> daily_signal(2026_08_03)

A city switched its surveillance vendor before the public was told, a cheap TV stick shipped a backdoor, and the volunteers and AI meant to keep software and science honest ran thin.

PickBits Daily Signal · Monday, August 3, 2026

This is the teaser. The full edition — all 4 stories, sources, and what to do about each — is on Substack. Read it free at pickbitsai.substack.com.

1. The body-cam monopoly just switched on a warrantless license-plate dragnet in Syracuse — Axon's move onto Flock's turf.

Switching a city's surveillance vendor from Flock to Axon doesn't shrink the dragnet; it hands the same warrantless tracking to the company with the deepest federal ties.

Key fact: If your city or county is weighing an ALPR contract (Axon or Flock), demand the written data-retention and data-sharing policy in the procurement record before a vote — Syracuse's permits use 'for any investigation' and shared 697,104 reads before the public was told the system was live.

Central Current reports the Syracuse Police Department activated 14 of 26 Axon automatic license plate readers at 7:00 a.m. on Monday, July 28, 2026, with 12 more still to be installed, and that the transparency portal already showed 697,104 plate reads logged before public activation. · New York Assemblymember Pam Hunter called the system 'a constant, warrantless surveillance system,' saying 'it's the same tech, and it serves the same purpose' as the Flock cameras it replaces; NYCLU's Daniel Schwarz and the Melt Coalition's Genevieve Garcia Kendrick are quoted opposing it. · Bruce Schneier (Schneier on Security, July 2026) argues switching from Flock to Axon is like switching gambling addictions — Axon's cameras still collect personal details far beyond a plate number, and Axon carries deeper ties to the federal government than Flock, so a city loses no privacy by swapping vendors. · primary source

2. The internet's most-used transfer tool stopped taking security bug reports for all of July — AI 'slop' had made volunteer triage a full-time chore.

When the software everyone ships is guarded by volunteers, a flood of AI-generated fake vulnerability reports isn't a nuisance — it taxes the exact people who keep the supply chain safe until they close the door.

Key fact: Security/engineering leaders: inventory the volunteer-maintained open-source projects in your SBOM (curl/libcurl almost certainly among them) and back them with a paid support contract or sponsorship rather than only filing bugs — Stenberg's paid customers kept service through the freeze while everyone else waited.

LWN.net reported on June 15, 2026 that curl declared a 'summer of bliss' and accepted zero vulnerability reports from July 1 through August 3, 2026; maintainer Daniel Stenberg wrote 'Now we need some rest. We do not expect this deluge to be over,' paid support-contract customers kept full service, and the curl 8.22.0 release slipped to September 2, 2026. · IT Pro (January 22, 2026) reported that Stenberg had already shut down curl's bug bounty — run since 2019 — after the twenty vulnerability reports submitted in early 2026 produced a 0% confirmed-vulnerability rate (not one described a real bug); he said the aim was to 'remove the incentive for people to submit crap and non-well researched reports.' · The problem is AI-generated reports that read like genuine CVE write-ups — plausible titles and root causes — but cite functions curl never had or bugs patched years ago; every one still costs the volunteer team triage hours to disprove, which is why, after a January batch of twenty reports confirmed zero real bugs, curl chose to close its intake for the month rather than keep filtering. · primary source

3. That $30 Android TV stick on Amazon ships with a factory backdoor that rents out your home internet.

You don't get hacked later — the device arrives already enrolled in someone else's crime infrastructure, before you plug it in.

Key fact: Do not buy no-name Android TV boxes/sticks (H96 and similar generic brands) that promise 'free' streaming for a one-time fee; stick to devices from vendors that ship verified firmware (Roku, Apple TV, Google TV, Amazon Fire) and can push security updates.

Krebs on Security (Brian Krebs, 2026-07-30) reports that cheap Android TV streaming sticks — including the H96 model currently advertised on Amazon — ship with a preinstalled backdoor, and that roughly 38,000 such boxes worldwide were still phoning home to an expired domain tied to Zhejiang Fengwo IoT Technology Ltd (the 'Fengwo Group,' founded 2019 in mainland China). · Bitsight threat researcher Pedro Fale found the compromised boxes spoof themselves as mobile phones (Samsung, Vivo, Huawei, Xiaomi models) to commit click fraud on AI-generated websites, and toggle between residential-proxy mode when the TV is on and ad-fraud mode when it's off — earning an estimated $50,000 a day from ad fraud off a single older domain. · The report cites a 2025 FBI advisory warning that internet-connected devices like these facilitate criminal activity by turning a home's internet connection into a residential proxy rented out to strangers. · primary source

4. An AI 'spam filter' for science just screened 2.6 million cancer papers — and flagged more than 250,000 as likely paper-mill fakes.

The fraudulent-research problem quietly poisoning the cancer literature has been invisible at scale; a free, open machine-learning tool finally makes it measurable — the first step to cleaning up the studies doctors and patients actually rely on.

Key fact: Clinicians and evidence reviewers: when a cancer finding rests on a single study — especially in the hardest-hit fields (gastric, liver, bone, lung) — check it against Retraction Watch and look for independent replication before acting on it, since the BMJ screen shows more than 1 in 6 recent cancer papers in some areas carry paper-mill warning signs.

ScienceDaily (reported July 16, 2026) reports that a team led by Professor Adrian Barnett of Queensland University of Technology, publishing in The BMJ (2026;392:e087581), used a BERT machine-learning model to screen 2.6 million cancer research papers published from 1999 to 2024 and flagged more than 250,000 of them — about 1 in 10 — as sharing the linguistic fingerprints of known paper-mill and retracted fraudulent work. · The tool — which Barnett likens to 'a scientific spam filter' — correctly identified suspicious papers about 91% of the time against verified examples, and found the share of flagged cancer papers rose from roughly 1% in the early 2000s to a peak of more than 16% in 2022, with gastric, liver, bone and lung cancer among the worst-hit fields. · The researchers stress the flags are 'warning signals, not confirmed findings of misconduct' and that each paper still needs human expert review — but the screen is the first to measure the scale of suspected fabricated research contaminating the cancer literature that clinicians, guideline-writers and patients depend on. · primary source

PickBits Daily Signal is a free working brief by Mark Pickering. Subscribe at pickbitsai.substack.com.