> ## Content Index
> Fetch the complete content index at: https://techlore.tech/llms.txt
> Use this file to discover other available public pages before exploring further.

# VPNs Could Expose You to NSA Spying, North Korea's Open-Source Hijack, Android Malware Hits 2.3 Million Devices via Google Play, and the EU Ending Chat Control
- URL: https://techlore.tech/vpns-could-expose-you-to-nsa-spying-north-koreas-open-source-hijack-android-malware-hits-2-3-million-devices-via-google-play-and-the-eu-ending-chat-control/
- Published: 2026-04-10T01:17:14.000Z
- Updated: 2026-04-11T15:37:58.000Z
- Description: Techlore Surveillance Report: Weekly News for Your Digital Freedom
- Author: Henry Fisher
- Tags: Surveillance Report

This week's highlight story is a big one...six lawmakers are pressing intelligence officials to answer whether Americans using commercial VPNs could be stripped of their constitutional protections and treated as foreign targets under Section 702 of FISA. The irony here is these same organizations have all recommended that consumers use VPNs for privacy, which may inadvertently hand the NSA legal cover to surveil your traffic as if you're a foreign national. I don't think this is any reason to ditch your VPN, but it does expose the deeper flaw in how governments are approaching digital rights. I think the real fix isn't carving out exceptions for Americans; it's recognizing that mass surveillance is wrong, regardless of whose citizens it targets.

Beyond the VPN story, this was an enormous week. North Korea pulled off a weeks-long, methodically planned supply chain hijack of the widely-used Axios JavaScript library. And right as Google is pushing to lock down Android sideloading under the banner of Play Store safety, we got the story of NoVoice—Android malware distributed through 50+ Play Store apps with 2.3 million downloads, capable of surviving a factory reset. I also covered Apple's expanding device-level age verification, the EU Parliament's big vote to kill Chat Control (and Patrick Brayer's compelling five-point action plan for real child protection), and a packed Defense Bulletin with updates from VeraCrypt, Meta's child exploitation loss in court, Apple Maps ads, and more.

📰

Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG)

## Episode Sources

**Highlight: VPN Use May Subject You to NSA Spying**

- <https://www.wired.com/story/using-a-vpn-may-subject-you-to-nsa-spying/>
- <https://techlore.tech/vpns-nsa-spying-and-the-surveillance-double-standard-nobody-wants-to-address/>

**Story 1: North Korea's Weeks-Long Open Source Hijack**

- <https://techcrunch.com/2026/04/06/north-koreas-hijack-of-one-of-the-webs-most-used-open-source-projects-was-likely-weeks-in-the-making/>

**Story 2: Android Malware Infected 23 Million Devices via Google Play**

- <https://www.bleepingcomputer.com/news/security/novoice-android-malware-on-google-play-infected-23-million-devices/>

**Story 3: Apple Expands Device-Level Age Verification**

- <https://gizmodo.com/apple-requires-device-level-age-verification-in-the-uk-now-could-the-us-be-next-2000738481>
- <https://apple.slashdot.org/story/26/04/05/0120236/apple-brings-device-level-age-verification-to-two-more-countries>
- <https://www.wired.com/story/your-vape-wants-to-know-how-old-you-are/>
- <https://itsfoss.com/news/systemd-age-verification/>
- <https://gizmodo.com/group-pushing-age-verification-requirements-for-ai-turns-out-to-be-sneakily-backed-by-openai-2000741069>
- <https://futurism.com/artificial-intelligence/openai-nonprofit-child-safety>
- <https://adguard-vpn.com/en/blog/yoti-age-verification-gdpr-violation.html>
- <https://www.reuters.com/business/media-telecom/greece-ban-social-media-under-15s-2027-pm-says-2026-04-08/>
- <https://www.bbc.com/news/articles/cwyv70de9exo>
- <https://adguard-vpn.com/en/blog/age-verification-privacy-experts-open-letter.html>

**Story 4: EU Parliament Kills Chat Control**

- <https://www.patrick-breyer.de/en/end-of-chat-control-eu-parliament-stops-mass-surveillance-in-voting-thriller-paving-the-way-for-genuine-child-protection/>
- <https://www.patrick-breyer.de/en/the-end-of-chat-control-is-an-opportunity-5-point-action-plan-for-genuine-child-protection/>

