LIVE · cybersecurity feed
Live wire
Critical Elementor Pro bug exposes WordPress sites to RCE attacksThe push to designate AI as the next critical infrastructure sectorCritical Zimbra RCE flaw now actively exploited in attacksExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerCVE-2026-19478 · Critical GitLab Flaw Exploited Shortly After DisclosureCVE-2026-32475 · Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructure
security

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears

The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.

zeroday.news ·

A bill aimed at combating organized retail theft has passed the House of Representatives with significant bipartisan support, but it faces opposition from civil liberties groups who warn it could lead to an expansive and dangerous surveillance network centered within Immigration and Customs Enforcement (ICE). The Combating Organized Retail Crime Act (CORCA) passed the House in June by a vote of 348-60, and its supporters are now pushing for its inclusion in the annual defense policy bill, a piece of legislation considered essential for passage.

At its core, CORCA proposes the establishment of an Organized Retail and Supply Chain Crime Coordination Center within ICE’s Homeland Security Investigations (HSI) division. The bill also seeks to create new criminal penalties for money laundering proceeds from the sale of stolen goods and sets a $5,000 threshold for the combined value of stolen property over a year for charging purposes.

Opponents of the bill argue that its broad and vague language, particularly regarding definitions of "organized retail crime" and "retailers," could enable extensive data sharing between government entities and retailers. They express concern that the bill would grant the Department of Homeland Security (DHS) access to retail surveillance data, including information from security cameras in public spaces like malls and train stations, as well as automated license plate readers. Critics contend that this framework would allow the government to obtain such data freely, bypassing existing practices where agencies might purchase data from brokers.

Civil liberties and civil rights organizations, including the American Civil Liberties Union (ACLU) and the NAACP Legal Defense and Education Fund, are actively working to defeat CORCA. A primary concern for these groups is the proposed fusion center within ICE, an agency that has been scrutinized for its data collection practices, including cell phone location and health information. They argue that adding retail data to this existing pool would exacerbate concerns about ICE's ability to track individuals and their associates, particularly given allegations of racial profiling.

Supporters of CORCA, however, maintain that the bill is narrowly focused on organized retail crime leaders and poses no risk to ordinary citizens. They emphasize that organized retail crime has evolved into a multi-jurisdictional threat with significant economic and national security implications. They also clarify that the bill does not grant DHS new enforcement authorities, but rather leverages HSI's existing role in addressing transnational and organized criminal activity.

The American Trucking Associations supports the bill, with its legislative director dismissing surveillance concerns as unfounded. They argue that the bill primarily creates a central repository within HSI for industry to report high-level crimes committed by large organized theft groups, rather than expanding government surveillance powers.

Retail industry representatives also highlight the distinction between ICE's HSI, which focuses on criminal investigations including cybercrime, and its Enforcement and Removal Operations division, which handles immigration enforcement. They point to a substantial increase in cyber-enabled retail crime, such as gift card fraud, e-commerce fraud stemming from phishing or account takeovers, and cargo theft facilitated by false personas. They argue that CORCA could provide a crucial tool to address the convergence of cyber and physical theft methods.

Both proponents and opponents of the bill remain optimistic about their respective efforts. While some lawmakers who initially sponsored the legislation ultimately voted against it, suggesting a growing understanding of its potential implications, supporters point to the wide House vote and bipartisan backing from key committee leaders as evidence of strong momentum. Opponents, however, emphasize the need to further educate legislators about the extensive power that could be granted to ICE and the potential for a lack of accountability within DHS.

ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks

A nation-state threat actor is picking on immature organizations run by the Taliban, but failing against more prepared government agencies in India.

CVE-2026-73570

Hackers Target Zimbra Servers in Active Exploitation Campaign

Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska. The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek.

vulnerabilitycritical

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]

security

Surveillance – Everything You Wanted to Know, But Were Afraid to Ask

We all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it. The post Surveillance – Everything You Wanted to Know, But Were Afraid to Ask appeared first on SecurityWeek.

vulnerability

JFrog Artifactory Flaws Enable Software Supply Chain Attacks

Two Artifactory flaws allowed attackers to poison package metadata across software repositories

nation-statecritical

The push to designate AI as the next critical infrastructure sector

The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security. The post The push to designate AI as the next critical infrastructure sector appeared first on CyberScoop.