This week's highlight story is a big one...six lawmakers are pressing intelligence officials to answer whether Americans using commercial VPNs could be stripped of their constitutional protections and treated as foreign targets under Section 702 of FISA. The irony here is these same organizations have all recommended that consumers use VPNs for privacy, which may inadvertently hand the NSA legal cover to surveil your traffic as if you're a foreign national. I don't think this is any reason to ditch your VPN, but it does expose the deeper flaw in how governments are approaching digital rights. I think the real fix isn't carving out exceptions for Americans; it's recognizing that mass surveillance is wrong, regardless of whose citizens it targets.
Beyond the VPN story, this was an enormous week. North Korea pulled off a weeks-long, methodically planned supply chain hijack of the widely-used Axios JavaScript library. And right as Google is pushing to lock down Android sideloading under the banner of Play Store safety, we got the story of NoVoice—Android malware distributed through 50+ Play Store apps with 2.3 million downloads, capable of surviving a factory reset. I also covered Apple's expanding device-level age verification, the EU Parliament's big vote to kill Chat Control (and Patrick Brayer's compelling five-point action plan for real child protection), and a packed Defense Bulletin with updates from VeraCrypt, Meta's child exploitation loss in court, Apple Maps ads, and more.
Episode Timestamps
00:00 WELCOME TO SURVEILLANCE REPORT
01:18 HIGHLIGHT STORY: NSA VPN SPYING
08:24 NORTH KOREA HACKS OPEN SOURCE SOFTWARE
10:30 GOOGLE HOSTING MALWARE ON PLAY STORE
15:00 AGE VERIFICATION ADVANCES EVERYWHERE
26:12 END OF CHAT CONTROL & WHAT'S NEXT!
31:00 DEFENSE BULLETIN
Episode Sources
Highlight: VPN Use May Subject You to NSA Spying
- https://www.wired.com/story/using-a-vpn-may-subject-you-to-nsa-spying/
- https://techlore.tech/vpns-nsa-spying-and-the-surveillance-double-standard-nobody-wants-to-address/
Story 1: North Korea's Weeks-Long Open Source Hijack
Story 2: Android Malware Infected 23 Million Devices via Google Play
Story 3: Apple Expands Device-Level Age Verification
- https://gizmodo.com/apple-requires-device-level-age-verification-in-the-uk-now-could-the-us-be-next-2000738481
- https://apple.slashdot.org/story/26/04/05/0120236/apple-brings-device-level-age-verification-to-two-more-countries
- https://www.wired.com/story/your-vape-wants-to-know-how-old-you-are/
- https://itsfoss.com/news/systemd-age-verification/
- https://gizmodo.com/group-pushing-age-verification-requirements-for-ai-turns-out-to-be-sneakily-backed-by-openai-2000741069
- https://futurism.com/artificial-intelligence/openai-nonprofit-child-safety
- https://adguard-vpn.com/en/blog/yoti-age-verification-gdpr-violation.html
- https://www.reuters.com/business/media-telecom/greece-ban-social-media-under-15s-2027-pm-says-2026-04-08/
- https://www.bbc.com/news/articles/cwyv70de9exo
- https://adguard-vpn.com/en/blog/age-verification-privacy-experts-open-letter.html
Story 4: EU Parliament Kills Chat Control
- https://www.patrick-breyer.de/en/end-of-chat-control-eu-parliament-stops-mass-surveillance-in-voting-thriller-paving-the-way-for-genuine-child-protection/
- https://www.patrick-breyer.de/en/the-end-of-chat-control-is-an-opportunity-5-point-action-plan-for-genuine-child-protection/
The Defense Bulletin
- https://techcrunch.com/2026/04/08/veracrypt-encryption-software-windows-microsoft-lock-boot-issues/
- https://www.wired.com/story/apple-will-push-out-rare-backported-patches-to-protect-ios-18-users-from-darksword-hacking-tool/
- https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-flaw-in-ninja-forms-wordpress-plugin/
- https://www.bleepingcomputer.com/news/security/linkedin-secretely-scans-for-6-000-plus-chrome-extensions-collects-data/
- https://www.bleepingcomputer.com/news/security/new-infinity-stealer-malware-grabs-macos-data-via-clickfix-lures/
