Meta Jury Finds 43.9M Violations, Plus 3 Stories
43.9 million violations is not 43.9 million people
The Meta New Mexico verdict produced two enormous numbers Friday, and both need an asterisk before they become useful.
A Santa Fe jury found that Facebook committed 43,899,725 violations of New Mexico’s Unfair Practices Act. That does not mean 43.9 million people were harmed, breached or even using Facebook in New Mexico. The number comes from the way the jury counted allegedly deceptive statements across the population or Facebook-user base affected by those statements.
The second number is even easier to turn into a headline: New Mexico law allows a civil penalty of up to $5,000 for each willful violation. Multiply that by the jury’s count and you get a theoretical ceiling north of $219 billion.
Meta has not been fined $219 billion.
The jury decided liability. Judge Francis Mathew still has to decide the penalty, and the New Mexico Department of Justice says the amount is entirely within the judge’s discretion. The state is asking for the maximum and also wants an injunction. Meta says it disagrees with the verdict and will continue defending itself.
What the jury did find is substantial. According to the New Mexico DOJ, jurors concluded Facebook made willfully false or misleading statements about how users controlled their information, whether Facebook sold or provided personal information to advertisers, how consistently it enforced Community Standards, what it did about misinformation and hate speech, and how thoroughly it investigated third-party apps after the Cambridge Analytica scandal.
The verdict wasn’t a clean sweep for the state. Associated Press reporting says jurors rejected some claims involving Facebook’s statements about removing harmful content. Meta argued that New Mexico relied on outdated material and says its policies and systems have changed.
One more distinction matters: this is separate from New Mexico’s child-safety case against Meta that Raymond Tec covered in August. Same company, same state, different lawsuit.
I don’t think the giant theoretical fine is the most useful part of this story. The more durable point is that privacy settings and content policies aren’t just product copy once a company tells customers what those controls supposedly do. They can become representations that regulators, courts and juries compare against what the system actually did.
There isn’t an action item for ordinary Facebook users today, and this isn’t a class action with a claim form. But if you’re a business writing your own privacy promises, “we protect this,” “we don’t share that,” and “you control this setting” are not harmless marketing sentences. Say what your system actually does.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Check Point customers have two active-exploit patches to install
If you run Check Point firewalls or Security Management, this part is much less philosophical: check the version and install the actual fix.
Check Point says attackers are exploiting two critical vulnerabilities, both rated 9.8 out of 10. CVE-2026-85102 is a pre-authentication remote-code-execution flaw in VPN certificate handling on Security Gateway and Spark Firewall products. “Pre-authentication” is the important phrase. The vulnerable code can be reached before an attacker has a valid login.
A fix for that flaw has been available since September 9. Check Point says it began seeing exploitation attempts against Spark customers around the world on September 12.
The second problem, CVE-2026-93616, affects Check Point Security Management. It’s a pre-authentication path-traversal flaw that can lead to arbitrary script execution and loading an arbitrary Java class. Check Point says it saw a handful of targeted attacks on July 23 and released the fix with its September 22 advisory.
There is one wrinkle worth putting in bold in an administrator’s head: Check Point says LivePatch Take 28 and 29 do not fix CVE-2026-93616. “We have LivePatch” is therefore not the same thing as “this vulnerability is fixed.”
If an affected system was exposed before the patch went on, don’t make the common mistake of treating a successful update as a time machine. Check Point recommends reviewing logs and its published indicators for suspicious access and follow-on activity. Patch first, yes. Then ask whether somebody got there before you did.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
The FTC is asking whether platforms should be responsible for scam ads
The Federal Trade Commission has opened an advance notice of proposed rulemaking about impersonation scam ads. That phrase matters: this is the beginning of a rulemaking process, not a new rule that took effect Thursday.
The FTC wants public comment on whether its existing Impersonation Rule should be expanded, whether a separate rule is needed, or whether some other action should address the role that social networks, search engines and other digital marketplaces play when their advertising systems optimize and distribute scam ads.
The scale is not theoretical. The FTC says consumers filed more than one million imposter-scam reports in 2025 and reported nearly $3.5 billion in losses. Nearly 30% of people who reported losing money to scammers said the first contact came through social media, representing $2.1 billion in reported losses.
Among the questions the agency is asking: should platforms have stronger duties to vet advertisers, monitor ads, investigate suspected impersonation, remove confirmed scam ads and discipline repeat offenders?
A separate investigation from CERT Polska this week is a pretty good illustration of why those questions exist. Researchers began with two Facebook ads falsely warning Polish users that their PDF software had expired. The ads sent people to Google Play, where they were offered an unrelated app called Messenger Pro. The investigation eventually connected 852 Meta ads, displayed under 60 profile names, to 17 Google Play apps tied through code or infrastructure to a toll-fraud operation. Some of the confirmed malware could send premium SMS messages or enroll devices in recurring carrier-billing services.
That Polish campaign is not the FTC’s case, and it isn’t evidence that every paid ad or every app-store listing is malicious. It does show the trust problem rather neatly. People have been taught that a paid ad on a familiar platform and an app available through an official store are signals that somebody has done at least some checking.
Sometimes they are. They are not guarantees.
If an ad claims software on your phone has suddenly “expired” and sends you to install an unrelated messaging or cleaner app, stop. For businesses, the same ecosystem creates another problem: scammers can borrow your name and reputation while the platform gets paid to put the fake in front of potential customers.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Cloudflare fixed a cloud flaw that exposed old disk fragments
Cloudflare disclosed a fascinating Containers vulnerability Thursday, and I mean “fascinating” in the technical sense. If you were a customer, this is the kind of fascinating you’d rather read about after it’s fixed.
Cloudflare Containers and Sandboxes run customer workloads on shared physical infrastructure. Security researcher Oren Yomtov of Accomplish found that a paid Workers customer could sometimes recover residual disk blocks left behind by a different customer’s container that had previously used the same underlying storage.
The bug was in Linux device-mapper thin provisioning. Cloudflare explains that its storage pools used 64-kilobyte blocks and had block zeroing disabled. When a used block was returned to the shared pool and later reassigned, a new 4-kilobyte write could overwrite only that small portion while leaving the other 60 kilobytes holding bytes from the previous tenant. Reading the raw device could then reveal those leftovers.
That is a real cross-tenant isolation failure. It was not, however, a magic button for targeting a particular Cloudflare customer. Cloudflare says the researchers couldn’t select a specific customer, workload, host or data set, and residual data wasn’t guaranteed to be present.
Cloudflare says it fixed the configuration across the Containers fleet, cleared pre-fix cached snapshots by September 19 and found no evidence of malicious exploitation in the historical telemetry it retained. Customers don’t need to change anything.
The broader lesson is wonderfully boring: multi-tenant cloud security includes what happens to storage after one customer’s workload disappears and before that physical space gets handed to somebody else. The guarantee you want is that somebody else’s leftovers become zeroes before they become your disk.
For a while here, they didn’t.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- New Mexico Department of Justice: Jury finds Facebook violated New Mexico consumer protection law
- Associated Press: New Mexico jury finds Facebook liable for deceiving users about privacy protections
- Check Point: Active exploitation of CVE-2026-85102 and CVE-2026-93616
- FTC: Public comment on platforms’ role in impersonation scams
- CERT Polska: Multi-stage toll fraud operation using Meta ads and Google Play
- Cloudflare: How it addressed a cross-tenant Containers data exposure vulnerability
Photo by Solen Feyissa on Unsplash.
