LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
patch

Wiretapping change sparks big privacy fight in the Golden State

California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers"…

ZeroDay News ·

Source: CyberScoop

California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers" and "trap-and-trace" technologies.

Originally enacted in 1967, CIPA mandated court orders for wiretapping, eavesdropping, and recording of telephone calls. Over time, courts expanded its scope to include internet communications like email and website activity. In 2015, a provision was added allowing residents to sue companies for up to $5,000 per violation, plus triple damages, for unauthorized use of internet-tracking technologies such as pen registers.

Governor Newsom and the bill's sponsors contend that this provision has led to thousands of lawsuits and demand letters against businesses for using common internet-tracking tools, including browser cookies, analytics software, and pixels, which they argue serve legitimate business purposes. Newsom stated in his signing statement that the measure addresses the "vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses that unwittingly install software on their websites." He praised the authors' efforts to protect small businesses from "overzealous lawsuits based on a statute written without today's complex technology landscape in mind."

Pen registers and trap-and-trace devices are typically used by law enforcement agencies like the FBI and DEA, as well as national security organizations, with a court order to log metadata such as dialed phone numbers, IP addresses, and timestamps, without accessing the content of communications. Privacy attorneys at Kelley Drye noted that the 2015 addition of the pen register and trap-and-trace statute was intended to codify how law enforcement could obtain court orders for phone metadata without violating CIPA.

Estimates of lawsuits filed under the provision vary, with the Alliance for Legal Fairness, a lobbying firm supporting the legislative update, tracking approximately 600 lawsuits in 2025, a number they claim has since surged to over 4,000. Privacy attorneys Shruti Bhutani Arora and Christine Mastromonaco of Pillsbury reported that plaintiffs have sent tens of thousands of demand letters threatening class-action suits under CIPA's pen-register and trap-and-trace provisions. A report from the California Assembly Committee on Privacy and Consumer Protection characterized the pen register provision as a "poster child for abusive lawsuits," noting that businesses often settle quickly due to the potential for staggering liability.

The new law was widely supported by business groups, including the Chamber of Commerce, and hundreds of other California organizations. However, it faced strong opposition from privacy advocates, labor unions, and civil rights groups. Major California labor unions, the American Civil Liberties Union, the Consumer Federation of California, the Privacy Rights Clearinghouse, and the Electronic Privacy Information Center were among those who opposed the measure. The Electronic Frontier Foundation (EFF) actively fought the bill, with its director of state affairs, Hayley Tsukayama, stating that the bill should not have been signed and that the organization unsuccessfully lobbied Newsom for a veto.

Privacy groups argue that the exemption will make it easier for companies to track, collect, and sell consumer data to third parties, including data brokers, while simultaneously making it more difficult for individuals to pursue legal action. Tsukayama emphasized that CIPA was originally intended to protect personal privacy against surveillance of private communications, and this reform "harms privacy by making it impossible for ordinary people to sue companies engaged in unlawful metadata surveillance." She also expressed concern about federal and law enforcement agencies seeking data from businesses or data brokers to target individuals based on their beliefs or health decisions.

Early versions of SB 690 sought to exempt other privacy provisions from private lawsuits, but later iterations narrowed the exemption to specifically address pen registers and trap-and-trace devices. California has some of the nation's strictest data broker laws, requiring brokers to register with the government and offer consumers universal opt-out options for data collection, and established the California Privacy Protection Agency in 2018 to enforce digital privacy laws.

patchcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

ClickFix Attack Hides VBScript Payload in Browser Cache

A new "ClickFix" social engineering campaign has been identified that leverages browser caches to conceal malicious VBScript payloads. The technique, detailed by Microsoft Threat Intelligence on October 3, involves compromised websites pre-fetching a script disguised as an image into a visitor's browser cache. This allows the payload to be present on the victim's device before they are tricked…

zero-day

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

Security researchers collectively uncovered 32 zero-day vulnerabilities on the first day of the Pwn2Own Ireland 2026 competition, earning a total of $388,500. The event, organized by the Zero Day Initiative (ZDI), aims to identify critical flaws in various products before malicious actors can exploit them.

phishing

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Cybersecurity researchers have uncovered a human-operated phishing platform designed to impersonate advertising portals for popular artificial intelligence (AI) chatbots. The platform specifically targets users by mimicking ad products for services such as Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. Its primary objective is to capture user credentials and…

security

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Recent reports indicate the discovery of Linux backdoors actively targeting telecommunications and network appliances within South Korea and Taiwan. These sophisticated backdoors are designed to evade detection by masquerading their malicious traffic as legitimate email services and by impersonating benign system processes. This tactic allows the malware to blend into normal network activity…

vulnerability

Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps

Google has reportedly developed an artificial intelligence agent, named PageBreak, which has identified approximately 500 flaws within Google's own web applications. This development highlights an emerging trend in the cybersecurity industry: the application of AI and deterministic validation methods to automate the discovery of vulnerabilities, assess their exploitability, and provide a…

ai

Former NSA chief Nakasone says agency overhaul is ‘probably needed’

Former National Security Agency Director Paul Nakasone stated that a reported comprehensive reorganization of the agency is likely necessary to address rapidly evolving cyber threats and the competitive landscape in artificial intelligence (AI). Nakasone, who led the NSA and U.S. Cyber Command from 2018 to 2024, made these remarks on Tuesday at VulnCheck's ThreatCon1 conference.