- https://www.bleepingcomputer.com/news/security/backdoored-telnyx-pypi-package-pushes-malware-hidden-in-wav-audio/
- https://www.bleepingcomputer.com/news/security/claude-code-leak-used-to-push-infostealer-malware-on-github/
- https://www.404media.co/a-top-google-search-result-for-claude-plugins-was-planted-by-hackers/
- https://techcrunch.com/2026/04/01/whatsapp-notifies-hundreds-of-users-who-installed-a-fake-app-that-was-actually-government-spyware/
- https://www.404media.co/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless/
- https://arstechnica.com/tech-policy/2026/04/perplexitys-incognito-mode-is-a-sham-lawsuit-says/
- https://www.bleepingcomputer.com/news/security/adversaries-exploit-vacant-homes-to-intercept-mail-in-hybrid-cybercrime/
- https://alternativeto.net/news/2026/4/samsung-is-officially-discontinuing-its-native-messages-app-in-favor-of-google-messages/
- https://arstechnica.com/gadgets/2026/03/apple-confirms-that-its-maps-app-will-begin-showing-ads-to-users-this-summer/
- https://meta.slashdot.org/story/26/03/25/172211/meta-loses-trial-after-arguing-child-exploitation-was-inevitable
- https://meta.slashdot.org/story/26/03/25/1745232/meta-and-youtube-found-negligent-in-landmark-social-media-addiction-case
- https://www.bleepingcomputer.com/news/security/european-commission-confirms-data-breach-after-europaeu-hack/
- https://www.bleepingcomputer.com/news/security/dutch-police-discloses-security-breach-after-phishing-attack/
- https://www.bleepingcomputer.com/news/security/dutch-finance-ministry-takes-treasury-banking-portal-offline-after-breach/
- https://www.bleepingcomputer.com/news/security/dutch-ministry-of-finance-discloses-breach-affecting-employees/
- https://techcrunch.com/2026/04/02/telehealth-giant-hims-hers-says-its-customer-support-system-was-hacked/
- https://techcrunch.com/2026/04/01/hasbro-hacked-may-take-several-weeks-to-recover/
- https://techcrunch.com/2026/03/24/crunchyroll-confirms-data-breach-after-hacker-claims-unauthorized-access/
- https://www.bleepingcomputer.com/news/security/mazda-discloses-security-breach-exposing-employee-and-partner-data/
- https://arstechnica.com/security/2026/03/after-hack-some-ignition-interlock-users-couldnt-start-their-own-cars/
- https://www.bleepingcomputer.com/news/security/infinite-campus-warns-of-breach-after-shinyhunters-claims-data-theft/
- https://proton.me/business/blog/introducing-proton-meet
- https://proton.me/blog/meet-security-model
- https://proton.me/business/blog/proton-workspace
- https://blog.mozilla.org/en/firefox/built-in-vpn/
- https://blog.mozilla.org/en/firefox/split-view/
- https://blog.mozilla.org/en/firefox/tab-notes/
- https://blog.torproject.org/new-release-tor-browser-1508/
- https://tails.net/news/version_7.6/
- https://blog.torproject.org/new-release-tails-7_6_1/
- https://www.mullvad.net/en/blog/2026/3/26/mullvad-browser-alpha-moves-to-firefox-rapid-release-and-adds-linux-arm-support/
- https://alternativeto.net/news/2026/3/matrix-1-18-adds-policy-servers-invite-blocking-and-safety-api-updates/
- https://ente.com/blog/rust-crypto-audit/
- https://blog.crypt.ee/end-to-end-encrypted-photo-sharing/
- https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware/
- https://alternativeto.net/news/2026/4/dns-resolver-quad9-enables-dns-over-http-3-and-quic-globally-expanding-encrypted-options/
- https://linux.slashdot.org/story/26/04/02/0350211/steam-on-linux-use-skyrocketed-above-5-in-march
- https://itsfoss.com/news/gnome-drops-google-drive-support/
- https://itsfoss.com/news/onlyoffice-forked/
- https://alternativeto.net/news/2026/3/kali-linux-2026-1-launches-with-linux-6-18-theme-update-backtrack-mode-and-8-new-tools/
- https://itsfoss.com/news/kde-plasma-oxygen-air-comeback/
- https://itsfoss.com/news/pinetime-pro-early-look/
- https://www.waterfox.com/blog/15-years-of-forking/
- https://defcon.social/@llas/116334969059308748
- https://itsfoss.com/news/wayland-session-management/
Digital Rights Digest—threats to your freedom and how to fight back. A five-minute weekly read, 100% free.