CVE-2026-3502
Get tomorrow's brief in your inbox
Today: FCC proposes $4.5 million fine against Voxbeam Telecommunications for accepting illegal robocall traffic from unlisted foreign provider Axfone. CISA orders federal agencies to patch CVE-2026-3502 in TrueConf video conferencing software within two weeks after Chinese hackers exploited the flaw in espionage campaign. FAA maintains nationwide 21-month flight restriction criminalizing drone operation within half-mile of any ICE or CBP vehicle, drawing constitutional challenges from EFF and news organizations.
FCC Proposes $4.5 Million Fine Against Voxbeam for Foreign Robocall Traffic
The Federal Communications Commission proposed a $4.5 million fine against voice service provider Voxbeam Telecommunications for accepting suspicious call traffic from Czechia-based Axfone, an unauthorized foreign provider not listed in the FCC's Robocall Mitigation Database. Between March 31 and April 3, 2025, Voxbeam transmitted tens of thousands of financial impersonation robocalls spoofing Bank of America, Chase Bank, and other institutions' fraud prevention numbers. The calls originated from dormant Voxbeam accounts inactive since 2018. Voice service providers are barred from accepting traffic from unlisted providers under FCC rules designed to block higher-risk robocall sources. The fine is not yet final as Voxbeam will have opportunity to respond before the FCC makes a permanent decision.
Mizuno Data Breach Class Action Settlement (Case No. 25EV010647)
Mizuno agreed to settle claims arising from a November 2024 data breach that compromised names, Social Security numbers, financial account numbers, driver's license numbers, and passport numbers. The settlement provides up to $475 in reimbursement for ordinary losses (bank fees, travel expenses, four hours lost time at $15/hour), up to $5,000 for extraordinary identity theft losses, or a $50 alternative cash payment. All class members receive 24 months of one-bureau credit monitoring with $1 million fraud protection. Claims must be submitted by June 15, 2026. The final approval hearing is scheduled for June 4, 2026 in the State Court of Fulton County, Georgia.
JCPenney Faces BIPA Class Action Over Skincare Tool Facial Scans (Case No. 2026CH02396)
Christine Borovoy filed a class action lawsuit against Penney OpCo LLC in Cook County Circuit Court alleging violations of the Illinois Biometric Information Privacy Act. The complaint claims JCPenney's "Skincare Advisor," an AI-powered product recommendation tool on the company's website and mobile app, captured and stored facial scans without providing required notice, obtaining written informed consent, or publishing a biometric data retention policy. The plaintiff alleges JCPenney's violations were knowing and willful or in reckless disregard of BIPA requirements. The case seeks to represent Illinois consumers who scanned their faces using the tool within the past five years.
CVS and Caremark Sued for Pharmacy Benefit Manager Kickback Scheme (Case No. 1:26-cv-00162)
Roofers' Unions Welfare Trust Fund filed a federal class action in Rhode Island alleging CVS Health Corp. and pharmacy benefit manager CaremarkPCS Health sold access to drug formularies in exchange for kickbacks from pharmaceutical manufacturers. The complaint claims CVS and Caremark diverted payments to subsidiary Zinc Health Services for routine PBM services instead of securing greater rebates for customers, maximizing defendants' profits while inflating prescription drug costs. The trust fund alleges violations of the Racketeer Influenced and Corrupt Organizations Act, unjust enrichment, breach of contract, and breach of implied covenant of good faith and fair dealing. The case seeks to represent all entities that paid for Caremark services inflated by the alleged scheme from March 18, 2020 to present.
Lemon Perfect Class Action Challenges "No Artificial Sweeteners" Claim (Case No. 3:26-cv-01153)
Star Ghanaat filed a class action in Alameda County Superior Court alleging The Lemon Perfect Company falsely advertises beverages as containing "no artificial sweeteners" when they contain stevia leaf extract. The complaint argues that stevia leaf extract is not crude stevia leaf but rather a highly purified, chemically processed sweetener, and crude stevia leaves are not approved for food use in the United States. The plaintiff alleges violations of California consumer protection laws and breach of express warranty on behalf of California consumers who purchased the products within the applicable statute of limitations.
Navitas Organics Chia Seeds Salmonella Recall Sparks Federal Lawsuit (Case No. 9:26-cv-794)
Jennifer Soumekh filed a class action in the U.S. District Court for the Eastern District of New York alleging Navitas LLC failed to disclose Salmonella contamination in its Organic Chia Seeds. The complaint stems from a January 23, 2026 voluntary recall affecting 8-ounce bags with best-by date of April 2027 and lot code W31025286, distributed through Whole Foods Market, Target, Amazon, iHerb, and Vitacost.com. The plaintiff claims she purchased contaminated chia seeds in January 2026 from Whole Foods in Manhasset, New York for $7.59, and that Navitas Organics' USDA Organic, non-GMO, and gluten-free marketing misled consumers about product safety. The lawsuit alleges violations of New York General Business Law and breach of warranties.
Supreme Court Oral Argument Analysis: Trump v. Barbara Birthright Citizenship Case
The Supreme Court heard over two hours of oral argument on April 1 in the challenge to President Trump's executive order ending birthright citizenship for children born in the U.S. to undocumented parents or those on temporary visas. Solicitor General D. John Sauer argued the citizenship clause's phrase "subject to the jurisdiction thereof" requires parental allegiance and domicile, excluding unauthorized immigrants and temporary visa holders. ACLU National Legal Director Cecillia Wang pressed the broader reading that virtually everyone born on U.S. soil is a citizen except children of foreign diplomats and hostile occupying forces. Transcript analysis shows the argument was dominated by history and originalism, with Justice Clarence Thomas leading at 37.2 originalist references per 1,000 words and Justice Ketanji Brown Jackson close behind at 34.2. Every lower court has blocked the executive order.
Minnesota Files Federal Lawsuit to Force Trump Administration Cooperation in ICE Shooting Investigations
Hennepin County Attorney Mary Moriarty and Minnesota Attorney General Keith Ellison filed a federal lawsuit against the Departments of Homeland Security and Justice over the Trump administration's refusal to release evidence in three ICE shootings: Renee Good (killed), Julio Cesar Sosa-Celis (wounded), and Alex Pretti (killed on January 24). The lawsuit, characterized as "unprecedented in American history," seeks to compel federal cooperation after the administration declined to release shooter names despite their identification by the Minnesota Star Tribune and ProPublica. The case presents a constitutional test of supremacy clause immunity, which protects federal officers from state prosecution if acting lawfully within duty scope. Legal experts note the Supreme Court has not addressed supremacy clause immunity in over 100 years, and odds are stacked against Minnesota overcoming the defense. If charges are filed, logistical challenges include locating agents and potential extradition requirements.
CISA Orders Federal Agencies to Patch TrueConf Video Conferencing Vulnerability by April 16
The Cybersecurity and Infrastructure Security Agency added CVE-2026-3502, a TrueConf video conferencing vulnerability with severity score 7.8, to its Known Exploited Vulnerabilities catalog with a two-week patching deadline. CISA confirmed active exploitation following Check Point Research reports of a Chinese espionage campaign dubbed TrueChaos targeting government entities in Southeast Asia. The flaw affects TrueConf's updater validation mechanism, allowing attackers controlling on-premises servers to distribute and execute arbitrary files across connected endpoints. Chinese hackers exploited the trusted update channel to distribute malicious updates including the Havoc penetration testing tool. TrueConf serves approximately 100,000 organizations globally across government, military, and critical infrastructure sectors, particularly in locations requiring offline or air-gapped secure communications. TrueConf released a patch in March 2026.
GSA Proposes AI Procurement Rules Limiting Safety Guardrails
The General Services Administration proposed procurement rules requiring contractors and service providers to license AI systems to the government for "all lawful purposes" and prohibiting AI systems from refusing outputs based on discretionary safety policies. Comments filed by the Electronic Frontier Foundation, Center for Democracy and Technology, Protect Democracy Project, and Electronic Privacy Information Center argue the provisions would make AI tools less safe and less useful. The draft rules include requirements that contractors disable safety guardrails if they might prevent government requests, contradicting widespread public concerns about AI safety. The provisions would become standard components of every federal contract if adopted. Commenters note the rules include technologically incoherent "anti-Woke" requirements and fail to serve the public interest in promoting privacy, safety, and responsible innovation.
Senators Request DNI Warning That VPN Use May Trigger Domestic Surveillance Under Section 702
Senators Ron Wyden, Elizabeth Warren, Edward Markey, Alex Padilla, and Representatives Pramila Jayapal and Sara Jacobs sent a letter to Director of National Intelligence Tulsi Gabbard requesting public guidance warning Americans that VPN use may subject them to domestic surveillance. Because VPNs obscure users' true locations and intelligence agencies presume unknown-origin communications are foreign, Americans using VPNs may inadvertently waive privacy protections under Section 702 of FISA. The NSA can legally intercept communications appearing "foreign" due to VPN routing, and the FBI can query the data. The letter notes Americans spend billions annually on commercial VPN services, many offered by foreign-headquartered companies using overseas servers. While federal agencies including the FBI, NSA, and FTC recommend VPN use for privacy protection, following that advice may cost Americans the protections they seek. The lawmakers request DNI issue guidance clarifying that VPNs advertised as privacy protection could negatively impact rights against U.S. government surveillance.
European Commission AWS Breach Exposes 92GB of Data via Trivy Supply Chain Compromise
CERT-EU attributed a March 19, 2026 data breach at the European Commission to hacking group TeamPCP, which exploited the Trivy supply chain compromise to steal approximately 92 gigabytes of compressed data from the Commission's Amazon Web Services account. The breach involved misuse of a secret Amazon API key and affected the Europa.eu platform, impacting 42 internal clients and at least 29 EU entities. The stolen dataset included nearly 52,000 files totaling 2.2 gigabytes of outbound email communications, mostly automated messages but with potential personal data exposure through bounceback notifications. The attackers gained management rights for the compromised AWS API key, potentially enabling lateral movement to other Commission AWS accounts, though no such movement has been detected. ShinyHunters posted the stolen data on its dark web site on March 28. CERT-EU confirmed attribution based on timing, targeted resources, and the Commission's use of a compromised Trivy version received through normal software update channels.
Massachusetts Emergency Communications System Hit by Cyberattack
The Patriot Regional Emergency Communications Center serving Pepperell, Ashby, Dunstable, Groton, and other northern Massachusetts towns suffered a cyberattack beginning April 1, 2026 that impacted town and public safety computer systems. While 9-1-1 phone systems remain operational, non-emergency and business phone lines are out of service. The center dispatches police, fire, and medical services for multiple municipalities and is linked to CodeRED emergency notification service. Federal law enforcement has been notified and cybersecurity experts are determining what information was accessed or stolen. CodeRED parent company Crisis24 suffered its own ransomware attack in November 2025, during which hackers stole information on local officials who controlled municipal CodeRED systems and urged users who reused CodeRED passwords to change them immediately.
FAA Nationwide Drone Flight Restriction Criminalizes Recording ICE Operations
The Federal Aviation Administration issued Temporary Flight Restriction FDC 6/4375 on January 16, 2026, prohibiting any person from flying drones within 3,000 horizontal feet of any Departments of Defense, Energy, Justice, or Homeland Security "facilities and mobile assets," including ground vehicle convoys and escorts. The restriction lasts 21 months until October 29, 2027 and covers the entire nation. Violators face criminal and civil penalties and risk drone seizure or destruction. In practical terms, the TFR criminalizes drone operation within half a mile of any ICE or CBP vehicle, including unmarked rental cars and vehicles with switched or missing license plates. The EFF, New York Times, and Washington Post sent a January 2026 letter demanding the FAA lift the restriction, arguing it violates First Amendment rights to record law enforcement and Fifth Amendment due process by failing to provide fair notice before property deprivation. The FAA has not responded over two months later. The restriction violates FAA regulations requiring specification of hazards necessitating TFRs and provision of contact points for accredited news representatives to obtain permission.
