports: Statement on Connecticut's Surveillance Pricing Bill Signing (June 2026)
  17. EPIC: New York Becomes Third State to Pass Surveillance Pricing Ban (June 2026)
  18. SEC EDGAR: Evertec, Inc. Form 8-K (June 9, 2026)
  19. EFF: EFF Testifies to Congress on Protecting Americans' Rights from Government AI (June 4, 2026)
  20. TechTimes: Colorado's AI Law Update (June 8, 2026)