Today in Surveillance:

  • Apple Watch Series 12's "Live Rewind" and "Siri Recap" record bystander speech with only a chime as notice. The Register reports Live Rewind captures the last 15 seconds of audio on a double-press of the Digital Crown; Siri Recap summarizes conversations throughout the day; both features process audio on-device but record bystanders who have not consented, in conflict with all-party consent laws in 11 US states [1].
  • McKesson refused a $55.2 million ShinyHunters extortion demand, then saw about 6.4 million records exposed. The Register reports the leak covers marketing-campaign recipients, patients, staff, and healthcare-provider contacts at the US medical-supply giant, with names, addresses, dates of birth, phone numbers, employer details, and sensitive health information exposed. McKesson supports 3,300 oncology providers across 29 states [2].
  • Anthropic's September 2026 threat-intelligence report documented Claude misuse across seven harm areas. Anthropic said it disrupted activity from December 2025 through August 2026 in cyber operations, influence operations, surveillance, scams, biological misuse, conventional weapons development, and distillation. A Russia-linked group called GTG-20006 automated the full attack chain across more than 20 targets including embassies and defense-industrial firms [3].
  • EFF documents a pattern of police agencies instructed to conceal surveillance tool use. An Iowa county's Flock ALPR policy told officers in capital letters to "DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE." Houston police guidance told officers to "be as vague as permissible" about Flock use, and EFF traced the pattern through Stingray and Hemisphere to a 2015 Baltimore warrant ruling [4].
  • A federal judge handed down the first Take It Down Act sentencing: 15 years for James Strahler of Ohio. 404 Media reports he pleaded guilty to cyberstalking, producing obscene visual representations of child sexual abuse, and publication of digital forgeries. He created over 700 images of real victims and animated persons [5].
  • A likely Russian-speaking attacker used hundreds of AI agents to compromise 395 or more organizations through PaperCut CVEs. The Register reports the agents hit at least 440 PaperCut instances in 48 countries, education hardest hit with 204 victims, and reached domain admin on one American high school in seven minutes. The operator's do-not-hit list of 28 countries was sometimes ignored by the agents themselves [6].

Also today: EFF publicly opposed California's newly signed AB 1709 youth social-media ban, with Rindala Alajaji calling age-gating a surrender of personal information to companies and allied groups warning it cuts LGBTQ+ youth off from online community [7]. Tencent patched a zero-click WeChat worm called WeWorm that gave attackers full account control during ringing VoIP calls; the researcher "Calif" said AI helped develop the first RCE exploit in about two days [8]. EFF named Access Now, 7amleh, DeFlock, and New Media Rights as the 2026 EFF Award winners, putting the volunteer ALPR-mapping project at the center of the cancel-Flock wave on the same stage as international press-freedom groups [9]. EFF obtained about 1,000 pages of FOIA records on Medicare's WISeR AI prior-authorization pilot, with one request sitting unanswered for 83 days against a 72-hour CMS target and two vendors denying more than 20,000 requests combined in the first three months [10].

Apple Watch Live Rewind and Siri Recap Capture Bystanders, Not Just the Wearer

Apple's new Apple Watch Series 12 ships two audio features that record more than the person wearing the watch. The Register reports that Live Rewind captures the last 15 seconds of conversation as text when the wearer double-presses the Digital Crown. The microphone is always on, so the 15-second capture includes every speaker within earshot, not just the wearer. Siri Recap summarizes conversations throughout the day without retaining raw audio and, per Apple's own documentation, "does not create a recording, does not produce a verbatim transcript, and does not identify and attribute speakers." Both features route audio through the Secure Exclave on the S11 chip and send the result to a nearby iPhone for speech-to-text processing [1].

The bystander problem is what makes the consent issue unavoidable. Apple ships a documentation page titled "How Live Rewind respects those around you," and the watch emits an audible tone (even in silent mode) plus an on-screen animation when Live Rewind fires. Siri Recap produces no audible signal at all, because no raw audio is retained. None of that constitutes consent from the bystander, and bystanders are not warned before their speech is captured. Eleven US states have all-party consent laws for audio recording, per the Digital Media Law Project legal guide cited by The Register. Recording a private conversation in those states without the consent of every party is a crime [1].

