Get tomorrow's brief in your inbox
Today: The Trump administration is weighing whether to defy a FISA Court order requiring privacy fixes to Section 702 surveillance tools, with reauthorization scheduled before the end of April. Virginia signed a law banning the sale of precise geolocation data, joining a small group of states with targeted location privacy protections. Four major companies face pixel tracking class actions in California alleging wiretap violations for intercepting communications without consent.
McGraw Hill Acknowledges Data Leak from Salesforce Misconfiguration
Educational publisher McGraw Hill confirmed unauthorized access to non-sensitive data following a Salesforce platform misconfiguration affecting multiple organizations. The ShinyHunters cybercriminal group claimed to have stolen 45 million Salesforce records and threatened a leak by April 14 if ransom was not paid. McGraw Hill stated the breach involved limited, non-sensitive information from a Salesforce-hosted webpage and did not include Social Security numbers, financial data, or student records. Salesforce maintains no platform compromise occurred and attributes the incidents to customer misconfigurations rather than platform vulnerabilities. ShinyHunters previously targeted dating apps Bumble and Match Group, Canada Goose, the University of Pennsylvania, and the European Commission before members were arrested in the U.S. and U.K.
$24.75M Grubhub Driver Misclassification Settlement (Case No. 15-cv-05128-JSC)
Grubhub agreed to pay $24.75 million to settle claims that it misclassified California delivery drivers as independent contractors instead of employees between December 3, 2014, and March 13, 2026. The settlement in Lawson, et al. v. Grubhub Holdings Inc., et al., pending in the U.S. District Court for the Northern District of California, resolves allegations that Grubhub violated California law by failing to reimburse drivers for business expenses and failing to pay minimum wage and overtime. Class members will receive payments based on miles driven while using the Grubhub platform, with a minimum payment of $25. Grubhub has not admitted wrongdoing. The final approval hearing is scheduled for July 30, 2026.
Pixel Tracking Class Actions Target Hilton, LinkedIn, PNC Bank, and Wells Fargo
Four companies face class action lawsuits in California federal courts alleging they used pixel tracking and similar technologies to intercept users' online communications without consent in violation of the California Invasion of Privacy Act and the Federal Wiretap Act. Hilton faces claims that it embedded third-party trackers that intercepted browsing data including page URLs and search behavior for identity resolution and targeted advertising. LinkedIn is accused of using hidden scripts to scan browsers for installed extensions, potentially revealing political views, religious beliefs, and employment status tied to real identities. PNC Bank allegedly embedded pixel trackers from Pinterest, LinkedIn, and X that captured browsing activity on personal finance pages. Wells Fargo faces allegations that it used Google and Adobe trackers to monitor visits to debt-related pages with persistent identifiers enabling cross-session tracking. Plaintiffs argue the tracking occurred automatically during page loads without user knowledge or consent mechanisms. All four complaints emphasize real-time interception rather than after-the-fact data collection.
$70M Baby Formula Verdict Against Abbott Laboratories
An Illinois jury awarded $70 million ($53 million compensatory, $17 million punitive) to four families whose premature infants developed necrotizing enterocolitis (NEC) after consuming Abbott's Similac Special Care 24 formula. The lawsuits, including Mendez v. Abbott Laboratories, Case No. 2022-L-005377, alleged Abbott failed to warn that cow's milk-based formula increased NEC risk in premature infants. All four children survived but suffered long-term complications requiring bowel surgery. The judge allowed punitive damages after finding evidence Abbott may have concealed risks. Abbott denies the allegations and maintains no reliable scientific evidence links its formula to NEC. This verdict follows a 2024 Illinois jury award of $60 million in Watson v. Mead Johnson for a similar NEC claim involving Enfamil formula. Thousands of similar lawsuits are pending against Abbott and Mead Johnson over cow's milk-based formula and NEC risk.
Trump $10 Billion Defamation Suit Against Murdoch Dismissed
Federal Judge Darrin Gayles dismissed President Trump's $10 billion defamation lawsuit against the Wall Street Journal, Rupert Murdoch, News Corp, and two reporters for publishing a story about a letter allegedly written by Trump in Jeffrey Epstein's birthday book. Trump denied writing the letter before publication, but the court found he failed to adequately allege actual malice under the New York Times v. Sullivan standard. The court noted the reporters contacted Trump, the FBI, and the DOJ before publication, printed Trump's denial, and allowed readers to decide for themselves. The court ruled that reaching out for comment and printing the denial alongside the evidence demonstrated responsible reporting, the opposite of actual malice. Actual malice requires showing the defendant either knew the story was false or harbored serious doubts about its truth, not merely that the subject denied the allegations.
Supreme Court to Consider Federal Court Review of State Judgments in T.M. v. University of Maryland Medical System
The Supreme Court will hear arguments April 21 in T.M. v. University of Maryland Medical System Corporation about when lower federal courts may review state court judgments under the Rooker-Feldman doctrine. T.M., a Maryland woman involuntarily committed after a psychotic episode, signed a consent order in state court requiring her to continue medication and dismiss other lawsuits against the hospital. She later filed a federal lawsuit seeking to declare the consent order unconstitutional. The U.S. District Court for the District of Maryland dismissed the case under Rooker-Feldman, which bars lower federal courts from reviewing state court judgments that became final before federal proceedings commenced. The case highlights confusion over lower court jurisdiction despite the Supreme Court's 2005 attempt to resolve the issue in Exxon Mobil Corp. v. Saudi Basic Industries Corp., which limited Rooker-Feldman to cases where plaintiffs ask federal courts to reverse or modify state judgments.
Supreme Court to Hear Geofence Warrant Fourth Amendment Challenge
The Supreme Court will hear arguments April 27 in Chatrie v. United States on whether geofence warrants violate the Fourth Amendment. The case has generated 31 amicus briefs, including eight supporting neither party, reflecting disagreement over how to frame the issue. Microsoft argues users maintain reasonable expectations of privacy in cloud data and that reverse warrants must be sufficiently particular and supported by individualized probable cause, but takes no position on whether the specific warrant in Chatrie's case complied with the Fourth Amendment. The Policing Project at NYU School of Law urges the Court to resolve the case narrowly to avoid "embarrassing the future" given the technical complexities, liberty risks, and public safety benefits of these tools, arguing the right fix is legislative rather than judicial.
Supreme Court to Consider SEC Disgorgement Remedy in Sripetch v. SEC
The Supreme Court will hear arguments next week in Sripetch v. SEC on whether the Securities and Exchange Commission can use disgorgement to force wrongdoers to turn over profits to the government without proving the activities directly harmed customers. Ongkaruck Sripetch pleaded guilty to selling unregistered securities and was sentenced to 21 months' imprisonment. In a separate civil enforcement action, the SEC sought to force him to disgorge more than $6 million in profits. The court of appeals declined to require the SEC to prove Sripetch's activity caused pecuniary harm to customers, contrary to requirements imposed by other circuit courts. Sripetch argues the Supreme Court's 2020 decision in Liu v. SEC compels reversal because Liu repeatedly stated disgorgement's point is to pay fair compensation to the person wronged, requiring a victim who suffered harm. The government argues disgorgement has a long history as restitution forcing wrongdoers to turn over ill-gotten gains, and Liu is satisfied so long as the SEC proves the defendant profited from illegal activities and limits recovery to those profits.