**The Defense Bulletin**

- <https://techcrunch.com/2026/04/08/veracrypt-encryption-software-windows-microsoft-lock-boot-issues/>
- <https://www.wired.com/story/apple-will-push-out-rare-backported-patches-to-protect-ios-18-users-from-darksword-hacking-tool/>
- <https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-flaw-in-ninja-forms-wordpress-plugin/>
- <https://www.bleepingcomputer.com/news/security/linkedin-secretely-scans-for-6-000-plus-chrome-extensions-collects-data/>
- <https://www.bleepingcomputer.com/news/security/new-infinity-stealer-malware-grabs-macos-data-via-clickfix-lures/>
- <https://www.bleepingcomputer.com/news/security/backdoored-telnyx-pypi-package-pushes-malware-hidden-in-wav-audio/>
- <https://www.bleepingcomputer.com/news/security/claude-code-leak-used-to-push-infostealer-malware-on-github/>
- <https://www.404media.co/a-top-google-search-result-for-claude-plugins-was-planted-by-hackers/>
- <https://techcrunch.com/2026/04/01/whatsapp-notifies-hundreds-of-users-who-installed-a-fake-app-that-was-actually-government-spyware/>
- <https://www.404media.co/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless/>
- <https://arstechnica.com/tech-policy/2026/04/perplexitys-incognito-mode-is-a-sham-lawsuit-says/>
- <https://www.bleepingcomputer.com/news/security/adversaries-exploit-vacant-homes-to-intercept-mail-in-hybrid-cybercrime/>
- <https://alternativeto.net/news/2026/4/samsung-is-officially-discontinuing-its-native-messages-app-in-favor-of-google-messages/>
- <https://arstechnica.com/gadgets/2026/03/apple-confirms-that-its-maps-app-will-begin-showing-ads-to-users-this-summer/>
- <https://meta.slashdot.org/story/26/03/25/172211/meta-loses-trial-after-arguing-child-exploitation-was-inevitable>
- <https://meta.slashdot.org/story/26/03/25/1745232/meta-and-youtube-found-negligent-in-landmark-social-media-addiction-case>
- <https://www.bleepingcomputer.com/news/security/european-commission-confirms-data-breach-after-europaeu-hack/>
- <https://www.bleepingcomputer.com/news/security/dutch-police-discloses-security-breach-after-phishing-attack/>
- <https://www.bleepingcomputer.com/news/security/dutch-finance-ministry-takes-treasury-banking-portal-offline-after-breach/>
- <https://www.bleepingcomputer.com/news/security/dutch-ministry-of-finance-discloses-breach-affecting-employees/>
- <https://techcrunch.com/2026/04/02/telehealth-giant-hims-hers-says-its-customer-support-system-was-hacked/>
- <https://techcrunch.com/2026/04/01/hasbro-hacked-may-take-several-weeks-to-recover/>
- <https://techcrunch.com/2026/03/24/crunchyroll-confirms-data-breach-after-hacker-claims-unauthorized-access/>
- <https://www.bleepingcomputer.com/news/security/mazda-discloses-security-breach-exposing-employee-and-partner-data/>
- <https://arstechnica.com/security/2026/03/after-hack-some-ignition-interlock-users-couldnt-start-their-own-cars/>
- <https://www.bleepingcomputer.com/news/security/infinite-campus-warns-of-breach-after-shinyhunters-claims-data-theft/>
- <https://proton.me/business/blog/introducing-proton-meet>
- <https://proton.me/blog/meet-security-model>
- <https://proton.me/business/blog/proton-workspace>
- <https://blog.mozilla.org/en/firefox/built-in-vpn/>
- <https://blog.mozilla.org/en/firefox/split-view/>
- <https://blog.mozilla.org/en/firefox/tab-notes/>
- <https://blog.torproject.org/new-release-tor-browser-1508/>
- <https://tails.net/news/version%5F7.6/>
- <https://blog.torproject.org/new-release-tails-7%5F6%5F1/>
- <https://www.mullvad.net/en/blog/2026/3/26/mullvad-browser-alpha-moves-to-firefox-rapid-release-and-adds-linux-arm-support/>
- <https://alternativeto.net/news/2026/3/matrix-1-18-adds-policy-servers-invite-blocking-and-safety-api-updates/>
- <https://ente.com/blog/rust-crypto-audit/>
- <https://blog.crypt.ee/end-to-end-encrypted-photo-sharing/>
- <https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware/>
- <https://alternativeto.net/news/2026/4/dns-resolver-quad9-enables-dns-over-http-3-and-quic-globally-expanding-encrypted-options/>
- <https://linux.slashdot.org/story/26/04/02/0350211/steam-on-linux-use-skyrocketed-above-5-in-march>
- <https://itsfoss.com/news/gnome-drops-google-drive-support/>
- <https://itsfoss.com/news/onlyoffice-forked/>
- <https://alternativeto.net/news/2026/3/kali-linux-2026-1-launches-with-linux-6-18-theme-update-backtrack-mode-and-8-new-tools/>
- <https://itsfoss.com/news/kde-plasma-oxygen-air-comeback/>
- <https://itsfoss.com/news/pinetime-pro-early-look/>
- <https://www.waterfox.com/blog/15-years-of-forking/>
- <https://defcon.social/@llas/116334969059308748>
- <https://itsfoss.com/news/wayland-session-management/>