CVE-2026-20131
Get tomorrow's brief in your inbox
Today: Illinois sees multiple biometric privacy lawsuits against Fireflies.AI and Eggland's Best as BIPA enforcement continues. Federal agencies warn of cybersecurity risks in Microsoft Intune following Iran-linked attacks on Stryker, while CBP confirms it sources location data from real-time bidding ad systems. The Supreme Court weighs asylum rights at borders, birthright citizenship challenges under 8 U.S.C. § 1401(a), and class action procedures for uninjured plaintiffs.
Croatian DPA Fines Controller €20,000 for Preloaded Cookies
Croatia's data protection authority (AZOP) fined a company €20,000 for processing personal data through cookies without valid consent. The investigation revealed that personal data was stored and processed immediately upon visiting the website, before users provided consent. The controller violated Article 6(1)(a) and Article 7 GDPR by failing to provide granular consent options, combining marketing, analytics, and functional cookies in a single consent interface. Between July 2013 and November 2022, the controller processed personal data for marketing and statistical purposes through preloaded cookies that executed before consent, depriving users of meaningful choice. The controller also violated Article 5(1)(a) GDPR for unfair and non-transparent processing and Article 13(1) and (2) for failing to provide adequate information about data processing, retention periods, and user rights.
Irish DPC Reprimands Microsoft for Mishandling Access Request
The Irish Data Protection Commission reprimanded Microsoft Ireland Operations Limited for violating Article 12(4) GDPR by failing to inform a user of the right to lodge a complaint with a supervisory authority and seek judicial remedy when declining an access request. Microsoft suspended a user's OneDrive account in February 2020 after scanning software allegedly discovered child abuse imagery, then declined to provide the requested files or reason for suspension, citing only a serious violation of its Services Agreement. The DPC found Microsoft violated Article 5(1)(a) GDPR in handling the access request and deleting the user's data in February 2021 under its standard retention policy. Microsoft's customer service team misinterpreted the access requests as account reactivation requests and failed to forward them to the privacy response team. The DPC could not determine whether Microsoft properly relied on the Article 15(4) GDPR exemption to refuse providing a copy of personal data due to the deletion of files.
UK ICO Reprimands City of London Police for SAR Delays
The UK Information Commissioner's Office reprimanded the City of London Police for failing to respond to subject access requests within statutory timeframes between April 2023 and July 2025. Between April 1, 2023 and March 31, 2024, less than half of submitted SARs received responses within the statutory timeframe, violating Article 12(3) UK GDPR and Section 45(3) of the Data Protection Act 2018. The controller's compliance improved to 93% for April 2025 to July 2025. The ICO issued a reprimand along with recommendations for bringing SAR response activities into compliance. The City of London Police receives SARs under Part 3 DPA 2018 for law enforcement processing and under UK GDPR for non-law enforcement processing such as employee HR matters.
Fireflies.AI Faces BIPA Suit Over Meeting Participant Voiceprints (Case No. 1:26-cv-02675)
Plaintiff Ethan Fricker filed a class action in Illinois federal court alleging Fireflies.AI Corp. violated the Illinois Biometric Information Privacy Act by collecting and storing voiceprints without obtaining consent. Fricker claims Fireflies, an AI meeting assistant that automatically joins virtual meetings on Zoom, Microsoft Teams, and Google Meet, records, analyzes, transcribes, and stores voiceprints of all meeting participants, including individuals who never created Fireflies accounts or agreed to terms of service. The lawsuit alleges Fireflies failed to inform Fricker in writing that it was collecting his biometric data during meetings, nor did it disclose the purpose or duration of biometric data collection or storage. Fricker seeks to represent a class of individuals whose voiceprints were collected by Fireflies while in Illinois during the five years preceding the filing. He requests statutory damages, injunctive relief, and a jury trial.
Crunchyroll Sued for VPPA Violations Over Video Viewing Data (Case No. 2:26-cv-02373)
Lead plaintiff Francisco Cabonios filed a class action in California federal court alleging Crunchyroll LLC violated the Video Privacy Protection Act by disclosing users' personally identifiable information to Braze Inc., a third-party marketing and analytics company, without proper consent. The lawsuit claims Crunchyroll embedded Braze's software development kit in its mobile application, transmitting users' email addresses, persistent device identifiers, and titles of specific video content to Braze without obtaining informed, written consent in a form distinct and separate from other legal or financial obligations. The VPPA provides consumers whose privacy has been breached with statutory damages of $2,500 per violation, plus attorney fees and costs. Plaintiffs seek to represent all persons in the United States who created accounts on the Crunchyroll app and had their personal viewing information disclosed to Braze within the applicable statute of limitations.
