In major privacy win, Supreme Court rules geofence warrants are protected by privacy rights

TechCrunch - Mon, 06/29/2026 - 09:05
The Supreme Court's decision to limit geofence warrants is a win for privacy advocates, who called their use unconstitutional but sought an outright ban.
Categories: Nerd News

WhatsApp now lets you reserve usernames

TechCrunch - Mon, 06/29/2026 - 09:00
WhatsApp username can be between 3 to 35 characters length
Categories: Nerd News

Supreme Court rules states can count late-arriving mailed ballots, rejecting Trump-led challenge

Lookout Santa Cruz - Mon, 06/29/2026 - 08:51

The Supreme Court on Monday ruled that states can count ballots that arrive after Election Day, rejecting in a 5-4 decision a Republican-led attack on laws in more than half the states and the District of Columbia that permit mailed ballots to arrive and be counted some number of days after the election, provided they are postmarked by Election Day.

Sotomayor Warns Supreme Court Gave Trump the Powers of a King

The New Republic - Mon, 06/29/2026 - 08:47

Supreme Court Justice Sonia Sotomayor slammed her conservative colleagues on Monday for making President Donald Trump more powerful than a king.

The Supreme Court’s conservative majority scrapped Humphrey’s Executor, a high court precedent that established Congress could limit the president’s ability to fire executive officials of independent federal agencies, and allowed Trump to remove Rebecca Slaughter, a Democratic commissioner on the Federal Trade Commission.

In a scathing dissent, joined by Justices Ketanji Brown Jackson and Elena Kagan, Sotomayor warned that Trump had just become more powerful than the English monarch whose Parliament “often restricted the Crown’s ability to remove even high-level royal officers.”

“The text of the Constitution, along with its history, the longstanding practices of the political branches, and the precedents of this Court, make clear that Congress may limit the causes for which the heads of Commissions like the FTC can be removed by the President,” Sotomayor wrote. “In holding otherwise, the Court gives the President a power unknown even to the English Crown against which the Founders revolted, elevating him above his once-coequal branches by transforming a duty to take care that the laws be faithfully executed into a license to act in defiance of those very laws.”

Sotomayor argued that there was simply no way that the decision was Constitutional, because the country’s founding framers had “‘never intended’ to give the President ‘the complete set of powers’ that the English Crown held, let alone more.”

Categories: Political News

The British Paper That Americans Are Rushing to Read

The New Republic - Mon, 06/29/2026 - 08:45

You can watch this episode of Right Now With Perry Bacon above or by following this show on YouTube or Substack.

The news about the news has been terrible over the last year: CBS News taken over by Bari Weiss; Jeff Bezos pushing The Washington Post opinion section to the right; CNN, The New York Times, and other outlets often choosing to downplay the radicalism of President Trump so they can portray themselves as neutral and objective; numerous local and national outlets laying off reporters. But The Guardian US is the rare positive news media story. The London-based paper is vastly expanding its audience and staff size in the United States. It’s covering Trump honestly and directly. Steve Sachs, managing director of The Guardian US, explains the paper’s strategy in the latest edition of Right Now. The paper’s core journalism is global, independent, and free, and he argues all three are essential.

Categories: Political News

Americans’ Pride Drops to New Low as 250th Anniversary Approaches

The New Republic - Mon, 06/29/2026 - 08:04

America will reach a historic milestone at the end of this week as it celebrates its semiquincentennial, but the people that comprise this storied nation have reportedly never felt so detached from its identity.

An AP-NORC poll published Monday (but conducted in April) found that American pride has dropped significantly over the last decade. Negativity surrounding the government has seeped into public perception of the core components of America’s story, such as its history, its foreign influence and impact, and the way the country’s democracy works.

Pride in American democracy has dropped 14 percentage points since 2017, when it was measured at 42 percent. It is now at 28 percent.

The survey also found that a majority of Americans are disillusioned with the American dream: They are not confident in their current financial situations, do not believe they can find a “good job” in the current market, do not believe they have the ability to purchase new homes if they want, and do not believe they’ll have enough money to retire when the day comes.