NIST to Limit CVE Enrichment as Submissions Surge
The National Institute of Standards and Technology announced it will only enrich CVE records meeting specific criteria, abandoning its longstanding mission to categorize every cybersecurity vulnerability. NIST will prioritize CVEs in CISA's catalog of exploited vulnerabilities (enriched within one day of notice), products used by the federal government, and software deemed critical. Submissions during the first three months of 2026 were nearly one-third higher than the same period in 2025. NIST enriched nearly 42,000 CVEs in 2025, 45% more than any prior year, but this productivity increase cannot keep up with growing submissions driven by AI code review tools discovering new but often minor vulnerabilities. NIST will not enrich the backlog of CVEs with NVD publish dates earlier than March 1, 2026. The agency said the changes allow focus on critical CVEs while developing automated systems and workflow enhancements for long-term sustainability.
UK Government Warns Businesses to Address Cyber Risks Amid AI Developments
The British government warned businesses to strengthen cyber defenses following Anthropic's release of Mythos, an AI model demonstrating advanced capabilities for autonomously discovering and exploiting software vulnerabilities. The UK's AI Security Institute evaluated Mythos as more capable at cyber offense than any model previously assessed but noted significant limitations. AISI described Mythos as at least capable of autonomously attacking small, weakly defended, and vulnerable enterprise systems where network access has been gained, but emphasized test environments were deliberately simplified and lacked active security teams, monitoring tools, and detection risks. NCSC Chief Executive Richard Horne said AI will increasingly expose organizations that have not taken appropriate cyber security steps, but defenders who adopt AI effectively can also strengthen detection and response. The Bank of England governor warned of potential systemic cyber risks. Security expert Bruce Schneier cautioned that early claims risk overstating the immediate threat, noting similar warnings have accompanied previous AI-enabled tool generations.
Virginia Bans Sale of Precise Geolocation Data
Virginia Governor Abigail Spanberger signed S.B. 338 into law, prohibiting the sale of Virginians' precise geolocation data. The law makes Virginia one of a small number of states with targeted location privacy protections addressing the data broker market. The legislation follows growing concerns about warrantless government access to location data purchased from commercial brokers and the use of geofence warrants targeting individuals based on their presence in specific areas. No effective date or compliance timeline was specified in the brief announcement.
EPIC Urges Meta to Halt Facial Recognition in Ray-Ban Smart Glasses
EPIC joined an ACLU-led coalition of more than 70 organizations urging Meta to halt and publicly disavow plans to add facial recognition to its Ray-Ban smart glasses. EPIC has opposed the plan since the New York Times broke news of its existence in February. The day the story broke, EPIC asked the Federal Trade Commission and other regulators to investigate. The coalition's open letter argues the technology raises significant privacy risks by enabling covert identification and tracking of individuals in public spaces without their knowledge or consent.
EPIC Defends South Carolina Age-Appropriate Design Code Against First Amendment Challenge
EPIC filed an amicus brief defending South Carolina's Age-Appropriate Design Code (H. 3431) against a tech industry lawsuit claiming surveillance-based feeds are protected by the First Amendment. South Carolina's AADC protects minors' sensitive data and gives users the ability to opt out of personalized algorithmic feeds that surveil users to manipulate them into staying on platforms. EPIC argues that surveillance-based data collection and algorithmic manipulation are not protected speech under the First Amendment and that states can regulate harmful business practices targeting children without violating platforms' speech rights.
Maine Legislature Fails to Pass Comprehensive Privacy Law
The Maine Online Data Privacy Act (LD 1822) failed to pass the Maine House of Representatives by five votes on its final vote. The bill closely mirrored Maryland's 2024 privacy law and would have extended strong privacy protections including data minimization requirements and enhanced protections for sensitive data to Maine residents. Maine remains without comprehensive consumer privacy legislation despite momentum in other states.
Trump Administration Weighing Appeal of FISA Court Order on Section 702 Surveillance
The Trump administration is considering whether to appeal a March 17 FISA Court ruling that objected to filtering tools used by the CIA, FBI, and NSA to process Section 702 surveillance data. The court's classified annual recertification allows the program to continue collecting phone calls and emails through March 2027 even if Congress fails to renew the statute by the end of April. The court ordered the government to re-engineer filters that allow analysts to drill down data to specific people who communicated with foreign persons, finding agencies are using the filter to search for U.S. persons in violation of restrictions. The administration wants Congress to extend Section 702 without changes rather than codifying the court's order during reauthorization. Senator Ron Wyden warned the administration's consideration of an appeal represents a highly aggressive and unusual move indicative of an administration that would exploit every angle to expand surveillance at the expense of Americans' rights. The court ruling needs to be declassified so Americans can understand what the administration is doing, Wyden said.
Government AI Analysis of Data Obtained Without Warrants
The government plans to use AI to analyze Americans' information obtained without warrants through purchases from data brokers and incidental collection from foreign intelligence surveillance. Congress is considering these practices as part of Section 702 reauthorization scheduled before the end of April. Privacy advocates argue AI analysis of warrantless data collection exponentially increases privacy risks and call for legislative action to close loopholes around Fourth Amendment protections before any Section 702 renewal.
EFF Calls for Release of Journalist Ahmed Shihab-Eldin Detained in Kuwait
EFF called on Kuwait to immediately release journalist Ahmed Shihab-Eldin, a dual American-Kuwaiti citizen arrested March 3 while visiting family. The Committee to Protect Journalists reported he is charged with spreading false information, harming national security, and misusing his mobile phone. Shihab-Eldin published footage of a U.S. Air Force F-15E Strike Eagle crash and posted about the incident on Substack, noting video showed local residents assisting crash survivors. Kuwait's Ministry of Interior warned the same day not to photograph or publish clips or information related to missiles or relevant locations. A new decree bans circulation of reports that "undermine the prestige of the military" or erode public trust, imposing penalties of three to 10 years imprisonment and fines between 5,000 and 10,000 Kuwaiti dinars. Shihab-Eldin has not been seen or heard from in nearly six weeks.
Network Shutdowns Reach Record High in 2024
Authorities imposed 304 internet shutdowns across 54 countries in 2024, the highest number ever recorded. EFF analysis traces the evolution from Egypt's 2011 five-day internet shutdown during Arab Spring protests to today's normalized infrastructure of control. Governments have formalized power to cut connectivity through legal frameworks and telecommunications industry consolidation. Iran's internet has been intermittently disrupted for months. In India, recurring shutdowns and throttling have become routine responses to protests and unrest. The Telecommunications Industry Dialogue, formed in 2013 in partnership with the Global Network Initiative, established shared norms for telecom companies but has done little to constrain legal and political pressures driving shutdowns or prevent companies from complying with government orders.
Section 702 Reauthorization: Monitor congressional action on Section 702 before the end of April. Prepare for potential expansion of AI-driven analysis of communications data collected under foreign intelligence authorities. Review policies for handling employee communications that may be subject to incidental collection.
Pixel Tracking and Wiretap Claims: Audit all third-party tracking technologies including pixels, session replay, and browser fingerprinting scripts. Deploy consent mechanisms before any tracking occurs and update privacy policies to accurately disclose tracking technologies and data sharing with third parties. California Invasion of Privacy Act and Federal Wiretap Act claims increasingly target real-time interception during page loads.
Virginia Geolocation Ban: Companies selling precise geolocation data must implement controls to prevent sales tied to Virginia residents. Review data broker contracts and processing agreements for compliance with state-level location privacy restrictions.
NIST CVE Prioritization Changes: Supplement the National Vulnerability Database with additional vulnerability intelligence sources including CISA's Known Exploited Vulnerabilities catalog, vendor security advisories, and commercial threat intelligence. NIST will only enrich CVEs in CISA's KEV catalog, federal systems, and critical software starting March 1, 2026.
Grubhub Settlement: California delivery drivers for Grubhub between December 3, 2014, and March 13, 2026, must submit claim forms by June 18, 2026, to receive payments from the $24.75 million settlement. Review independent contractor classifications for gig economy workers to ensure compliance with California employment law.