California Curbs Web-Tracking Suits, Plus 3 Stories
A new California web tracking law just changed one of the stranger legal risks that has been hanging over ordinary websites, and this one matters whether you run a national ecommerce operation or a five-page site for a local business.
Governor Gavin Newsom signed Senate Bill 690, narrowing who can sue under one specific part of the California Invasion of Privacy Act, or CIPA. That sounds like a niche legal cleanup. It isn’t, because plaintiffs have been using that provision against website analytics, advertising pixels, session-replay tools and other ordinary tracking technology.
California just took one web-tracking lawsuit off the table
The provision at issue covers “pen registers” and “trap-and-trace” devices. Those terms come from telephone surveillance, where a pen register records numbers dialed and a trap-and-trace device records incoming routing information. More recently, lawyers began arguing that website tracking tools could fit the same basic concept because they collect routing or metadata about a visitor’s interactions.
That argument created an uncomfortable mismatch between an old surveillance law and a modern website stack. According to Reuters, lawyers at Fisher Phillips estimate more than 4,700 digital-wiretap lawsuits invoking California law have been filed since 2022, with roughly two-thirds including the pen-register theory. CIPA can provide statutory damages of $5,000 per violation, which is how a tracking script that seems mundane can turn into terrifying arithmetic very quickly.
SB 690 says that when this particular pen-register claim arises from activity on a website, online application or mobile app, only California’s attorney general can bring the action. The change also applies retroactively to certain pending claims filed within two years before the law takes effect January 1.
Newsom said the bill addresses what he called the “vexatious use” of CIPA lawsuits and demand letters to extract settlements from small businesses. Privacy lawyers quoted by Reuters argue the change takes an enforcement tool away from consumers. Both points can be true enough to make the policy dispute understandable: abusive demand-letter economics are a real problem, and private lawsuits are also one way privacy rules get enforced when regulators don’t catch everything.
The part I don’t want lost in the headline is what SB 690 doesn’t do. California did not declare analytics pixels, session replay or ad tracking universally legal. The bill was narrowed from earlier language that would have protected a much broader range of tracking done for a commercial business purpose. Other CIPA theories, the California Consumer Privacy Act and other privacy rules still exist. If your takeaway is “great, we can stop worrying about consent and tracking disclosures,” you’ve taken the wrong lesson.
We’ve already seen why the distinction matters in recent fights over location and tracking data. The useful small-business takeaway here is narrower: one especially aggressive legal theory just got substantially weaker. Your privacy practices still need to make sense.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
FortiMail has a zero-day and the patch isn’t here yet
If you administer FortiMail, the second story is less philosophical. CVE-2026-104286 is a critical vulnerability in the FortiMail management interface, and Fortinet says attackers are already exploiting it.
The flaw combines a path-traversal problem with improper handling of a NULL character. In plain English, the management interface is supposed to constrain where a request can write a file. A specially crafted request can get around that boundary and write an arbitrary file to the appliance without authentication. Once an attacker can place files where they shouldn’t be able to, “it’s only a mail appliance” stops being comforting very quickly.
BleepingComputer reports the affected versions are FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9. FortiMail 7.2 users can move to 7.4 or later, but the fixed 7.4.9, 7.6.7 and 8.0.2 builds are still listed as upcoming for the other affected branches. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog.
So this is one of those irritating security stories where “install the patch” is correct advice that can’t yet solve the whole problem. Fortinet says administrators can disable Identity-Based Encryption support as a temporary mitigation, or keep the management interface off the public internet and restrict it to trusted private networks. Fortinet has also published indicators of compromise tied to the observed attacks.
If you run an affected appliance, mitigate it now and check the published indicators. Then install the fixed build when it arrives. And if there is evidence the device was already compromised, remember the rule we’ve been coming back to all month: closing the hole and investigating what happened while it was open are two different jobs.
WordPress security & maintenance
Keeping WordPress current is only part of keeping it healthy. Raymond Tec handles updates, backups, security monitoring, compatibility problems, access cleanup, and maintenance — plus the assorted weirdness that accumulates on a site over time.
Half a million GitHub credentials were still alive
Truffle Security went looking through a snapshot of 224 million public GitHub repositories and found 1,103,438 exposed credentials. When the company went back in late July and actually tested the candidates against the services that issued them, 543,699 still worked.
That number deserves one important qualification. This wasn’t a fresh scan of GitHub in July. The repository corpus, called The Stack v3, finished crawling in August 2025. Truffle then tested the credentials nearly a year later. That’s what makes the result interesting: these weren’t merely secrets that appeared in public code for a few minutes before somebody cleaned them up. The median credential had been exposed for 784 days.
GitHub’s secret scanning and push protection do help. Truffle’s research found the default block roughly halves the rate at which credential formats it recognizes reach public code. But 199,843 of the credentials that were still working came from files modified after GitHub turned push protection on by default in 2024. More than half of the live credentials were formats the default protection doesn’t recognize well enough to block.
There is a simpler failure underneath all of that: detection isn’t revocation. Deleting an API key from a repository, rewriting the commit or making the project private does not make the key stop working. If a credential was public, the safe assumption is that it was copied. Rotate or revoke it at the provider, then replace it everywhere that legitimately needs the new value.
That’s not glamorous security advice, but it scales from one-person development shops to huge software companies. If you’ve ever had that awful “oops, the .env file got committed” moment, cleaning Git history is only half the repair.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
Amazon’s delivery glasses bring cameras to the doorstep
Amazon’s camera-equipped delivery glasses are a good example of a technology that can be useful and uncomfortable at exactly the same time.
Amazon says the glasses use cameras, AI and computer vision to scan packages, provide walking directions, capture proof of delivery and warn drivers about hazards and pets. More than 500 delivery associates have tested them across more than 275,000 deliveries, and Amazon says thousands more devices will roll out through 2027. Use is voluntary for delivery partners and drivers.
The privacy story is what happens around that useful feature set. The Verge, citing Bloomberg, reports the glasses may make several thousand image captures during a typical shift and upload them to Amazon’s AI systems. Amazon says people and license plates are blurred before images go to human reviewers, and an executive said the intent isn’t surveillance. Bloomberg also reports Amazon hasn’t settled on a customer opt-out, wouldn’t specify retention time, and doesn’t plan to give customers a way to inspect or delete images of themselves or their property.
I don’t think the useful question is whether delivery glasses are secretly spy glasses. They’re doing a real job, and computer vision needs images to do that job. The useful question is what rules should follow when a work tool routinely captures the world around the worker: what gets stored, for how long, who can see it, what can be compelled by law enforcement, and what control the people being recorded get.
We’re going to have this conversation a lot more often as cameras move from phones and doorbells onto faces. The technology can be genuinely useful. That doesn’t make the data-governance questions disappear; it makes answering them part of building the product.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- California Legislature: SB 690 — Crimes: invasion of privacy
- Reuters: Thousands of web-tracking lawsuits face extinction under California overhaul
- BleepingComputer: Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
- Truffle Security: GitHub repos exposed 543,699 credentials
- SecurityWeek: 500,000 active credentials left exposed on GitHub
- Amazon: Delivery glasses use AI and computer vision
- The Verge: Amazon delivery smart-glasses privacy questions
Photo by Liam Charmer on Unsplash.