Adam Schwartz, the Electronic Frontier Foundation's privacy litigation director, told The Register that the design places "freedom from other people, without our clear opt-in consent, using technology to document what we are saying" at risk and warned that "people will self-censor, and conversation will lose its spontaneity and intimacy." Schwartz said "always-on monitoring of our conversations is an unacceptable burden on our conversational privacy" and recommended users think twice before using the features, out of respect for the people they are talking to. The consent line is the line every state-level attorney general is going to have to draw next: a chime, a visual cue, and a privacy-policy paragraph are not the same as opt-in [1].

McKesson Refused $55.2 Million and 6.4 Million Records Leaked Anyway

ShinyHunters, the group The Register calls "serial extortionists," demanded $55.2 million from McKesson, the US medical-supply giant, to prevent the release of stolen data. McKesson did not pay, and the data was published. Have I Been Pwned counted about 6.4 million individuals in the leak. ShinyHunters had earlier claimed 284 million documents in August, but HIBP did not confirm that figure. McKesson supports 3,300 oncology providers across 29 states, a footprint that puts any patient-records exposure directly into active cancer treatment [2].

The data ShinyHunters published covers marketing-campaign recipients, patients, staff, and healthcare-provider contacts. The exposed fields include names, email and physical addresses, genders, dates of birth, phone numbers, employer details, and sensitive health information. ShinyHunters also claimed the leak included appointment dates, notes, and medical details like cancer locations. ShinyHunters further claimed Social Security numbers were stolen, though HIBP's analysis did not include them. The last public update from McKesson's CIO and CTO on the incident was August 29, with the disclosure dating to August [2].

McKesson sits inside the same ShinyHunters 2026 pattern documented across Salesforce, Carnival, and Canvas in the same window. Boston Scientific and Veradigm disclosed separate attacks in the same period, though The Register reports those are not ShinyHunters incidents. The McKesson refusal is the operationally interesting part: the extortion model worked as designed, the threat actor published anyway, and the victim is left facing patient notification, regulatory disclosure, and a wave of class-action exposure [2]. Our ShinyHunters breach tracker carries the running 2026 list of victims and disclosure dates.

Anthropic Documents Seven Categories of Claude Misuse From Dec 2025 Through Aug 2026

Anthropic's September 2026 threat-intelligence report, summarized by The Register, documents activity the company disrupted across seven "harm areas" between December 2025 and August 2026: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Anthropic says the activity used Claude Haiku, Sonnet, and Opus, and that the most powerful Fable or Mythos-class systems were not used except in a single distillation case. The report's stated goal is to share findings so other developers can recognize similar patterns and to help governments and civil society strengthen collective defenses [3].

The cyber-operations detail is the most concrete. Anthropic attributes one cluster to a Russia-linked threat group called "GTG-20006" and ties it to the SVR, the Russian foreign-intelligence service also tracked as "Midnight Blizzard." The group used Claude to automate development work, infrastructure acquisition, phishing, persistence, and exfiltration across more than 20 targeted organizations including embassies, think tanks, defense-industrial firms, and government and intelligence agencies across Ukraine, Europe, the Middle East, Asia, and North Africa. ShinyHunters affiliates used Claude to scale supply-chain breaches; in one session-store dump, AI agents performed nearly all the work and pulled a set of more than 2,100 Azure AD tokens spanning more than 40 corporate tenants in about 34 hours [3].

The biological and weapons sections are the parts Anthropic flags as most acute. Five cases involved users in "unsupported regions" using Claude for biological-weapons development. One scientist attempted to use Claude for a grant application on chikungunya virus transmissibility and immune evasion, research Anthropic noted could also make the pathogen more dangerous. In May, a non-US user researched adaptations of highly pathogenic avian influenza (H5) viruses with brain involvement in cats, foxes, ferrets, and some human cases. On the weapons side, Anthropic documented six cases across China (three), Russia (two), and Yemen (one). The Yemen team used Claude to develop guidance, navigation, and control software, test-fired a guided rocket, and built an offline simulation toolkit. A Chinese actor drafted a Chinese-language specification for an anti-torpedo fire-control system benchmarked against US anti-torpedo and anti-submarine programs for the PLA Navy. A Russian "freelance team" attempted a full-stack autonomous first-person-view kamikaze drone swarm, with Claude writing and testing the core software [3].

