The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.

A bill aimed at combating organized retail theft has passed the House of Representatives with significant bipartisan support, but it faces opposition from civil liberties groups who warn it could lead to an expansive and dangerous surveillance network centered within Immigration and Customs Enforcement (ICE). The Combating Organized Retail Crime Act (CORCA) passed the House in June by a vote of 348-60, and its supporters are now pushing for its inclusion in the annual defense policy bill, a piece of legislation considered essential for passage.
At its core, CORCA proposes the establishment of an Organized Retail and Supply Chain Crime Coordination Center within ICE’s Homeland Security Investigations (HSI) division. The bill also seeks to create new criminal penalties for money laundering proceeds from the sale of stolen goods and sets a $5,000 threshold for the combined value of stolen property over a year for charging purposes.
Opponents of the bill argue that its broad and vague language, particularly regarding definitions of "organized retail crime" and "retailers," could enable extensive data sharing between government entities and retailers. They express concern that the bill would grant the Department of Homeland Security (DHS) access to retail surveillance data, including information from security cameras in public spaces like malls and train stations, as well as automated license plate readers. Critics contend that this framework would allow the government to obtain such data freely, bypassing existing practices where agencies might purchase data from brokers.
Civil liberties and civil rights organizations, including the American Civil Liberties Union (ACLU) and the NAACP Legal Defense and Education Fund, are actively working to defeat CORCA. A primary concern for these groups is the proposed fusion center within ICE, an agency that has been scrutinized for its data collection practices, including cell phone location and health information. They argue that adding retail data to this existing pool would exacerbate concerns about ICE's ability to track individuals and their associates, particularly given allegations of racial profiling.
Supporters of CORCA, however, maintain that the bill is narrowly focused on organized retail crime leaders and poses no risk to ordinary citizens. They emphasize that organized retail crime has evolved into a multi-jurisdictional threat with significant economic and national security implications. They also clarify that the bill does not grant DHS new enforcement authorities, but rather leverages HSI's existing role in addressing transnational and organized criminal activity.
The American Trucking Associations supports the bill, with its legislative director dismissing surveillance concerns as unfounded. They argue that the bill primarily creates a central repository within HSI for industry to report high-level crimes committed by large organized theft groups, rather than expanding government surveillance powers.
Retail industry representatives also highlight the distinction between ICE's HSI, which focuses on criminal investigations including cybercrime, and its Enforcement and Removal Operations division, which handles immigration enforcement. They point to a substantial increase in cyber-enabled retail crime, such as gift card fraud, e-commerce fraud stemming from phishing or account takeovers, and cargo theft facilitated by false personas. They argue that CORCA could provide a crucial tool to address the convergence of cyber and physical theft methods.
Both proponents and opponents of the bill remain optimistic about their respective efforts. While some lawmakers who initially sponsored the legislation ultimately voted against it, suggesting a growing understanding of its potential implications, supporters point to the wide House vote and bipartisan backing from key committee leaders as evidence of strong momentum. Opponents, however, emphasize the need to further educate legislators about the extensive power that could be granted to ICE and the potential for a lack of accountability within DHS.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed