Right To Know - August 2026, Vol. 44
Cyber, Privacy, and Technology Report
Welcome to your monthly rundown of all things cyber, privacy, and technology, where we highlight all the happenings you may have missed.
View previous issues and sign up to receive future newsletters by email here.
Litigation & Enforcement:
- DOJ Targets Alleged Russian Cybercrime Infrastructure Operators: The U.S. Department of Justice unsealed an indictment against three Russian nationals and two Russia-based companies, Media Land and ML.Cloud, alleging they operated infrastructure that enabled cybercriminal activity resulting in more than $62 million in losses to victims worldwide. According to federal prosecutors, the defendants provided “bulletproof hosting” services, a type of hosting designed to help cybercriminals evade detection and law enforcement scrutiny while conducting malicious operations. The charges stem from a seven-year investigation involving U.S. and international law enforcement partners. Prosecutors allege that the defendants’ infrastructure supported a wide range of cybercriminal activity, including ransomware attacks, malware distribution, phishing campaigns, brute-force attacks, and other online fraud schemes. The impact was significant, with victims spanning 21 U.S. states and multiple countries. Organizations affected reportedly include banks, hospitals, schools, government agencies, and media companies, highlighting the broad threat posed by cybercrime-enabling services that facilitate attacks against critical institutions and businesses. In addition to the criminal charges, the U.S. State Department’s Rewards for Justice program announced a reward of up to $10 million and possible relocation for information related to the defendants and their cyber activities. The defendants and associated companies have previously been sanctioned by the United States and allied governments, including the United Kingdom, Australia, and the European Union. These efforts reflect a growing international effort to target not only cybercriminals themselves but also the infrastructure providers that enable ransomware, phishing, and other large-scale cyberattacks.
- Serial CIPA Plaintiff Hits a Prefiling Wall: The United States District Court for the Central District of California granted Crain Communications’ motion to declare Vivek Shah a vexatious litigant, citing his history of at least twenty-nine lawsuits—including a recent run of near-template CIPA website-privacy complaints that repeatedly ended at the pleading stage or by voluntary dismissal. The court found the pattern sufficiently frivolous and harassing to warrant a prefiling order. Going forward, Shah must obtain leave before filing new CIPA or related digital-privacy claims in the Central District of California courts.
- Anthropic Settlement Approved, but AI Copyright Fight Continues: A federal judge in the United States District Court for the Northern District of California gave final approval Monday to Anthropic’s $1.5 billion copyright settlement with authors and publishers who alleged the company used copyrighted books to train Claude. The deal covers an estimated 500,000 works and provides $3,000 per eligible work. The approval is a milestone, not an endpoint. AI-training copyright suits remain pending against various other popular AI tools.
- Apple Sues OpenAI for Stealing Secrets: Apple has sued OpenAI, along with former Apple executives Chang Liu and Tang Yew Tan, accusing them of stealing confidential Apple trade secrets to accelerate OpenAI’s consumer hardware efforts. The lawsuit alleges that Liu improperly retained and accessed Apple systems to download confidential hardware files, while Tan emailed himself sensitive information about suppliers and internal projects before leaving the company. Apple also claims Tan continued gathering proprietary information by questioning current employees about secret projects and asking them to bring Apple hardware to meetings. Apple is seeking a court order requiring the defendants to stop using its technology, preserve evidence, and return any confidential materials. The lawsuit marks a significant escalation in tensions between the two companies, which currently partner to integrate ChatGPT into Apple devices. The dispute comes as OpenAI expands into hardware following its $6.5 billion acquisition of io Products, a startup co-founded by former Apple designer Jony Ive and Tan, highlighting the increasingly fierce competition between major technology companies in the race to develop AI-powered consumer products.
Industry Updates:
- Cato Networks Study Shows How AI Is Accelerating Cyber Threats: Recent research from cybersecurity firm Cato Networks points to a major shift in cyber threats: the rise of the “agentic attacker.” In a controlled enterprise lab, researchers showed that an AI-powered attack stack—combining a frontier language model, agent platform, MCP-enabled tools, and operational guidance—could compromise an Active Directory environment from initial access to Domain Administrator privileges. The fastest successful attack reached its goal in just 40 minutes from a single high-level prompt, with the AI handling much of the planning and execution on its own. The study found that the model was only one part of the equation. Success relied heavily on the surrounding ecosystem: agent orchestration, operational context, specialized tools, and clear objectives. Across several scenarios, better guidance, context, and tooling mattered more than switching models. Researchers observed the AI conducting reconnaissance, exploitation, privilege escalation, lateral movement, and data collection while adapting when blocked. The researchers cautioned that the results did not reveal new hacking techniques. Instead, they show how advanced AI can lower barriers and accelerate attacks by combining automation with existing cybersecurity methods. Defenders should prepare by strengthening monitoring, detection, governance, and response capabilities as AI-enabled threats continue to evolve.
- State Department, FBI, and International Partners Issue Alert Regarding Fraudulent North Korean Remote IT Workers (DR): On Jul. 31st, the U.S. State Department, Federal Bureau of Investigation, and international partners issued “Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers.” It follows FBI Alert Number: I-072325-4-PSA, “North Korean IT Worker Threats to U.S. Businesses,” (July 23, 2025) warning about the same threat. The new Alert warns about a North Korean network of skilled Information Technology workers that uses false identities to get remote jobs to earn income to fund North Korea’s unlawful nuclear weapons and ballistic missile programs. It explains in detail how the scheme operates and provides advice for companies operating online platforms and companies hiring remote workers and using remote services. There have been news media reports that this is a widespread international problem. Companies operating covered platforms and using covered remote workers and services should review this alert and address the warnings it provides.
- Microsoft Patches Record 663 Vulnerabilities: Microsoft released patches for a record-breaking 663 vulnerabilities in its July 2026 Patch Tuesday, including two flaws that were already being exploited as zero-days. The exploited vulnerabilities affect Active Directory Federation Services (CVE-2026-56155) and SharePoint Server (CVE-2026-56164), both of which could enable privilege escalation. Microsoft also highlighted a publicly disclosed BitLocker security-feature bypass vulnerability and several critical flaws affecting Windows VMSwitch, SharePoint, Remote Desktop Protocol, DHCP Server, Exchange Server, and other products. Of the 663 vulnerabilities, 421 affect Windows and 180 affect Microsoft Office, with additional fixes covering Azure, Defender, Exchange Server, Edge, SQL Server, and developer tools. The unusually large update pushed Microsoft’s 2026 year-to-date CVE count above previous annual totals. Microsoft attributes the increase in vulnerability discovery in part to its growing use of AI-powered security testing, including its multi-model agentic scanning system, MDASH, which is designed to identify vulnerabilities more quickly across the Windows codebase.
- OpenAI AI Agent Compromises Hugging Face Infrastructure During Cybersecurity Testing: OpenAI disclosed a July 2026 security incident involving Hugging Face that occurred while testing experimental AI models for advanced cybersecurity capabilities. During the evaluation, the models went beyond the intended testing environment and interacted with Hugging Face infrastructure in unauthorized ways, demonstrating how increasingly capable AI agents can potentially identify and exploit weaknesses in external systems. Hugging Face detected the activity, and the incident was contained without evidence of broader malicious intent. The incident highlights an emerging AI security and sandboxing risk: models with advanced cyber capabilities may behave unpredictably or exceed the boundaries established for controlled security testing. OpenAI said the event prompted changes to its evaluation infrastructure and safeguards, emphasizing the need for stronger isolation and monitoring as AI systems become more autonomous and capable of performing complex cybersecurity tasks.
- Small-Town Water Systems, Big-Time Target: Seven States Hit by Coordinated Cyberattacks: On Jul. 30th, the FBI and Environmental Protection Agency issued a joint Public Service Announcement regarding an ongoing cyber-attack against water and wastewater utility companies. Victims across seven states have reported flooding and loss of water pressure, with the largest concentration in Minnesota, where more than 30 water systems were targeted. Michigan has also reported that nine of its municipal water systems were hit. Federal officials have urged utilities to switch to manual operations as a backup and to remove exposed systems from the internet but have emphasized that there is no indication that the water supply is unsafe to drink. Attribution remains unconfirmed but the US Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI and EPA among others, issued a warning in April that “Iran-affiliated” hackers were targeting water infrastructure, among other entities. On Jul. 22nd, CISA also updated a prior advisory on the same topic providing additional recommendations.
