
This week's Surveillance Report covers the most severe Linux threat in years sending researchers and admins scrambling, Apple patching the bug police were using to extract deleted Signal messages from iPhones, Utah's new law regulating VPNs taking effect, and Microsoft Edge inexplicably storing your passwords in plaintext memory.
Episode Sources
Highlight: Most Severe Linux Threat in Years Has Researchers Scrambling
- https://arstechnica.com/security/2026/04/as-the-most-severe-linux-threat-in-years-surfaces-the-world-scrambles/
- https://arstechnica.com/security/2026/04/open-source-package-with-1-million-monthly-downloads-stole-user-credentials/
Story 1: Apple Quietly Fixes the Bug Police Used to Extract Deleted Signal Messages
- https://techcrunch.com/2026/04/22/apple-fixes-bug-that-cops-used-to-extract-deleted-chat-messages-from-iphones/
- https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/
- https://www.eff.org/deeplinks/2026/04/how-push-notifications-can-betray-your-privacy-and-what-do-about-it
Story 2: Utah's New Law Regulating VPNs Takes Effect
- https://www.kuer.org/politics-government/2026-05-07/utahs-online-porn-age-verification-law-now-includes-vpns-critics-say-it-wont-work
- https://le.utah.gov/~2026/bills/static/SB0073.html
- https://www.eff.org/deeplinks/2026/04/utahs-new-law-regulating-vpns-goes-effect-next-week
Story 3: Microsoft Edge Caught Storing Your Passwords in Plaintext RAM — For Apparently No Reason
The Defense Bulletin
Threats, Exploits & Supply Chain
- https://techcrunch.com/2026/04/30/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites/
- https://alternativeto.net/news/2026/4/bitwarden-cli-was-compromised-as-part-of-an-ongoing-checkmarx-related-supply-chain-attack/
- https://techcrunch.com/2026/04/14/someone-planted-backdoors-in-dozens-of-wordpress-plugins-used-in-thousands-of-websites/
Breaches
- https://techcrunch.com/2026/04/22/france-confirms-data-breach-at-government-agency-that-manages-citizens-ids/
- https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/
- https://www.bleepingcomputer.com/news/security/video-service-vimeo-confirms-anodot-breach-exposed-user-data/
Updates & Good News
- https://proton.me/blog/introducing-post-quantum-encryption
- https://blog.torproject.org/new-release-tails-7_7/
- https://www.mullvad.net/en/blog/2026/4/21/force-all-app-traffic-into-the-tunnel/
- https://brave.com/privacy-updates/37-shred-button-android/
- https://www.denver7.com/life/money/maryland-becomes-first-state-to-pass-bill-banning-surveillance-pricing
Digital Rights Digest—threats to your freedom and how to fight back. A five-minute weekly read, 100% free.