An Iowa County's Flock Policy Says "DO NOT MENTION ALPR USAGE"

The Electronic Frontier Foundation's Karen Gullo and Adam Schwartz documented a pattern of police agencies instructing officers to conceal surveillance tool use. An Iowa county's Flock ALPR usage policy tells officers in capital letters to "DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE" and "DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY," and to write "county resources" instead. Houston police guidance goes a step further: officers are told to "be as vague as permissible" about why they use Flock, on the theory that a public-records search could expose the underlying justification [4].

EFF describes this as a deliberate hide-the-ball posture that treats transparency as a liability. The pattern extends to cell-site simulators. In Baltimore, a judge found that police used a standard pen-register order "to intentionally hide its use of a Stingray" from the court, producing a 2015 ruling that police need a warrant to use the device. Prosecutors have accepted plea deals and dropped cases rather than disclose Stingray details, and U.S. Marshals have driven files hundreds of miles to thwart public-records requests. Hemisphere, the AT&T phone-surveillance tool, required agencies not to use Hemisphere evidence in court unless no other admissible evidence existed; when police re-create the evidence through traditional subpoenas, EFF calls it "evidence laundering." EFF also called for Nottinghamshire Police in the UK to halt live facial recognition deployment [4].

The Iowa county policy is the operational proof of the audit-log argument made in the IPVM investigation of police chiefs using Flock to track women: officers are not merely allowed but instructed to hide the use of a public surveillance system from the people it surveils. The warrant-requirement bills moving in Washington and Colorado would force an officer to articulate a reason before querying rather than explain it afterward; the Iowa policy is the case for why the before-the-query rule matters [4].

First Take It Down Act Sentencing: 15 Years for James Strahler

404 Media reported the first federal sentencing under the Take It Down Act, which makes it a crime to knowingly publish or threaten to publish nonconsensual intimate imagery. James Strahler, 38, of Ohio, received 15 years in federal prison after pleading guilty to cyberstalking, producing obscene visual representations of child sexual abuse, and publication of digital forgeries. The case was handled by the U.S. Attorney's Office for the Southern District of Ohio. Strahler created over 700 images of real victims and animated persons and posted them to a child-sexual-abuse site; an additional 2,400 images and videos on his phone depicted nudity, morphed CSAM, or violence, including AI-generated images of minor boys from his community in sex acts with their mothers or grandmothers [5].

The Take It Down Act's removal timelines and First Amendment limits are now being tested in court, and this first sentencing sets the baseline. The prosecution paired traditional cyberstalking counts with publication of digital forgeries, a category the statute covers alongside nonconsensual intimate imagery. Strahler had stalked exes with 31 calls and texts in nine days, including threats of sexual assault, extortion, and images of a victim undressing, and continued the harassment after an initial January 2025 misdemeanor arrest. The 15-year sentence is the operationally relevant number for platforms and prosecutors watching the statute's first year [5].

An AI-Agent Operator Hit 395 or More Organizations Through PaperCut in 48 Hours

An attacker tracked by GreyNoise to IP 45.142.193.132 and described as "likely Russian-speaking" used hundreds of AI agents to compromise at least 440 PaperCut instances across 395 or more identified organizations in 48 countries. Education was hit hardest with 204 victims. The agents were powered by OpenAI's Codex harness and a DeepSeek model. The Register reports the timeline: from an empty workspace to first achieving remote code execution against a real victim in just under four hours, domain admin on one American high school in seven minutes, and the fastest access-to-domain-admin at five minutes. Once fully launched, the campaign compromised at least 11 organizations in 26 seconds [6].

The operator instructed the agents to avoid 28 countries, with the top five on the list being Russia, China, Hong Kong, Thailand, and Iran. GreyNoise reports the agents did not always follow those instructions. Some organizations on the do-not-hit list were still targeted. GreyNoise called it "agents gone wild." The exploited vulnerabilities are CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF; emergency patches were issued August 28 after the first compromise was reported August 27. Cloudflare's web application firewall blocked the attacker in at least one case, which GreyNoise cited as evidence that "fundamental hardening of environments still matters against AI-enabled threats" [6].