- CISA Publishes Lessons from CISA’s Cyber Incident: On Jul. 9th, the Cybersecurity and Infrastructure Security Agency (CISA) published “Lessons from CISA’s Cyber Incident” covering an incident in May 2026 in which internal CISA Amazon AWS GovCloud Keys and other information were available in GitHub, a public repository. It describes CISA’s incident response process, including “stop the bleeding,” “understand scope,” “assess impact,” and “corrective actions,” as well as the preparation of an after-action report (effective practices and areas for improvement). It identified several areas that could be strengthened, including preparation of incident response playbooks for all anticipated needs.
- CISA Publishes Guidance on Open-Source Software: Security Principles and Practices: On Jul. 30th, the Cybersecurity and Infrastructure Security Agency (CISA) published “Open Source Software: Security Principles and Practices” to help agencies to securely use, evaluate, and publish open-source software (OSS). It explores the background, benefits, and risks of OSS and risk management across the full OSS lifecycle. The Guidance also introduces the C4 Framework for trust assessment and provides recommendations for vulnerability management, software bills of materials, secure development, and handling artificial intelligence OSS. While it is directed to agencies, it also provides helpful guidance for businesses and organizations that use OSS.
- State Department Launches Digital Freedom Program Featuring Bitcoin: The U.S. State Department is launching the Freedom Tech Excellence Program (FTEP), an initiative aimed at advancing digital freedom worldwide. Working with the Bitcoin Policy Institute, Palantir Technologies, Anduril Industries, and the Victims of Communism Memorial Foundation, the program will address online surveillance, encryption, AI governance, free expression, online scams, and protections for children and other internet users. Private-sector personnel will also undertake temporary assignments within the State Department to help shape diplomatic efforts concerning specific digital-freedom issues. The initiative reflects the Trump administration’s broader support for cryptocurrency. In March 2025, President Trump signed an executive order establishing a Strategic Bitcoin Reserve and a separate U.S. Digital Asset Stockpile using digital assets already held by the federal government through forfeiture proceedings, treating Bitcoin as a strategic national asset rather than merely a speculative investment.
Regulatory:
- Delete Act Goes Live for Data Brokers as DROP Processing Obligations Take Effect: As of Aug. 1st, California’s Delete Act shifted from statute to active enforcement, requiring registered data brokers to begin honoring consumer requests submitted through the Delete Request and Opt-Out Platform (DROP). Created under the Delete Act and administered by the California Privacy Protection Agency, DROP lets California residents submit a single verified request that reaches every registered data broker in the state, rather than contacting hundreds of companies individually to delete their personal information and stop its sale. Beginning August 1, brokers must download consumer deletion lists from DROP at least once every 45 days, delete matching personal information in their databases, and report the status of each request back to Cal Privacy. They generally have 90 days to act on a request, must treat unresolved deletions as opt-out requests at a minimum, and must maintain suppression lists so the information isn’t re-collected or resold. Noncompliance carries financial penalties of $200 per consumer, per day.
- California Privacy Protection Agency Targets Gig Economy Platforms in First CCPA Audit: On Jul. 21st, the California Privacy Protection Agency announced the first formal California Consumer Privacy Act audit under California Civil Code § 1798.199.40, targeting gig economy platforms, such as app-based transportation, delivery, and task services operating in California. In its press release, the Agency noted that these platforms often collect “extensive personal information” including geolocation, biometric, financial, and communications data that may be used by algorithmic systems to make decisions regarding worker assignments, ratings, earnings, and account status. The audit will assess whether workers and consumers can effectively exercise their rights to know what personal information is collected, how it is used, and with whom it is shared, as well as whether companies comply with the statute’s 45-day deadline for responding to access requests.
International Updates:
- EDPB Publishes Draft Guidelines on Web Scraping for Generative AI Training: On Jul. 7th, the European Data Protection Board adopted draft Guidelines 03/2026 addressing how the GDPR applies when organizations scrape publicly available personal data to develop or train generative AI models. The guidance covers direct scraping, outsourced scraping, and acquisition of previously scraped datasets. It emphasizes that controller and processor roles depend on the parties’ actual decisions and responsibilities, and that organizations remain accountable even when they cannot readily identify all affected individuals or data types. The EDPB identifies legitimate interests as the most likely lawful basis but requires a specific interest, necessity analysis, and balancing of individual rights and reasonable expectations. Recommended safeguards include targeted collection criteria, source exclusions, respect for anti-scraping measures, filtering, pseudonymization, synthetic data, public notices, opt-out mechanisms, and protections against model memorization. Special-category data requires heightened controls. The draft remains open for public consultation through October 30, 2026, and may change before final adoption.
- Germany Expands Media Oversight to AI Search Tools: Germany’s media regulator has determined that Google’s AI Overviews and Perplexity AI are subject to the country’s media laws, increasing scrutiny of AI-generated search results and chatbot responses. The regulator concluded that these services create and present their own content rather than merely displaying third-party material. As a result, providers may be held directly responsible for inaccurate or unlawful AI-generated statements and may not qualify for certain liability protections under the European Union’s Digital Services Act.
State Actions:
- 42 State Attorneys General Reach Settlement with 23andMe Over 2023 Genetic Data Breach: A coalition of 42 state attorneys general announced a settlement resolving claims arising from 23andMe’s 2023 data breach, which exposed the personal and genetic information of approximately 6.9 million customers worldwide. Although the settlement allows $150 million in state claims, recovery is limited to $18 million due to the company’s bankruptcy. The attorneys general alleged that 23andMe failed to implement basic cybersecurity safeguards, including protections against credential stuffing attacks, multifactor authentication, rate limiting, intrusion detection, and effective monitoring of suspicious login activity. Following its March 2025 bankruptcy filing, 23andMe’s assets, including its genetic database, were acquired by the newly formed 23andMe Research Institute. As part of the bankruptcy proceedings, the purchaser agreed to enhanced privacy and security obligations, including stronger cybersecurity controls, ongoing consumer deletion rights, comprehensive privacy law compliance, and governance oversight.
- New Jersey Adopts New Data Broker Registry and Sensitive Data Sales Restrictions: On Jun. 30th, New Jersey Governor signed A.5328, establishing a new regulatory framework for both “data brokers” and “data collectors.” The Act defines a “data broker” as a person or legal entity that knowingly collects or purchases the personal data of a consumer with whom it does not have a direct relationship and sells or licenses that data to a third party. A “data collector” is a business, or unit of a business, that knowingly collects the personal data of a consumer with whom it has a direct relationship and sells or licenses that personal data to a data broker. The law requires covered entities to register annually, pay fees ranging from $5,000 to $1.5 million based on the volume of New Jersey consumer data involved, and provide specified disclosures, with the initial registration period scheduled to run from April 1 through June 30, 2027. The Act also prohibits controllers, data brokers, and data collectors from selling or licensing “sensitive data,” including health information, biometric data, precise geolocation data, financial information, personal data collected from a known child, and information revealing traits such as race, religion, sexual orientation, or immigration status. Notably, the prohibition is not subject to a consent-based exception and applies regardless of the number of consumers whose data an entity controls or processes. The law imposes significant penalties, including $2,500 per day for certain registration violations and up to $50,000 per record for the unlawful sale, offer for sale, or licensing of sensitive data.
This publication is intended for general informational purposes only and does not constitute legal advice or a solicitation to provide legal services. The information in this publication is not intended to create, and receipt of it does not constitute, a lawyer-client relationship. Readers should not act upon this information without seeking professional legal counsel. The views and opinions expressed herein represent those of the individual author only and are not necessarily the views of Clark Hill PLC. Although we attempt to ensure that postings on our website are complete, accurate, and up to date, we assume no responsibility for their completeness, accuracy, or timeliness.