Supreme Court Applies Heightened Scrutiny to Professional Licensing in Chiles v. Salazar
The Supreme Court held in Chiles v. Salazar that heightened First Amendment scrutiny applies to state professional licensing constraints predicated on viewpoints expressed by licensees, including during service provision. The decision involved Colorado's law prohibiting conversion therapy and requires states to meet heightened scrutiny standards before constraining licensing based on viewpoint. While the ruling does not affect laws prohibiting aversive physical interventions like electric shocks or nausea induction, it reaches conversion therapy delivered via talk therapy seeking to change patient behavior and identity. Justice Jackson's dissent noted the decision gives legitimacy to scientifically-discredited conversion therapy causing real harm and makes it harder for states to prevent such harm. The decision also protects therapists supporting LGBTQ+ patients from actions like those recently announced by Texas Attorney General Ken Paxton threatening licenses of therapists providing gender-affirming care.
Trump Administration Rewrites BEAD Broadband Grant Program, Creates $21 Billion Question
The Trump administration's National Telecommunications and Information Administration rewrote the $42.5 billion Broadband, Equity, Access and Deployment program to eliminate provisions ensuring affordable broadband for poor people and to prioritize satellite broadband subsidies for Elon Musk's and Jeff Bezos' networks over local fiber optics. The changes created a $21 billion pool of "non-deployment funds" from claimed savings, triggering a fight over fund usage. Congress and the infrastructure law specify the money must be dedicated to expanding broadband access. Commerce Secretary Howard Lutnick stated non-deployment funds would not be rescinded, but NTIA has not issued expected guidance on how states can use the funds. The administration threatened to withhold BEAD funding from states that stand up to telecom monopolies, insist on affordable pricing, or attempt to regulate AI, though such withholding would be illegal.
300 Immigration Habeas Cases Show Pattern of Government Non-Compliance with Court Orders
A dataset compiled by Katherine Pompilio and Benjamin Wittes documents 300 immigration habeas corpus cases since early 2026 in which courts found the federal government failed to comply with judicial orders. Violations include missed filings, delayed releases, unauthorized transfers, and failure to return property. U.S. District Judge Patrick Schiltz in Minnesota identified 210 orders in 143 cases with which the government failed to comply, stating "the court is not aware of another occasion in the history of the United States in which a federal court has had to threaten contempt again and again and again to force the United States government to comply with court orders." U.S. District Judge Michael E. Farbiarz in New Jersey ordered the government to identify its own compliance failures, producing a list of more than 50 failures that U.S. District Judge Christine P. O'Hearn later described as incomplete. The data visualization allows users to search cases by jurisdiction and violation type.
TrueConf CVE-2026-3502 Patch Deadline: Federal agencies must patch the TrueConf video conferencing vulnerability by April 16, 2026. Private sector organizations using TrueConf should apply the March 2026 update immediately, audit update server access controls, and review recent update deployments for malicious packages indicating compromise.
Illinois BIPA Compliance for Biometric Tools: Retailers and service providers deploying AI-powered tools that collect facial scans or other biometric data in Illinois must provide clear written notice before collection, obtain separate written informed consent, and publish biometric data retention and destruction schedules. Review all customer-facing tools for hidden biometric collection capabilities.
Data Breach Settlement Precedent: Organizations planning breach response programs should review the Mizuno settlement terms establishing tiered reimbursement structures: up to $475 for ordinary losses including four hours lost time at $15/hour, up to $5,000 for extraordinary identity theft losses, and 24 months credit monitoring with $1 million fraud protection as baseline offering.
VPN Section 702 Surveillance Risk: IT departments should reassess VPN policies considering that routing communications through foreign endpoints may trigger NSA interception under Section 702 of FISA. Document VPN provider jurisdictions, inform users of surveillance implications, and consider hybrid approaches limiting VPN use to corporate access rather than routing all domestic personal communications through foreign servers.
FCC Robocall Mitigation Database Verification: Voice service providers must verify all upstream traffic sources are listed in the FCC Robocall Mitigation Database and implement automated blocking for traffic from unlisted providers. Monitor dormant customer accounts for unauthorized reactivation and implement account activity thresholds triggering security reviews before call transmission resumes.