CVE-2025-26399, CVE-2026-1603
Get tomorrow's brief in your inbox
March 11, 2026
Today: Aetna settles $2M LGBTQ+ discrimination class action over infertility coverage. Anthropic sues DOJ after being designated a supply chain risk for refusing Pentagon AI surveillance use. CISA shortens patch deadlines for critical Ivanti and SolarWinds vulnerabilities exploited by nation-state actors.
Aetna Infertility Treatments LGBTQ+ Discrimination Settlement
Aetna agreed to pay $2 million to settle class action claims that it discriminated against LGBTQ+ couples seeking infertility treatments by requiring them to undergo more ovulation cycles than heterosexual couples to qualify for coverage (Case No. 4:23-cv-01849-HSG, N.D. Cal.). The settlement covers California members in LGBTQ+ relationships who sought coverage for intrauterine insemination (IUI), intracervical insemination (ICI), or in vitro fertilization (IVF) between April 17, 2019 and December 31, 2024. Class members denied IUI/ICI coverage can receive default payments of $1,408, while those denied IVF coverage can receive $2,500, with higher payments available for documented out-of-pocket costs. Aetna has not admitted wrongdoing.
Italian DPA Reprimands Joint Controllers Over Cookie Banner
The Italian DPA issued a reprimand to Jaguar Land Rover Italia and automotive dealer Dream Land after finding their jointly-operated website violated Articles 5, 12, and 13 GDPR through a defective cookie consent banner that overlapped the cookie policy when clicked, preventing users from reading it before making a choice (Case No. 10211780). The banner also contained contradictory information about the data controller's identity, including a non-existent VAT number. The DPA determined both parties were joint controllers under Article 26 GDPR despite their dealership agreement describing them as independent controllers, finding they jointly determined the purposes and means of cookie-based user tracking for shared commercial interests. The DPA ordered both parties to conclude an Article 26 agreement defining their respective responsibilities and ordered JLRI to bring the banner into GDPR compliance.
German Court Prohibits Pre-Ticked Consent Boxes
The Hamburg Regional Court prohibited an airline from obtaining consent through pre-ticked boxes that automatically activated when users clicked a search button (LG Hamburg Case No. 327 O 38/25). The court found the controller violated the GDPR and German consumer laws by misleading data subjects into thinking they had a choice when the website automatically ticked the consent box if users did not do so themselves. The court rejected the controller's argument that the message next to the box sufficiently informed data subjects, finding the practice violated Article 7(4) GDPR by making services conditional on consent. The court did find the controller's account creation process compliant, determining it processed only necessary data (email addresses) with additional fields voluntary.
DOJ Claims HHS Secretary's Vaccine Policies Are "Unreviewable"
A Justice Department lawyer argued in federal court that HHS Secretary Robert F. Kennedy Jr. has "unreviewable" authority over federal vaccine policies, even if he recommended people deliberately expose themselves to infectious diseases instead of getting vaccinated. The argument came during a lawsuit filed by the American Academy of Pediatrics and other medical groups seeking an injunction against HHS policy changes under the Administrative Procedure Act. U.S. District Judge Brian Murphy expressed skepticism of the government's position during a Boston hearing, questioning whether Kennedy's authority is truly unreviewable. The case challenges whether HHS vaccine policy changes were carried out in accordance with required administrative procedures.
Anthropic Sues DOJ Over Supply Chain Risk Designation
Anthropic filed suit asking courts to block the Department of Defense's designation of the company as a "supply chain risk" after Anthropic refused to allow the government to use its Claude AI model for lethal autonomous warfare and mass surveillance of Americans. In an amicus brief, EFF and other public interest organizations argued the designation violates the First Amendment because developing and operating large language models involves expressive choices protected by constitutional guarantees, and requiring Anthropic to rewrite its code to remove guardrails constitutes compelled speech. The brief notes the DOJ retaliated against Anthropic both for refusing the Pentagon's demands and for its CEO's public statements about AI surveillance risks. The case raises questions about whether the government can coerce private companies to modify their technology to serve government ends and whether companies can maintain their own AI safety guardrails without facing federal retaliation.