Home Depot Class Action Alleges Shelf Price Discrepancies (Case No. 1:26-cv-02241)
Plaintiff Hazel Cabanlit filed a class action in Illinois federal court on February 27 alleging Home Depot Inc. misleads customers by charging higher prices at checkout than those advertised on store shelves. The lawsuit claims shelf prices frequently differ from register amounts, with some items ringing up 10% to 40% higher than advertised, violating state and federal consumer laws. Cabanlit alleges Home Depot is aware of the pricing discrepancies, citing previous fines totaling $2 million paid to multiple California district attorneys for similar practices under stipulated judgments. The lawsuit claims the fines have not dissuaded Home Depot from continuing the practice. Cabanlit seeks to represent anyone who bought merchandise from a Home Depot store in the United States and paid higher prices than advertised shelf prices within the applicable statute of limitations.
General Motors Brake Defect Class Action (Case No. 2:26-cv-10570)
Plaintiffs Kaylee Thieme, Rebecca Gill, and Meghan Morley filed a class action in Michigan federal court alleging General Motors LLC sold 2016-2020 Buick Envision, 2018-2022 Chevrolet Equinox, and 2018-2022 GMC Terrain vehicles with a defective brake vacuum pump system that significantly increases stopping distances. The plaintiffs claim GM concealed the brake vacuum pump defect from owners and knew of the defect as early as March 2017 when it issued a stop delivery order identifying a safety-critical problem in the brake vacuum system. The lawsuit alleges GM violated the Magnuson-Moss Warranty Act and consumer protection laws in Michigan, Arizona, and New Jersey, and engaged in fraudulent concealment and unjust enrichment. The plaintiffs seek to represent a nationwide class of consumers who purchased or leased the class vehicles.
Eggland's Best "Cage Free" Claims Survive Motion to Dismiss (Case No. 24-cv-06222)
The Northern District of Illinois permitted a consumer class action to proceed against Eggland's Best over "cage free" egg labeling. Plaintiffs who care about animal welfare alleged they were misled by packaging claims that hens were "free to roam in a pleasant, natural environment," when hens were housed indoors in large industrial facilities lacking outdoor access. Eggland moved to dismiss, arguing statements were not misleading because eggs were accurately labeled "cage free" under state regulations and the language amounted to non-actionable puffery. The court rejected both arguments, holding that a reasonable consumer could plausibly interpret "free to roam" in a "natural" and "pleasant environment" to suggest outdoor access or materially different conditions. The court found "free to roam in a pleasant natural environment," taken as a whole, makes a verifiable promise about living conditions and is not mere puffery.
Supreme Court to Consider Uninjured Class Members in RICO Case
In Takeda Pharmaceutical Co. v. Painters and Allied Trades District Council 82 Health Care Fund, Takeda and Eli Lilly seek review of a 9th Circuit decision allowing a nationwide RICO class action to proceed based on alleged concealment of bladder-cancer risks associated with the diabetes drug Actos. The suit is brought by third-party payors who reimbursed prescriptions, alleging the companies concealed evidence linking Actos to bladder cancer for over a decade to boost prescriptions. The district court certified a nationwide class under Federal Rule of Civil Procedure 23(b)(3) that reimbursed at least five prescriptions, relying on an econometric model estimating roughly 57% of prescriptions were fraudulently induced. A divided 9th Circuit panel affirmed certification, reasoning that common proof including regression analysis and company documents could establish classwide injury and causation. The petition argues the 9th Circuit's approach deepens circuit splits on whether Rule 23(b)(3) permits certification of damages classes that include uninjured members without a reliable mechanism to identify and exclude them, and whether plaintiffs can use statistical modeling to prove individualized reliance in fraud class actions.
Afroman Wins First Amendment Defense Against Deputies' Defamation Suit
A jury cleared rapper Afroman of all liability after Adams County, Ohio deputies sued him for $3.9 million claiming defamation and emotional distress over music videos mocking their 2022 raid on his home. Deputies raided Afroman's home with guns drawn, found nothing, filed no charges, and broke his door. Afroman turned security camera footage into viral music videos. The jury took just hours to rule in Afroman's favor, affirming that public officials who raid a home cannot use courts to punish the homeowner for talking about it. Afroman's lawyer argued that public officials must accept criticism as part of their duties, citing NWA's "Fuck Tha Police" and Richard Pryor's comedy as protected speech. The case demonstrates the First Amendment protections for speech about public officials' actions.
Supreme Court to Hear Asylum Seekers' Rights at Border (Noem v. Al Otro Lado)
The Supreme Court will hear oral arguments next week on the government's policy of systematically turning back asylum seekers before they can reach the U.S. border with Mexico. The policy is no longer in place, but the Trump administration calls it a critical tool for addressing surges in immigrants at the border. In 2024, a divided 9th Circuit panel ruled that, for purposes of being able to apply for asylum under federal immigration law, noncitizens who were turned away from ports of entry before entering the United States had "arrived in" the country. The court held that "the phrase 'physically present in the United States' encompasses noncitizens within our borders, and the phrase 'arrives in the United States' encompasses those who encounter officials at the border, whichever side of the border they are standing on." In its brief, the government argues that in ordinary English, a person "arrives in" a country only when he comes within its borders, and the 9th Circuit effectively replaced the statutory text with alternative text of its own.
Judicial Estoppel Standards for Bankrupt Debtors Before Supreme Court (Keathley v. Buddy Ayers Construction)
The Supreme Court will hear arguments next week on whether courts evaluating prejudice from constitutional trial error may rely on evidence the jury never saw. The case involves Thomas Keathley, who filed bankruptcy in Arkansas in December 2019. While making payments under his Chapter 13 plan, Keathley was injured when a truck driven by a Buddy Ayers Construction employee struck his car. Keathley's lawyer did not disclose the accident to the bankruptcy court. When Keathley sued Buddy Ayers in Mississippi federal court, lower courts dismissed his complaint under judicial estoppel because Keathley had a motive to conceal the accident from the bankruptcy court. The case presents a circuit split: the 5th Circuit emphasizes the potential benefit of nondisclosure and applies the doctrine whenever there is a hypothetical motive to conceal, while other courts apply a totality of circumstances test that turns on whether the debtor intentionally concealed assets. Keathley argues there is nothing deceitful about being in a car accident and not knowing to immediately disclose it to the bankruptcy court, and he did tell his lawyer.
Volvo Sued Over Infotainment System Defect (Case No. 2:25-cv-18948)
Plaintiff Lydia Leonberg filed a class action in New Jersey federal court on December 23 alleging certain Volvo vehicles contain a defect that causes their Android Automotive Operating System infotainment system to fail. The lawsuit affects 2021-2025 Volvo XC40, 2022-2025 Volvo C40, 2022-2025 Volvo XC60, 2022-2025 Volvo XC90, 2022-2025 Volvo S60, 2022-2025 Volvo S90, 2022-2025 Volvo V60, 2022-2025 Volvo V90, 2025 Volvo EX30, 2025 Volvo EX40, and 2025 Volvo EX90 vehicles. Leonberg says her 2023 Volvo XC60 central infotainment system started to freeze within the first month, the rearview camera would not turn on, the headlights would flash, and the blinkers malfunctioned. The problems persisted despite multiple repairs, software updates, and a recall. The lawsuit alleges the infotainment system defect is so severe that it renders vehicles non-compliant with federal safety standards by affecting the rearview camera and defrosting systems. Leonberg claims Volvo knew about the defect before selling the vehicles but failed to disclose it to consumers.
FBI and CISA Warn of Microsoft Intune Risks After Iran-Linked Attack
The FBI and Cybersecurity and Infrastructure Security Agency released an advisory confirming their involvement in responding to the recent attack on Stryker, a Michigan medical device company. Attackers broke into Microsoft's Intune device management system and wiped more than 200,000 company devices. The hacking group Handala did not use malware but instead accessed the legitimate Microsoft tool to wipe data. CISA urged companies using Intune to follow Microsoft's best practices and harden endpoint management system configurations. Intune customers should use role-based access controls to assign minimum permissions necessary to each role, implement multi-factor authentication and Microsoft Entra ID to block unauthorized access to privileged actions, and set up policies requiring a second administrative account's approval for sensitive or high-impact actions such as device wiping. The FBI seized a website connected to the Handala group, determining it was used to conduct, facilitate, or support malicious cyber activities on behalf of, or in coordination with, a foreign state actor.
Interlock Ransomware Gang Exploited Cisco Firewall Zero-Day (CVE-2026-20131)
Amazon's CISO released a report revealing that the Interlock ransomware gang exploited CVE-2026-20131, a critical vulnerability in Cisco Secure Firewall Management Center software, beginning January 26, before Cisco disclosed the bug on March 4. Cisco updated its advisory on March 19 to confirm exploitation. Interlock had a week's head start to compromise organizations before defenders knew to look for the vulnerability. Amazon discovered information on exploitation through a misconfigured infrastructure server serving as a staging area for the ransomware gang. The ransom note invoked multiple data protection regulations, reflecting Interlock's practice of citing regulatory exposure to pressure victims with threats of regulatory fines and compliance violations. Interlock has historically targeted organizations that cannot afford operational downtime, including local governments, schools, dialysis treatment companies, and healthcare systems. The FBI and federal agencies said Interlock emerged in September 2024 and has repeatedly targeted critical infrastructure and businesses across North America and Europe, with potential links to the Rhysida ransomware operation.
Intelligence Officials Urge Clean Extension of Section 702 Surveillance Authority
U.S. intelligence leaders presented a united front in favor of extending Section 702 of the Foreign Intelligence Surveillance Act without changes. The White House privately requested an 18-month clean extension of the surveillance power, which enables broad electronic surveillance of overseas security threats. House Speaker Mike Johnson said he will put the renewal on the chamber floor next week, despite opposition from hardline Republicans and progressive Democrats who want more privacy safeguards, including a warrant requirement for accessing the Section 702 database. The authority expires April 20 without congressional action. CIA Director John Ratcliffe said he wished the reauthorization was longer than 18 months, noting the tool provides more than half of the important, actionable intelligence the president relies on. FBI Director Kash Patel said he would like five to ten years. Director of National Intelligence Tulsi Gabbard, who in 2020 introduced legislation to repeal the authority, said she would support the president's decision to execute this. A coalition of privacy and civil liberty groups sent a letter arguing against renewing FISA without limits at a time when the federal government's use of artificial intelligence is rapidly expanding.
White House Rejects Cyber "Letters of Marque" Speculation
The Trump administration is not considering cyber letters of marque or allowing private companies to carry out cyberattacks on behalf of the U.S. government, senior White House officials clarified this week. Thomas Lind, senior adviser at the Office of the National Cyber Director, acknowledged at the Prague Cyber Security Conference that the administration's national cyber strategy calls for a more aggressive approach against criminal networks and adversarial governments. However, Lind rejected suggestions that this meant relying on private companies to conduct offensive operations, stating "We're not interested in fighting pirates with pirates." National Cyber Director Sean Cairncross specified that "private sector, industry or companies engaging in cyber offensive campaigns - that's not what we're talking about." Officials described a model for collaboration centered on coordination and scale, with the private sector helping identify threats and providing support for government-led actions. Many companies have existing processes for coordinating with U.S. law enforcement to disrupt hostile actors.
CBP Confirms Location Data Sourced from Real-Time Bidding Ad Systems
A document obtained by 404 Media confirms that Customs and Border Protection sourced location data from real-time bidding, the technical system powering targeted ads shown on nearly every website and app. CBP acknowledged that "RTB-sourced location data is recorded when an advertisement is served," marking the first time the agency has confirmed the location data it buys is partially sourced from the online advertising ecosystem. The document covers a 2019-2021 pilot program, but CBP and other federal agencies have continued to purchase and use commercially obtained location data. Location data comes from two sources: software development kits embedded in apps and real-time bidding. Apps for weather, navigation, dating, fitness, and family safety often request location permissions to enable features, then share location with data brokers through SDKs or indirectly through RTB. Federal law enforcement agencies have been buying location data from shady data brokers that most people have never heard of. ICE, CBP, and the FBI have purchased location data from the data broker Venntel. Last year, ICE purchased a spy tool called Webloc that gathers the locations of millions of phones and allows filtering by unique advertising IDs assigned by Apple and Google.
Senators Demand Answers on Meta's Facial Recognition Smart Glasses Plans
Senators demanded answers on Meta's plans for facial recognition in smart glasses following a New York Times report and EPIC letters to federal and state regulators last month. The senators' inquiry echoes warnings raised by the Electronic Privacy Information Center in a series of letters regarding privacy risks from facial recognition capabilities in consumer wearable devices. The development follows growing concerns about biometric data collection by technology companies without adequate user consent or regulatory oversight.
