HeadFlash

Privacy

Newsom Vetoes AB 1542 as 19 of 21 Cars Leak Data

California keeps sensitive data on sale, connected cars phone home, and a filesystem flaw tracks users across every major OS.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Governor Gavin Newsom vetoed AB 1542 on Sunday, leaving precise geolocation, health records, immigration status and four other sensitive categories legally sellable in California. The legislature passed the bill 31 to 4 in the Senate and 44 to 19 in the Assembly, and the California Privacy Protection Agency endorsed it. Introduced by Assemblymember Chris Ward, it would have replaced CCPA opt-out rules with a categorical ban on selling or sharing sensitive data. Newsom called a categorical ban a step too far, saying consumers should not be removed from the decision process. Nearly 20 businesses lobbied against it. Consumer Reports called the veto a gift to data brokers, scammers and spammy marketers. Newsom signed SB 923 the same day, extending CCPA deletion rights effective January 1, 2027.

Location, Health, Immigration Data Still for Sale in California After Newsom Veto →

Study Finds 19 of 21 Late-Model Cars Share Data With Third Parties

A Northeastern University study with Consumer Reports tested 21 late-model vehicles and 30 companion apps, finding 19 vehicles sent data to third parties. Researchers captured Wi-Fi traffic via a Raspberry Pi access point, testing idle, active and driving states from 5 to 45 mph, plus 11 EVs in a Faraday tent. Vehicles contacted manufacturer domains, support parties and advertising and tracking services. Seven of 30 apps transmitted VINs, emails, phone numbers and precise locations, roughly doubling exposure. Tesla and General Motors shared at higher rates. Alphabet, Amazon, Meta, Microsoft, Pinterest and Reddit were top recipients. Of 14 responding manufacturers, all blamed third-party contracts; seven also blamed consumers. Honda improved its practices.

19 Out of 21 Late-Model Cars Tested Shared Data With 3rd Parties, Including Big Tech Companies: Study →

Filesystem Attack Tracks Users Across Windows, macOS, Linux and Android

Researchers at Graz University of Technology demonstrated an attack tracking users via file change events across all major operating systems, assuming only local, unprivileged access and read access to globally readable files. It exploits built-in monitoring subsystems: inotify on Linux, ReadDirectoryChangesW on Windows and FSEvents on macOS. On Linux they achieved a keystroke timing attack inferring typed text including passwords, and fingerprinted the top-100 websites via font access patterns. In KDE a fake authentication popup stole a password, exploiting broken focus-stealing protection. Android leaked file existence and filenames, revealing activity in private messengers. Windows exposed full paths of files the attacker could not read, an undocumented behavior. Microsoft said the leakage was by design.

New Attack Can Track You Across Operating Systems Without Elevated Privileges →

Liberties Urges EU Council to Drop Data Omnibus AI Privacy Exemption

Liberties sent a letter urging EU Member States to abandon plans empowering AI companies and undermining privacy in the Digital Omnibus, also called the Data Omnibus. The Commission suggested exempting AI technologies from protecting personal information to help European AI firms compete with Chinese and US rivals. Liberties argued every company would benefit, including US and Chinese firms operating in Europe, undermining the Commission’s own rationale. The letter targets Article 88 bis of the Council document, warning it would let ChatGPT train on chat discussions or Facebook use users’ blogposts. With Ireland holding the Council Presidency and hosting most large Big Tech companies, Liberties called it a gift to Big Tech and criticised the rushed negotiations while Parliament still disagrees.

The EU is Pushing to Weaken Privacy Rules for AI | liberties.eu →

Pentagon Breach Exposed Data on Nearly 3 Million People

A Pentagon data breach exposed sensitive information on nearly 3 million people and took months to discover, according to a defense official. Few further details were immediately available about the incident, which adds to a growing list of large-scale government data exposures. The months-long gap between the breach and its discovery highlights persistent detection weaknesses in systems holding highly sensitive personal records. More information on the scope of the compromised data and the response is expected as the investigation continues.

Pentagon data breach took months to discover, reports show →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches