> daily_signal(2026_08_03)
A city switched its surveillance vendor before the public was told, a cheap TV stick shipped a backdoor, and the volunteers and AI meant to keep software and science honest ran thin.
PickBits Daily Signal · Monday, August 3, 2026
// tl;dr
- Syracuse switched on Axon license plate readers and logged 697,104 plate reads before anyone was told the system was live. Assemblymember Pam Hunter calls it "a constant, warrantless surveillance system"; Bruce Schneier's point is that trading Flock for Axon changes nothing, because Axon carries deeper federal ties than the company it replaced.
- curl stopped accepting security bug reports for a full month, July into August, a "summer of bliss" its maintainer took because triaging AI-generated fake reports had become unsustainable. Paid support customers kept full service; everyone else waited. It follows curl killing the bug bounty it had run since 2019 in January after twenty reports produced zero real bugs. The freeze runs through today.
- Cheap Android TV sticks, including the H96 still on Amazon, ship with a backdoor built into the firmware at the factory. Bitsight traced about 38,000 still-active boxes to a Chinese firm; the malware spoofs each device as a name-brand phone to run ad fraud and rents your home internet out as a proxy, netting an estimated $50,000 a day from one old domain.
- A BMJ machine-learning screen read 2.6 million cancer papers and flagged more than 250,000, about one in ten, as carrying paper-mill fingerprints. The tool, built by a Queensland University team, was right about 91% of the time; the authors are explicit that a flag is a warning signal, not a verdict, and every paper still needs human review.
Start in Syracuse, where the surveillance dragnet we began tracking in June, when we covered the license-plate camera networks quietly blanketing whole towns, just changed hands to Axon before the public was told. On a $30 shelf at Amazon, the streaming stick we flagged back in June as a fraud relay node is still shipping with its backdoor pre-installed. Both work the same way: the tracking gets cheaper and quieter, and it lands on you whether you agreed to it or not. The volunteers and reviewers who normally catch this kind of thing are stretched thin right now. A handful of curl volunteers closed their security inbox for a month because AI "slop" made triage impossible, and the pipeline meant to keep cancer research honest turned out to be so overrun with paper-mill fakes that it took a machine to even measure the damage. My read on the day is that the surveillance keeps getting cheaper while the people paid to push back keep getting fewer, and the one genuinely good thing here is that, for once, a machine did some of the pushing back itself.
The cameras went up in Syracuse before anyone was told, and the only thing guarding your software and your medicine this week was a few tired volunteers and one useful algorithm.
1. Syracuse switched on a warrantless license plate dragnet, and the only thing that changed was the logo on the camera.
Swapping the surveillance vendor is not the reform it gets sold as.
Your car's movements are being logged by a company you never chose, and the cameras were reading plates before the public was told the system was on. On July 28, the Syracuse Police Department switched on the first 14 of 26 new Axon automatic license plate readers, and the department's own transparency portal had already recorded 697,104 plate reads before public activation. Assemblymember Pam Hunter calls it "a constant, warrantless surveillance system," and says "it's the same tech, and it serves the same purpose" as the Flock Safety cameras it replaces. The NYCLU and the Melt Coalition are on record against it.
Bruce Schneier wrote last week that switching from Flock to Axon is like a gambling addict swapping one betting app for another: Axon's cameras still hoover up personal details far beyond a plate number, and Axon carries deeper ties to the federal government than Flock does. So a town that "switched vendors" has not reduced the dragnet by an inch. It is the same warrantless record of everyone who drives, now held by the firm with deeper federal ties than the one it replaced.
centralcurrent.org: Axon license plate readers go live in Syracuse; state legislator calls it a "constant, warrantless surveillance system" (July 2026)
schneier.com: Axon is another license plate surveillance company (July 28, 2026)
govtech.com: Axon to debut license plate reading after a year of input (2026)
2. The internet's most-used transfer tool closed its security inbox for a month, because AI slop burned out the volunteers.
The people guarding the code inside your product just ran out of patience for AI-written fakes.
The free library holding your product together just closed its security inbox for a month, and the reason should change how your whole team consumes open source. curl, the ubiquitous data-transfer tool whose libcurl ships inside countless apps, phones, cars, and servers, accepted zero vulnerability reports from July 1 through today, a "summer of bliss" its maintainer Daniel Stenberg took because triaging AI-generated "slop" reports had become unsustainable for a handful of volunteers. It follows Stenberg shutting curl's bug bounty, which it had run since 2019, in January 2026, after the year's first twenty submissions produced a 0% confirmed-vulnerability rate: every one an LLM-written report that looked like a real CVE but cited code that never existed or bugs long since fixed.
An AI can now spit out a report that looks exactly like a real vulnerability in a few seconds, and a human still has to read every single one to find out it is fake. Twenty of them in a row were fake. The companies paying for a support contract kept full service through the freeze. Everyone else waited a month for the free thing they had been treating as infinite.
lwn.net: curl's "summer of bliss" and the pause on vulnerability reports (June 15, 2026)
itpro.com: curl scraps its open-source bug bounty after a wave of AI slop (January 22, 2026)
3. That $30 Android TV stick on Amazon ships with a factory backdoor that rents out your home internet.
You do not get hacked later; the device arrives already enrolled in someone else's crime operation.
The $30 streaming stick you plugged into your TV may be renting your home internet to criminals, and it was doing it before you opened the box. In a July 30 report, Brian Krebs detailed how cheap Android TV sticks, including the H96 model still sold on Amazon, arrive with a backdoor built into the firmware at the factory, no hacking required. Bitsight researcher Pedro Fale traced roughly 38,000 still-active boxes to Zhejiang Fengwo IoT Technology Ltd, and found the malware disguises each device as a name-brand phone to run click fraud on AI-generated sites, then rents the buyer's home internet out as a residential proxy, flipping to ad-fraud mode when the TV is off. One old domain was pulling in an estimated $50,000 a day.
The reason to treat this as more than a cheap-gadget warning is where the compromise lives: at the supply chain, not in some download you clicked. The FBI warned in 2025 that exactly these devices turn a home network into criminal infrastructure, and the boxes keep selling because they show up next to legitimate gear on mainstream retailers, so people reasonably assume they are safe. They are not. A device that arrives pre-enrolled in a botnet is a different problem from one you can avoid with good habits, because there was no moment you could have done anything differently.
krebsonsecurity.com: Read this before you buy that TV streaming stick (July 30, 2026)
foxnews.com: How a cheap streaming box can hijack your home internet (July 2026)
4. An AI "spam filter" for science screened 2.6 million cancer papers and flagged more than 250,000 as likely fakes.
The rot in the cancer literature was invisible at scale; a free tool finally makes it measurable.
If your care, or the care of someone you love, rests on cancer research, some of the studies underneath it are fabricated, and an AI just measured how many. A team at Queensland University of Technology, led by Professor Adrian Barnett and publishing in The BMJ, built what Barnett calls "a scientific spam filter": a machine-learning model that read 2.6 million cancer research papers from 1999 to 2024 and flagged more than 250,000 of them, about one in ten, as carrying the same linguistic fingerprints as known paper-mill and retracted fraudulent work. The tool matched suspicious papers about 91% of the time against verified examples, and showed the share of flagged papers climbing from roughly 1% in the early 2000s to a peak above 16% in 2022, worst in gastric, liver, bone, and lung cancer.
The good news here comes with a caveat the authors put right in front, and it is the part that keeps this honest. A flag is a warning signal, not a verdict; every paper the screen catches still needs a human expert to confirm actual misconduct. What the tool changes is not the truth of any single paper but the scale of the problem, which until now nobody could see. Paper mills mass-produce fabricated studies, and the peer-review pipeline that is supposed to catch them runs on unpaid, exhausted reviewers. Now there is at least a way to triage which studies to check first.
sciencedaily.com: AI "spam filter" for science flags scale of paper-mill fraud in cancer research (July 16, 2026)
the-scientist.com: Nearly ten percent of cancer papers flagged as potentially fake (July 2026)
ecancer.org: New tool exposes scale of fake research flooding cancer science (July 2026)
» What to watch this week
- Whether any Syracuse body, or a resident with standing, gets the Axon data-retention and data-sharing policy onto the public record before the last 12 cameras go up. The cameras are already live without one; the lever left is the procurement paperwork, and the question is whether those retention and query-access rules survive being read out loud.
- Whether curl's inbox stays open once the freeze lifts, and whether any company in its dependency chain responds by funding a support contract instead of just filing more bugs. The freeze proved paid customers kept service; the tell is whether the firms shipping libcurl treat that as a warning or ignore it until the next shutdown.
- Whether Amazon and other mainstream retailers pull the H96 and its clones, and whether the FBI or FTC moves past a warning to an actual recall or import block. A PSA is not enforcement; the boxes are still on the shelf, and the residential-proxy market keeps paying for them.
- Whether a journal or guideline body actually deploys the BMJ screen as routine triage, and publishes what it does with the flags. A flag is a warning signal, not a verdict, so the thing to watch is whether anyone builds the human-review step the tool is designed to feed, or just cites the headline number.
Tomorrow's signal lands here.