FTC Should Develop Privacy-Protective Age Assurance Standards, Advocacy Groups Say
The Center for Digital Democracy, the Electronic Privacy Information Center, and Fairplay sent a letter urging the Federal Trade Commission to revise its enforcement policy statement on age verification under the Children's Online Privacy Protection Act and develop stronger, privacy-protective age assurance standards. The organizations argue that current age verification approaches pose privacy risks and that the FTC should establish standards that protect children's privacy while minimizing data collection from all users.
New Android Malware Perseus Targets Note-Taking Apps
Researchers at ThreatFabric discovered Perseus, a new Android malware masking itself within television streaming apps to steal passwords, banking data, and spy on personal notes. Perseus is being actively distributed primarily targeting users in Turkey and Italy. The malware builds on leaked code from Cerberus, a banking trojan whose source code was exposed in 2020. Attackers disguise the malware inside apps offering IPTV services, platforms often used for pirated content downloaded outside Google Play. Once installed, Perseus uses overlay attacks and keylogging to capture credentials. Perseus actively scans infected devices for note-taking apps such as Google Keep, Evernote, and Simple Notes, then opens them and extracts stored content. Notes can contain highly sensitive information including passwords, financial details, and recovery phrases.
Trump's Birthright Citizenship Order Conflicts with 8 U.S.C. § 1401(a)
Legal scholars argue that President Trump's executive order 14160 attempting to redefine birthright citizenship violates 8 U.S.C. § 1401(a), part of the 1952 Immigration and Nationality Act, which states: "The following shall be nationals and citizens of the United States at birth: (a) a person born in the United States, and subject to the jurisdiction thereof." This language closely tracks the 14th Amendment's citizenship clause. Solicitor General D. John Sauer claims these words do not citizenize American-born children of illegal aliens or temporary visitors, and that birthright citizenship pivots on the status and domicile of an American baby's parents. However, neither the 14th Amendment nor Section 1401(a) uses the words "parent," "parents," "mother," "father," or "domicile." Scholars note that no one significant in 1952 read this statutory provision as Sauer now reads it, and the Supreme Court in United States v. Wong Kim Ark (1898) held that "the fundamental principle of citizenship by birth within the dominion was reaffirmed in the most explicit and comprehensive terms" by the 14th Amendment.
Prediction Markets Create Incentives to Corrupt Information
A Times of Israel war correspondent faced a campaign of harassment and death threats after reporting that an Iranian ballistic missile struck an open area outside Jerusalem on March 10. Over $14 million had been wagered on a Polymarket bet titled "Iran strikes Israel on...?" with a clause specifying intercepted missiles would not count. The reporter's accurate confirmation that a missile warhead impacted the ground stood between gamblers and their winnings. Gamblers sent threatening messages across email, WhatsApp, Discord, and X. Someone fabricated a fake screenshot showing the reporter had agreed to change his story, then circulated it on social media. The incident demonstrates how attaching high financial stakes to single metrics creates powerful incentives to game the metric rather than reflect reality, a phenomenon known as Goodhart's Law. The case raises questions about prediction markets' promise to improve information quality when participants can threaten journalists more cheaply than accepting bad bets.
Audit cookie consent mechanisms to ensure no cookies execute before users provide informed, granular consent separated by purpose (marketing, analytics, functional) as required by Article 7 GDPR. The Croatian DPA's €20,000 fine demonstrates enforcers' focus on preloaded cookies that process data before meaningful consent.
Implement Microsoft Intune hardening measures immediately following the FBI and CISA advisory: role-based access controls with minimum permissions, multi-factor authentication with Microsoft Entra ID, and approval workflows requiring second administrative account sign-off for sensitive actions like device wiping. The Iran-linked Stryker attack wiping 200,000 devices shows the catastrophic impact of compromised endpoint management systems.
Review third-party SDKs and real-time bidding integrations for location data collection and sharing. CBP's confirmation that it sources location data from ad tech systems means mobile app location data can reach government agencies through advertising supply chains. Implement granular user controls for location data sharing and disclose these data flows in privacy policies.
Verify BIPA compliance for third-party meeting tools if your organization operates in Illinois or has Illinois employees. The Fireflies.AI lawsuit demonstrates that vendors automatically joining meetings and processing voice data from participants who never consented create BIPA exposure. Review vendor contracts and ensure written notice and consent before biometric data collection.
Strengthen SAR response procedures and tracking to meet the one-month statutory deadline under Article 12(3) GDPR and equivalent data protection laws. The UK ICO's reprimand of City of London Police for less than 50% timely SAR responses shows enforcers expect compliance above 90%. Implement monitoring systems and escalation procedures as deadlines approach.