H&R Block Faces Military Lending Act Class Action
Service member Joshua Montgomery filed a class action lawsuit alleging H&R Block overcharges military members for tax refund advance loans in violation of the Military Lending Act (MLA), which prohibits creditors from extending consumer credit to covered borrowers at a military annual percentage rate (MAPR) exceeding 36% (Case No. 3:26-cv-00759-LL-MSB, S.D. Cal.). The complaint alleges that while H&R Block markets the loans as "0% APR" and "no-fee," the product's structure and required ancillary financial accounts generate revenue that causes the MAPR to far exceed the 36% cap when fees and charges imposed as conditions of credit are included. Montgomery seeks to represent nationwide classes of covered members charged refund transfer fees or check disbursement fees, and those subjected to arbitration agreements, class waivers, or jury trial waivers. The plaintiff demands declaratory and injunctive relief plus actual, statutory, and punitive damages.
Department of Education Sued Over Student Loan Balance Reporting
Federal student loan borrower Adriana Walsh filed a class action against the U.S. Department of Education alleging violations of the Fair Credit Reporting Act (FCRA) and Privacy Act for reporting inaccurate loan balances when loans transfer between servicers (Case No. 1:26-cv-01358, S.D.N.Y.). The lawsuit claims the DOE directs original servicers to "suppress" accounts rather than report $0 balances to credit reporting agencies, resulting in borrowers appearing to owe double the actual amount with two separate accounts showing outstanding balances. Walsh discovered the issue after her loans transferred from Nelnet to MOHELA, finding her credit report showed she owed more than $300,000 instead of the actual amount. The complaint alleges the DOE has been aware of this issue since receiving approximately 500 credit reporting complaints since December 2023 but has failed to take corrective action. The lawsuit seeks statutory, actual, and punitive damages.
Reddit Denied Access to Dutch DPA Investigation Records
The Hague District Court rejected Reddit's request to access all records from the Dutch DPA's ongoing investigation into the company's data processing activities (Case No. C/09/697042 / KG ZA 26/2). The court found Reddit had not provided sufficient evidence to support its claims that the DPA possessed confidential or privileged information obtained through improper means. The DPA initiated the ex-officio investigation in March 2025 following media coverage revealing that users' public content was shared or sold to train AI models. Reddit ceased cooperating with the investigation, arguing the DPA had access to incorrect or unlawfully obtained information, including material from a former employee. The court ordered Reddit to pay the DPA's litigation costs.
Social Media Addiction Trial Hears Expert Testimony
A California bellwether trial is underway involving allegations that Meta and Google intentionally designed social media platforms to encourage addiction in young users (Case No. JCCP5255, Superior Court of California, Los Angeles County). Stanford University professor Anna Lembke testified that peer-reviewed studies confirm social media addiction is real and can cause or worsen depression, anxiety, insomnia, and suicidal thoughts, citing a National Institutes of Health study tracking over 11,000 children that found heavy social media users who were not depressed became depressed after prolonged use. The trial focuses on allegedly addictive platform features including infinite scroll, autoplay, notifications, and reward systems, with pretrial rulings limiting claims to the platforms' features rather than third-party content. Plaintiff Kaley G.M., now 20, alleges social media addiction in her youth caused mental health problems. The trial is the first of at least nine planned out of thousands of consolidated cases, and its outcome could influence settlement negotiations.
Watch Tower Uses DMCA to Unmask Anonymous Jehovah's Witness Researcher
The Watch Tower Bible and Tract Society sent DMCA subpoenas to Google and Cloudflare seeking to unmask an anonymous Jehovah's Witness member who created the JWS Library website archiving historical church documents and research tools analyzing how the organization's public statements changed over time. The anonymous researcher, identified as J. Doe, used machine translation on foreign-language documents to help the community understand church statements to different audiences and potential changes in attitudes toward dissent. Watch Tower claims copyright infringement, but EFF argues in defense that Doe's research and commentary constitute clear fair use and that the First Amendment does not permit unmasking anonymous speakers based on weak copyright claims. Within the church, dissent or questioning has been punished through "disfellowshipping" that severs family, friend, and professional relationships, leading Doe and others to speak anonymously to avoid retaliation.