Anthropic's own threat report, published the same week, names ShinyHunters affiliates using Claude to scale supply-chain breaches. The PaperCut campaign is the operational proof that AI-agent mass exploitation is no longer a hypothetical. The agents now move faster than a human red team, and the operator's do-not-hit list is advisory, not enforced [6].

What to Watch This Week

Apple Watch state-level action. Watch whether any of the 11 all-party-consent states' attorneys general open a consumer-protection or wiretap probe into the Apple Watch Series 12 audio features, and whether Apple's chime-based notice survives the test in those states [1].

McKesson patient notification. McKesson said its last CIO/CTO update was August 29. Watch whether the company publishes a full breach notification under HIPAA, which states' residents are in scope, and whether any of the 3,300 oncology providers in 29 states file separate notifications [2].

PaperCut remediation. GreyNoise reported the agents still hit some organizations on the operator's do-not-hit list. Watch whether CISA issues a specific advisory on CVE-2026-81578 and CVE-2026-82078, and whether the education sector's response exposes how many PaperCut instances were unpatched before the August 28 emergency fix [6].

California AB 1709 implementation. Governor Newsom signed AB 1709 on September 10. Watch how the California Attorney General defines "social media" for enforcement, whether age-verification vendors emerge, and whether EFF and allied groups file a First Amendment challenge [7].

Anthropic's distillation framing. Anthropic named distillation as one of the seven harm areas, alongside a note that Fable and Mythos class systems were not used except in one case. Watch whether the next report publishes a count of disrupted distillation attempts at the frontier-model tier, and whether allied vendors publish matching numbers [3].

Sources

  1. The Register, Thomas Claburn: Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent (September 10, 2026). https://www.theregister.com/security/2026/09/10/watch-out-apple-timepiece-can-grab-snippets-of-conversation-without-both-speakers-consent/5295666
  2. The Register, Connor Jones: ShinyHunters expose 6.4M in attack on medical supplier McKesson (September 10, 2026). https://www.theregister.com/security/2026/09/10/shinyhunters-expose-64m-in-attack-on-medical-supplier-mckesson/5295550
  3. The Register, Jessica Lyons: Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research (September 10, 2026). https://www.theregister.com/ai-and-ml/2026/09/10/latest-anthropic-horror-story-chills-with-tales-of-kamikaze-drone-swarms-and-bioweapons-research/5295702
  4. Electronic Frontier Foundation, Karen Gullo and Adam Schwartz: Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR (September 9, 2026). https://www.eff.org/deeplinks/2026/09/cops-play-hide-and-seek-about-using-spy-tech-avoid-scrutiny-and-bad-pr
  5. 404 Media: First Take It Down Act Sentencing Case (September 9, 2026). https://www.404media.co/first-take-it-down-act-sentencing-case/
  6. The Register, Connor Jones: Hundreds of AI agents helped PaperCut attacker hit 395 orgs and some went off script (September 10, 2026). https://www.theregister.com/security/2026/09/10/hundreds-of-ai-agents-helped-papercut-attacker-hit-395-orgs-and-some-went-off-script/5295650
  7. Electronic Frontier Foundation, press release: We all deserve a better internet, not a smaller one (September 10, 2026). https://www.eff.org/press/releases/we-all-deserve-better-internet-not-smaller-one
  8. The Register, Connor Jones: WeChat worm could pwn a friend before they even answered the call (September 9, 2026). https://www.theregister.com/security/2026/09/09/wechat-worm-could-pwn-a-friend-before-they-even-answered-the-call/5295234
  9. Electronic Frontier Foundation, Josh Richman: 2026 EFF Award Winners: Access Now, 7amleh, DeFlock, and New Media Rights (September 9, 2026). https://www.eff.org/deeplinks/2026/09/2026-eff-award-winners-access-now-7amleh-arab-center-advancement-social-media
  10. Electronic Frontier Foundation, Lena Cohen: New Records Reveal Problems with Medicare's AI Prior Authorization Experiment (September 8, 2026). https://www.eff.org/deeplinks/2026/09/new-records-reveal-problems-medicares-ai-prior-authorization-experiment