← Carolina Clear Tech

Legal & Privacy Brief

2026-06-11

Listen to this brief (15:27)

Download MP3
Show Notes

Show Notes - 2026-06-11

Stories Covered

CVEs Referenced

CVE-2026-41091, CVE-2026-45657, CVE-2026-50507

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - June 11, 2026

Today: The Supreme Court ruled 8-1 to uphold FCC fines against AT&T and Verizon for selling customer location data, rejecting telecom arguments that the penalties violated Seventh Amendment jury trial rights. EFF calls for a warrant requirement before Section 702 reauthorization expires, warning that FBI's warrantless access to Americans' communications collected under foreign surveillance authority must end. Congress rushed through H.R. 6028 to make the Register of Copyrights a presidential appointee and sever Copyright Office oversight from the Library of Congress, consolidating power in an office that already favors entertainment industry interests over public rights.

Enforcement Actions

Supreme Court Backs FCC Fines for AT&T, Verizon Location Data Sales

The Supreme Court ruled 8-1 in favor of the FCC's effort to fine AT&T ($57 million), Verizon ($48 million), and T-Mobile ($91 million) for selling customer location data to third parties without proper disclosure or security controls. The case began after a 2018 New York Times investigation showed stalkers, police impersonators, and prison officials routinely purchased access to real-time location data. The 5th Circuit had previously ruled the fines violated AT&T's Seventh Amendment right to a jury trial, relying on the Supreme Court's 2024 SEC v. Jarkesy decision. Only Justice Clarence Thomas dissented. The Biden FCC proposed these fines six years after the initial revelations, and collection remains uncertain under the current administration.

Connecticut AG Investigates Roblox Over Child Safety Allegations

Connecticut Attorney General William Tong launched a major investigation into Roblox over widespread allegations of child exploitation on the gaming and chat platform. The investigation follows mounting concerns about inadequate safety controls for minors using the service.

Litigation Updates

$2.5M Esse Health Data Breach Settlement

Esse Health reached a $2.5 million class action settlement covering individuals whose private information was compromised in a 2025 data breach incident. The settlement provides compensation to affected class members for exposure of protected health information.

X.AI Class Action Alleges Grok Shares User Data with Google, Meta, TikTok

A new class action lawsuit alleges X.AI, operator of the Grok chatbot, shares user data and conversations with third parties including Google, Meta, and TikTok without user consent. The complaint challenges the company's data handling practices and third-party disclosure policies.

Apartments.com Class Action Challenges Hidden Transaction Fees

A class action lawsuit alleges the owner of Apartments.com charges consumers unlawful transaction fees on rent payments made through the platform. The complaint characterizes these as "junk fees" imposed without adequate disclosure.

John Hancock Voiceprint Collection Investigation (Illinois BIPA)

Illinois residents who called John Hancock may have had voiceprints collected without consent in violation of the Illinois Biometric Information Privacy Act (BIPA). The investigation examines whether Amazon's voice technology used in call centers captured biometric identifiers without required disclosures.

Regulatory Guidance

CISA Mandates 3-Day Patching for Critical Vulnerabilities

CISA released a binding operational directive requiring federal civilian agencies to patch certain cyber vulnerabilities within 72 hours. The directive applies to vulnerabilities meeting three of four criteria: internet-exposed, listed in the KEV catalog, automatable exploitation, and potential for adversary control of systems. Agencies have 180 days to implement the new patching timeline. The directive prioritizes vulnerabilities that are currently exploited, automatable, and would grant system control. Non-automatable vulnerabilities meeting other criteria require patching within two weeks. Agencies must check for compromise before patching, as applying patches does not evict threat actors already present.

Microsoft Ships Record 206-CVE Patch Tuesday, Including Wormable Kernel Flaw

Microsoft released 206 CVEs in its June 2026 Patch Tuesday, the largest monthly release in program history. The surge reflects AI-driven vulnerability discovery across the industry. CVE-2026-45657, rated 9.8/10 severity, is a wormable Windows kernel flaw allowing remote code execution with no user interaction. CVE-2026-41091, actively exploited, affects Microsoft Defender and allows privilege escalation. CVE-2026-50507 is a BitLocker encryption bypass disclosed as a zero-day. CISA added CVE-2026-41091 to its Known Exploited Vulnerabilities catalog on May 20.

Privacy Developments

NSO Group Violates Court Order, Continues WhatsApp Phishing

WhatsApp caught NSO Group phishing its users in violation of an existing court order prohibiting the spyware vendor from targeting WhatsApp users. NSO is appealing the order, arguing it will "suffer irreparable harm" if blocked from accessing WhatsApp communications. CISA lists WhatsApp as a secure messaging service for highly targeted individuals in senior government, military, or political positions.

EFF Documents ALPR Mission Creep for Noise Complaints

EFF published findings showing automated license plate reader (ALPR) networks are being used for low-level investigations including noise complaints, not just serious crimes. Surveillance companies have deployed tens of thousands of license plate cameras, creating universal people-tracking networks. The investigation reveals significant mission creep beyond original public safety justifications.

ICE Plans to Distribute Facial Recognition App to 1,000+ Local Agencies

ICE plans to distribute "Task Force Module," a facial recognition app querying 250+ million DHS and State Department records, to over 1,000 local law enforcement agencies. The app will verify immigration status and provide detention instructions to officers. The underlying Mobile Fortify app was deployed without required privacy impact assessments and exhibits reliability problems. DHS acknowledges the app will be used on U.S. citizens to verify their status.

Policy Changes

Section 702 Reauthorization Stalled Over Warrant Requirement

Congress continues temporary extensions of Section 702 FISA surveillance authority as negotiations remain deadlocked over FBI warrant requirements. EFF demands the FBI obtain warrants signed by a judge before accessing Americans' communications incidentally collected under foreign surveillance authority. Current practice allows FBI to query and read U.S.-side communications without probable cause warrants. The Trump administration's appointment of Bill Pulte as Director of National Intelligence raises concerns about politicized use of surveillance data, as Pulte previously used private FHFA data to accuse political opponents of mortgage fraud.

H.R. 6028 Restructures Copyright Office, Removes Library of Congress Oversight

The House passed H.R. 6028 in a voice vote, removing the Library of Congress's supervisory role over the Copyright Office, transferring rulemaking authority to the Register of Copyrights, and making the Register a presidential appointee confirmed by the Senate. The bill transfers DMCA Section 1201 rulemaking authority (digital lock bypass exemptions for security research, repair, preservation, accessibility) from the Librarian to the Register. EFF warns the changes politicize an office that already favors entertainment industry interests over public rights, citing the Office's support for SOPA and flawed AI fair use guidance.

California AB 412 Requires AI Training Data Disclosure (Unworkable Compliance)

California is reconsidering AB 412, which would require AI developers to identify and disclose all registered copyrighted works used in training. EFF submitted opposition testimony explaining the requirement is technically impossible to comply with: no machine-readable copyright registry exists, registration information is often incomplete or unavailable online, and cross-referencing training data against copyright status at scale is infeasible. The bill's definition of "developer" extends beyond large AI companies to indie developers, open-source projects, and nonprofits. Recent amendments exempt universities and government entities.

Compliance Takeaways