CISA Shortens Patch Deadline for Critical Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities catalog with significantly shortened patch deadlines following reports of active exploitation by cybercriminals and nation-state actors. Federal civilian agencies have until March 13, 2026 to patch CVE-2025-26399, a critical vulnerability in SolarWinds Web Help Desk discovered by Trend Micro's Zero Day Initiative. This is the third time in the last month CISA has ordered immediate patching of SolarWinds Web Help Desk bugs, with previous deadlines of four days and three days. CISA also added CVE-2026-1603 affecting Ivanti products, which Chinese nation-state attackers have allegedly exploited since mid-February, giving federal agencies a two-week deadline. Google's 2025 zero-day report found Chinese state actors repeatedly targeted Ivanti throughout 2025 with novel bugs. SolarWinds software is used by dozens of federal agencies and was previously targeted by Russian hackers in one of the largest nation-state attacks in U.S. history.
Joshua Rudd Confirmed as NSA Director and Cyber Command Chief
The Senate confirmed Army Lt. Gen. Joshua Rudd 71-29 to lead U.S. Cyber Command and the National Security Agency, ending a nearly year-long leadership vacuum after Air Force Gen. Timothy Haugh and his top NSA deputy were fired in April 2025. Rudd, who receives a promotion to four-star general, currently serves as deputy chief of U.S. Indo-Pacific Command but has no experience in cyber operations or signals intelligence. Sen. Ron Wyden (D-OR) opposed the nomination due to Rudd's vague answers when asked to commit to not using NSA foreign surveillance tools to spy on U.S. citizens without a warrant, with Rudd pledging to follow the law but declining to explicitly rule out the practice. The confirmation comes as Section 702 of the Foreign Intelligence Surveillance Act will expire next month without congressional action, with President Trump indicating he favors an 18-month "clean" extension.
Meta Ray-Ban Smart Glasses Raise Surveillance Concerns
EFF issued a warning about privacy and civil liberties concerns with Meta's Ray-Ban Display Glasses and similar smart glasses from Oakley and other manufacturers. Photos and videos recorded with the glasses are automatically imported by default into the Meta AI mobile app, which is required for setup, and footage is fed to Meta whenever AI features are used. An investigation by Swedish newspapers found that Meta workers review and annotate camera footage for AI training purposes, including sensitive videos of nudity, sex, and bathroom use, which Meta claims is in accordance with its terms of use. The glasses are designed to resemble regular glasses to the point where most people don't notice the embedded cameras outside of a small indicator light when recording (which cheap hacks can disable). Recorded audio from conversations with Meta AI are saved by default unless manually deleted after each use. When footage is saved to a phone's camera roll, it may also be sent to Apple or Google's servers depending on settings, where employees can potentially access the media and share it with law enforcement.
UK Launches Fraud Strategy Shifting Responsibility to Tech Companies
The British government unveiled a new fraud strategy that shifts more responsibility for stopping scams onto telecom companies, technology platforms, and financial firms. The plan includes a new Online Crime Centre backed by more than £30 million ($40.3 million) launching next month, bringing together government agencies including the National Crime Agency and GCHQ alongside private sector companies to share data identifying accounts, websites, and phone numbers used by criminal groups. The center will block scam text messages, freeze accounts, and remove fraudulent social media profiles at scale. The strategy responds to fraud accounting for approximately 40% of recorded crime in England and Wales but receiving only 2% of police funding. Critics including Starling Bank's head of fraud called the plan "disappointing" for failing to require major platforms to take greater responsibility for scams occurring on their services. Authorities also launched Report Fraud, a national reporting system run by the City of London Police to replace the Action Fraud service, analyzing reports from victims and the private sector to identify fraud patterns.
FBI Warns of Phishing Campaign Targeting Permit Applicants
The FBI issued a notice warning that cybercriminals are impersonating government officials and demanding fraudulent payments for land-use permits through a sophisticated phishing campaign affecting victims across the U.S. The phishing emails target people and businesses with active permit applications and include detailed, accurate information such as property addresses, case numbers, and true names of city and county officials. The cybercriminals use publicly-available permit information to craft emails on city letterhead with professional language mimicking real zoning documents, including detailed discussions of review processes, planning commission procedures, regulatory compliance, and relevant ordinances. Many emails use "@usa.com" addresses instead of ".gov" and demand payment through wire transfers or cryptocurrency, often including threats to create urgency. The FBI urged people to verify email addresses before interacting with them and to always check local county or city websites to call listed phone numbers to verify potential charges.