← Carolina Clear Tech

Legal & Privacy Brief

2026-08-13

Listen to this brief (12:06)

Download MP3
Show Notes

Show Notes - 2026-08-13

Stories Covered

CVEs Referenced

CVE-2026-62832, CVE-2026-68820

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Today: A $17.5 million class action settlement is open in the 700Credit data breach. The Ninth Circuit ruled Section 230 functions as a defense, not immunity, stripping platforms of early dismissal rights. CISA ordered federal agencies to patch CVE-2026-68820 by August 25 after North Korean hackers exploited it in Operation Dream Job targeting defense sector applicants. The UK's ICO reprimanded ACRO Criminal Records Office for three intrusions that went undetected for two years due to unpatched systems and ignored antivirus alerts.

Enforcement Actions

UK ICO Reprimands ACRO Criminal Records Office for Multi-Year Security Failures

The UK Information Commissioner's Office issued a formal reprimand to ACRO Criminal Records Office after three separate intrusions between July 2021 and June 2023 went undetected. ACRO's public-facing portal ran an unpatched version of Kentico CMS since September 2019, and multiple Trend Micro alerts, including four detections of Mimikatz credential-harvesting attempts, went unreviewed. In the most serious incident, an attacker maintained persistent access for seven months and staged nearly 11,000 individuals' data for exfiltration. ACRO notified over 84,000 people. Insufficient logging meant ACRO could not confirm whether data was actually exfiltrated.

CISA Orders Patch for CVE-2026-68820 Exploited by Lazarus Group

CISA added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog and gave federal agencies until August 25, 2026, to patch. The Windows Winsock vulnerability (CVSS 7.0) enables privilege escalation from a low-privileged foothold to full system control. Check Point attributed the exploitation to North Korea's Lazarus Group as part of Operation Dream Job, where hackers impersonated Lockheed Martin and Enveil recruiters on LinkedIn, sending malicious PDFs that deploy backdoors. Targets spanned defense sectors in France, Germany, Brazil, and India.

Litigation Updates

$17.5M 700Credit Data Breach Class Action Settlement Now Open

A $17.5 million class action settlement is available for individuals whose information was compromised in the 2025 700Credit data breach. 700Credit provides credit and compliance solutions to auto dealerships. Claims are now open.

Ninth Circuit Rules Section 230 Is a Defense, Not Immunity

The Ninth Circuit held that Section 230 does not provide immunity from lawsuit but instead functions as a defense against liability. The practical consequence: platforms like Meta and TikTok can no longer seek early dismissal of content-related claims through interlocutory appeals. They must instead litigate through the full process before raising Section 230. The ruling overrides prior Ninth Circuit precedent, including Judge Kozinski's characterization in the Roommates case that immunity was essential to prevent "death by ten thousand duck-bites." This fundamentally increases litigation costs for any company hosting user-generated content.

Victra Data Breach Spawns Two Class Action Lawsuits

Two class action lawsuits were filed against Victra, one of the largest Verizon authorized retailers, alleging the company failed to protect sensitive personal information of customers and employees, resulting in a data breach.

Apple Sued Over Hide My Email Privacy Claims

A class action alleges Apple misrepresented the privacy capabilities of its Hide My Email feature, claiming it does not function as advertised.

Regulatory Guidance

Microsoft August Patch Tuesday: 419 Vulnerabilities, Three Zero-Days

Microsoft released fixes for 419 security vulnerabilities, including 62 critical and 357 important-rated issues. Three are zero-days; one (CVE-2026-68820) is confirmed exploited in the wild by Lazarus Group. A second publicly known flaw, CVE-2026-62832, matches a proof-of-concept published by researcher Nightmare Eclipse. Microsoft has shifted from itemized CVE listings to summary tables by product family, making third-party triage more complex. AI-assisted vulnerability discovery continues to drive record patch volumes: 137 in May, 206 in June, 622 in July, and now 419 in August.

DOJ Bulk Data Security Program: Closing the Aggregate Data Gap

Lawfare published analysis arguing that the DOJ's Data Security Program should develop a regulatory framework to address bulk data sales that expose military and government personnel. The article highlights that privacy law, built around individual consent and choice, cannot address the national security risk of adversaries purchasing population-scale datasets of service members' records on the open market. Cross-referenced records can reveal unit structures, supply chains, and command relationships.

Privacy Developments

FBI Warns of Social Engineering Attacks Targeting Explicit Content

The FBI issued an alert that hackers are using social engineering and credential stuffing to breach social media accounts of adults and children, stealing explicit content for sale on criminal marketplaces. Tactics include password spraying from data leak sites, impersonating platform representatives to obtain reset codes, and cloned login pages. Stolen content is used for sextortion, harassment, and stalking. The DOJ has already charged several individuals in related campaigns, including a 27-year-old who compromised 600 Snapchat accounts and a former University of Michigan coach who accessed medical records of 150,000 student athletes.

Legal Ethics and AI: Compliance and Confidentiality Gaps Persist

Analysis from UC Law San Francisco's Lexlab program identifies two fundamental barriers to AI compliance in legal practice: unreliable outputs (beyond hallucinated citations, extending to judgment that AI cannot replace) and data protection failures (AI tools consuming, storing, and reusing confidential client data). Lawyers remain fully accountable under professional conduct rules regardless of AI tool use, and current AI tools cannot be presumed compliant with duties of competence, confidentiality, and candor.

Policy Changes

Supreme Court Mail-In Voting Executive Order Challenge Fully Briefed

The Trump administration urged the Supreme Court to act quickly on its July 27 application to block a federal judge's order prohibiting implementation of Executive Order "Ensuring Citizenship Verification and Integrity in Federal Elections" in 23 states and D.C. for the November 2026 midterms. Section 3 of the order requires states to provide voter lists to USPS and prohibits USPS from mailing ballots to voters not on its "enrolled" lists. U.S. District Judge Indira Talwani (D. Mass.) blocked implementation through November 3, 2026. The First Circuit denied the government's stay request. The matter is now fully briefed and a ruling could come at any time.

FCC Staffing: New Republican Commissioner Appointed, Democratic Seats Remain Vacant

FCC Chairman Brendan Carr appointed his former legal aide to fill the third Republican commissioner seat, establishing a full 3-0 Republican majority. No moves have been made to reappoint Democratic Commissioner Anna Gomez or fill the second vacant Democratic seat.

Compliance Takeaways