Illinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative oversight.

Prosecutors in at least 17 Illinois counties have been found to have shared sensitive personal data of criminal defendants with federal immigration agents without obtaining criminal warrants, public disclosure, or legislative oversight. This collaboration, which occurred during the first 15 months of President Donald Trump's second term, involved state's attorneys' offices acting as informants for US Immigration and Customs Enforcement (ICE) and Homeland Security Investigations (HSI).
The practice was uncovered through an investigation that reviewed over 5,000 pages of internal emails and case files obtained via Freedom of Information Act (FOIA) requests from all 102 Illinois state's attorney's offices. These documents revealed that prosecutors shared details such as defendants' dates of birth, home addresses, upcoming court dates, and even police reports and photographs. In some instances, prosecutors proactively offered information, while in others, they responded to direct inquiries from federal agents.
One documented case involved Rolando Perez Samayoa, who was arrested for a DUI in Marion County in October 2024. In January 2025, Assistant State’s Attorney John Christeson emailed HSI agent Sergio Fulgencio, providing Samayoa's date of birth, address in Centralia, Illinois, and an upcoming court date. Fulgencio subsequently requested and received Samayoa's police report and related tickets. Three weeks later, federal agents apprehended Samayoa outside his home, also taking his 17-year-old son.
The collaboration raises questions about the effectiveness of Illinois' 2017 TRUST Act, a "sanctuary" law intended to prevent local law enforcement from assisting federal deportation efforts. While the act bars police and other agencies from aiding federal agents without a federal criminal warrant, it does not explicitly define whether prosecutors and their staff are subject to the same restrictions.
The investigation found that the sharing of information often occurred without the knowledge of defendants or their attorneys. The consequences of this collaboration were significant, with individuals flagged to ICE being detained and deported, leading to family separations.
In another instance, just 20 minutes after flagging Samayoa, Christeson contacted Fulgencio again about another individual with a local warrant. Fulgencio confirmed that agents were already tracking this person on a civil removal order. Christeson indicated that the county warrant would not take priority over removal, and within 34 minutes, Fulgencio reported that the individual was in ICE custody awaiting removal.
The records indicate that DuPage County, where one in five residents are foreign-born, had the most frequent contact with federal immigration agents among Illinois prosecutor's offices. Staff there both responded to ICE requests and proactively offered cases for federal agents to pursue. For example, in April 2025, a Customs and Border Protection officer at O'Hare International Airport requested records related to a voter fraud investigation from an assistant prosecutor, using an administrative subpoena rather than a judge-issued warrant.
Legal experts suggest that local officials might be tempted to use deportation as an easier path than criminal prosecution to "clear their docket," potentially undermining defendants' rights in criminal proceedings. Unlike criminal cases, which require proof beyond a reasonable doubt and appointed attorneys for indigent defendants, immigration removal proceedings are civil, have a lower legal standard of "clear and convincing evidence," and do not guarantee the right to an appointed lawyer. Once a defendant is turned over to ICE, the protections afforded by the criminal justice system are often lost.
While some prosecutor's offices in Illinois had limited contact with ICE, others, despite facing similar federal pressure, reported no contact or actively avoided collaboration. This suggests that each instance of collaboration was a deliberate choice. The Department of Homeland Security has not commented on its agents' work with local officials in Illinois. Advocacy groups, who championed the TRUST Act, contend that the revealed collaborations demonstrate a breach of trust between immigrant communities and the criminal justice system.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed