On My Radar 🎯
Two Bills, One Goal: Court-Ordered Website Blocking In The US
There are two bills in Congress that do similar things:
- The first, the American Copyright Protection Act (ACPA) starts as a copyright issue. A copyright owner asks a court to label a foreign website a "piracy site." The court can then order internet service providers, DNS providers, and yes, VPNs, to block Americans from reaching it.
- The second, the DEFEND IP Act, came shortly after and has sponsors from both parties in the House and Senate. It's a little bit better because it exempts VPN providers and encrypted-only DNS, but regular DNS is still blockable.
The problem with both bills is the precedent set by forcing private companies to block traffic, it's a slippery slope. And who decides what counts as "piracy"? For context, the second bill with momentum is backed by the film and music industry—historically the good guys! 🫥 The EFF shared some nice case studies of this not working out:
- Italy's Piracy Shield blocked 510 harmless sites, including a telehealth platform.
- Spain blocked more than 550,000 domains during soccer broadcasts, including sites belonging to Greenpeace and Harvard.
What you can do: Support the EFF! They oppose both bills and will keep covering them. And it goes without saying: Tell your representative to oppose H.R. 10364 (ACPA) and H.R. 10575 (DEFEND IP).
Bits & Bytes 🤖
~ Story 1: First the FBI, then the Pentagon
ShinyHunters claimed they hacked the FBI, and the bureau has since declared a cybersecurity incident. They stole names, Social Security numbers, home addresses, and assignments for almost all FBI agents, plus records on the FBI's own hacking team! Days later, Pentagon personnel records for over 3 million people were stolen in a very similar breach, though no one has claimed that yet.
My take: The FBI and the Pentagon are two places that get casually hacked in movies but rarely in real life. If there's a lesson here, it's that nobody's safe!
~ Story 2: Chat Control 2.0 Temporarily Fought Off
Patrick Breyer reported that the "dirty deal" to legalize mass scanning of private messages failed, thanks to pressure from civil society and a firm stance from the European Parliament. Technical negotiations continue, with a final push for a political deal in November. The Council still wants to keep Chat Control 1.0, voluntary mass scanning, as a loophole.
My take: Just as Breyer has said: this is a defense, not a final victory! In general, I think everyone reading this should find a healthy, sustainable way to follow news. Something that allows you to stay engaged for years to come, which typically means something that's the right balance of 'active'! Whether that's following Patrick directly over RSS or a podcast/newsletter like this one, or yes—short form content...gasp...I just want you all to find the medium that keeps you active in these fights.
~ Story 3: Meta's Muse Knows Everyone You Know
Mark Zuckerberg says Meta's new AI agent, Muse, was built from the ground up for privacy and security. 🥴 Within weeks, researcher Patrick Wardle found a zero-day that let any app hijack the agent's login token. It traced back to design choices like doing dictation in the cloud instead of on the device. Meta patched it within 12 hours. Now Wired reports that Muse builds detailed profiles of your friends and family.
My take: What an AI tool does reflects the culture of the company running it, and Meta has one of the worst track records out there. If you want to experiment with AI agents, you should be proceeding extremely carefully. Use something open source (Hermes is a common one), run it in a container or VM, and only give it access to what it absolutely needs. Even with these precautions I'd consider this risky—but certainly safer than anything out of Meta.
This Week on Techlore 📺
Go Incognito v2 is HERE! The course, completely rebuilt for 2026: 66 lessons, real demos, and new lessons on AI threats, data brokers, passkeys and more. Section 1 opens Monday, and I'm running a 25% pre-launch discount + an exclusive pre-launch badge, so make sure to hop on that to join the internet's most comprehensive privacy course! The free version starts rolling out shortly after.

And last thing: I think this was one of the most beloved interviews of the year. The comments (and Signal messages!) sent overwhelming praise to Quad9, who is dealing with some similar blocking I shared earlier. This is a must-listen Techlore Talks, check it out here:

Action Item ✅
A few things this week:
- It didn't make the newsletter, but if you're on iOS, either update to 26.7.1 or 27.0.1 for important security fixes.
- Audit your news consumption, and make sure you have a healthy balance between 'time off' and 'time on'—it's going to be important these next few months!
- Consider Go Incognito for yourself or friends/family to go on the learning journey, it's designed for anyone & everyone.
Until next week 🫡
This Week's Sources
Highlight: Congress Comes For VPNs
- https://www.eff.org/deeplinks/2026/10/congress-has-another-site-blocking-bill-and-one-targets-vpns
- https://www.eff.org/deeplinks/2026/10/site-blocking-will-not-defend-ip-no-matter-bills-name
- https://www.eff.org/deeplinks/2026/10/court-agrees-eff-utahs-vpn-law-demands-technical-impossibility
- https://windscribe.com/blog/we-signed-a-letter-against-c22/
Story 1: Hackers Hit The FBI Then The Pentagon
- https://techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/
- https://techcrunch.com/2026/09/28/fbi-reportedly-declares-cyber-security-incident-after-hackers-steal-agents-personal-data/
- https://www.bleepingcomputer.com/news/security/hackers-breach-pentagon-human-resources-management-system-steal-data-of-nearly-3-million-people/
Story 2: Chat Control 2.0 No Deal (For Now)
Story 3: Meta's Muse Knows Everyone You Know
- https://www.wired.com/story/muse-creates-detailed-profiles-of-all-your-friends-and-family/
- https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/
The Defense Bulletin
Data Breaches
- https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/
- https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/
- https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/
- https://yro.slashdot.org/story/26/09/17/0517235/hackers-stole-flocks-camera-software-revealing-how-the-company-tracks-cars-and-people
- https://nos.nl/artikel/2632473-hackers-persen-klanten-boodschappendienst-flink-af-betalen-of-data-gepubliceerd
Threats
- https://techcrunch.com/2026/09/29/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix/
- https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/
- https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/
- https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/
- https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/
- https://techcrunch.com/2026/10/02/apple-says-its-tightening-macos-full-disk-access-controls-due-to-new-risks-from-ai-agents/
- https://macsouverain.com/en/macos-27-application-support-protection/
- https://tech.slashdot.org/story/26/09/30/1841213/reddit-is-killing-rss-feeds-ending-public-api-access
FOSS+ Updates
- https://support.signal.org/hc/en-us/articles/11197884108826-Phone-Numberless-Registration-for-Android
- https://signal.org/blog/backup-improvements
- https://arstechnica.com/gadgets/2026/09/f-droid-gets-its-biggest-update-in-a-decade-with-new-ui-and-smoother-app-installs/
- https://alternativeto.net/news/2026/9/keepassxc-2-8-0-beta-adds-sync-wayland-auto-type-and-arm64/
- https://alternativeto.net/news/2026/9/obscura-finally-brings-vpn-service-to-linux-users-and-shifts-to-open-source-gplv3-license/
- https://blog.mozilla.org/en/firefox/new-firefox-design-is-here/
- https://tails.net/news/version_7.14/
- https://alternativeto.net/news/2026/9/postmarketos-rebrands-as-nura-in-move-to-broaden-appeal-beyond-tech-community-keeps-logo/
- https://alternativeto.net/news/2026/9/-e-os-unveils-version-4-3-built-on-lineageos-23-with-enhanced-backup-and-restore-features/
- https://adguard.com/en/blog/adguard-home-beta-version-1-0.html
- https://tuta.com/blog/tuta-app-on-nextcloud
- https://nextcloud.com/blog/nextcloud-academy-free-online-courses-for-contributors/
- https://www.waterfox.com/releases/6.7.5/
- https://linux.slashdot.org/story/26/09/24/0155213/qualcomm-announces-snapdragon-x2-series-processors-will-support-linux
- https://linux.slashdot.org/story/26/09/29/1858218/microsoft-makes-linux-containers-native-on-windows-11
Surveillance Report: what matters in privacy, security, and digital rights. Weekly, free.