A Gallup poll, also published Monday, found that just 33 percent of U.S. adults were “extremely proud” to be an American. That’s the lowest rating since the polling group began asking the question in 2001, when 55 percent of the nation’s adult population answered similarly.

Another 20 percent of U.S. adults said they were “very proud” to be an American, indicating that just over half of the country feels a deep sense of pride in their national identity.

The falloff is represented most extremely amongst self-identified Democrats, of which just 14 percent said they were “extremely proud” to be an American in 2026. Right behind them were registered independents, 28 percent of whom offered the same response. Independents, according to Gallup’s data, have experienced a steady decline in national pride since 2004.

Meanwhile, 70 percent of Republicans said they were “extremely proud” to be an American when polled this year—a sharp uptick from when they were asked the question between 2020 and 2024.

Categories: Political News

Rocket Lab continues buying spree by acquiring satellite company Iridium

TechCrunch - Mon, 06/29/2026 - 08:02
The all-stock deal values Iridium at $8 billion, and gives Rocket Lab even more firepower to compete against Amazon and SpaceX.
Categories: Nerd News

The legality and inhumanity of 2 new Supreme Court rulings

Daily Kos - Mon, 06/29/2026 - 08:00

Ahead of their summer break, the conservative-stacked Supreme Court has been issuing back-to-back decisions related to immigration. From the state of Temporary Protected Status for Haitians and Syrians to denying entry of green card holders, what the justices decided has a large impact on the state of the nation. While these cases have a chance at being contested by legislation to come out…

Source

Categories: Political News

Trump Rankled as Terrible Reviews for Lackluster State Fair Pour In

The New Republic - Mon, 06/29/2026 - 07:53

President Donald Trump seems to be catching on that people aren’t impressed by his disastrous Great American State Fair.

“Do you think people appreciate what a fantastic job we did in building and operating the Great American State Fair at the National Mall, packed with happy people, and everybody loving it?” Trump wrote in a post on Truth Social Monday morning.

“Ask yourself this simple question, ‘DO YOU THINK THAT OBUMA OR SLEEPY JOE BIDEN COULD HAVE DONE IT?’ THE ANSWER IS NO!”

Since Trump’s pet project opened on the National Mall last week, it has been beset by a slate of issues, including technical difficulties and disappointing weather delays. Over the weekend, The New Republic’s Malcolm Ferguson visited the festival in-person and confirmed it was a ghost town, marred by low energy and few attendees.

If you don’t believe us, check out posts from Trump’s allies:

White House press secretary Karoline Leavitt posted pictures from the president’s festival on Sunday. Barely anyone else seemed to be around.

A screenshot of a tweet from Karoline Leavitt reading "Fun day at the Great American State Fair!🎡 How cool is it that we are alive during this historic time and we get to experience America’s 250th birthday!? 💙❤️ Looking forward to making more lifelong memories over the course of this very special week!!" It includes two photos of a little boy in a blue shirt.

Actor Dean Cain, a vocal supporter of Trump, also posted a picture from the top of Trump’s towering Ferris wheel, revealing thin crowds below.

A screenshot of an X post from Dean Cain reading "I don’t like heights, but the view from atop the Ferris Wheel at the Great American State Fair is awesome!!! 🇺🇸" A photo is included of him sitting at a large height overlooking the National Mall with sparse crowds below. A tweet from Dean Cain reading "View from atop the Ferris Wheel at the Great American State Fair!! 🇺🇸" with a picture of the National Mall, with very few people present.

Oh, and the food really is that overpriced.

Categories: Political News

Supreme Court Gives Trump More Power to Fire Anyone He Wants

The New Republic - Mon, 06/29/2026 - 07:52

The Supreme Court ruled Monday to scrap a key protection and allow President Donald Trump to fire whoever he wants, whenever he wants.

In a 6–3 decision along ideological lines, the Supreme Court found that the “for cause” removal provision for the Federal Trade Commission violated the separation of powers, allowing Trump to fire Rebecca Slaughter, a Democratic commissioner on the FTC.

In the process, the high court voted to overturn Humphrey’s Executor v. United States, a 1935 Supreme Court case that established Congress’s ability to limit the president’s ability to fire executive officials of independent federal agencies.

“If anything more is left of Humphrey’s, the Court overrules it,” Chief Justice John Roberts wrote in the majority ruling.

The decision grants the president broad firing powers across independent federal agencies. However, in a separate 5–4 decision on Monday, the Supreme Court found that the Federal Reserve was a different kind of entity, and blocked the removal of Federal Reserve Governor Lisa Cook.

In a scathing dissent in the FTC case, Justice Sonia Sotomayor insisted that Congress could limit the reasons for removing the head of a federal agency.

“In holding otherwise, the Court gives the President a power unknown even to the English Crown against which the Founders revolted, elevating him above his once coequal branches by transforming a duty to take care that the laws be faithfully executed into a license to act in defiance of those very laws.”

The court previously issued a 6–3 ruling along ideological lines approving Trump’s emergency request to remove Slaughter from the FTC. Trump attempted to fire Slaughter in March, leading the commissioner to challenge the move, as presidents may only legally remove FTC commissioners for “inefficiency, neglect of duty, or malfeasance in office.” In July, a federal court blocked Trump’s “unlawful” attempt to remove Slaughter, citing the Humphrey decision, which was upheld by the U.S. Circuit Court of Appeals for the District of Columbia.

Categories: Political News

In a Rare Blow to Trump, the Supreme Court Just Saved Mail-In Voting—For Now

Mother Jones - Mon, 06/29/2026 - 07:49

In a surprise victory for voting rights, the Supreme Court on Monday upheld a Mississippi law allowing mail-in ballots to be counted up to five days after Election Day, as long as they had been postmarked by the day of the election.

The 5-4 decision by Justice Amy Coney Barrett, which was joined by Chief Justice John Roberts and the court’s three liberal justices, averts a major election disaster that would have injected chaos into the midterms. Fourteen states have mail-in ballot grace periods on the books, and 30 states accept ballots from overseas and military voters sent before or on Election Day but only received after. The New York Times found that during the 2024 election “at least 725,000 ballots were postmarked by Election Day and arrived within the legally accepted post-election window.” Changing mail-in ballot deadlines months before the general election could have disenfranchised hundreds of thousands of voters who could have been unaware of the stricter rules, or have their ballots thrown out because of postal delays, or because they live in remote, rural locations in states like Alaska.

Overruling the Fifth Circuit Court of Appeals, Barrett affirmed that such laws are constitutional. “In sum, the election-day statutes require the electorate’s choice to be made on election day,” she wrote. “That occurs so long as election day is the deadline for individuals to vote—as it is in Mississippi. But the election-day statutes do not set a deadline for ballot receipt, so they do not prevent Mississippi from counting ballots postmarked before election day yet received afterward.”

“But the election-day statutes do not set a deadline for ballot receipt, so they do not prevent Mississippi from counting ballots postmarked before election day yet received afterward.”

Justice Samuel Alito dissented, joined by Justices Clarence Thomas, Neil Gorsuch, and Brett Kavanaugh. “The acceptance of these late-arriving ballots effectively postpones the date on which the electorate’s choice is made, and federal law precludes that postponement,” Alito claimed, even though late-arriving ballots do nothing to change a voter’s choice on Election Day, since ballots are still required to be submitted by then.

President Trump has long spread conspiracies about mail voting and most recently attacked California’s protracted vote count as a “rigged election.” The administration’s latest plan to undercut mail voting would require states to hand over their voter rolls to the Department of Homeland Security for the Postal Service to deliver mail-in ballots—a form of extortion that has generated furious pushback from election officials. The head of the Postal Service told the Senate they were following Trump’s directive, claiming that he wanted to ensure “the right ballots are going to the right people.” (A federal judge last week blocked key parts of a Trump executive order that authorized such a scheme.)

Alito’s dissent amplifies Trump’s conspiracies. “Today’s decision leaves open opportunities for voter fraud that may further undermine Americans’ faith in the integrity of this country’s elections,” he wrote. “Diverse sources have recognized that mail-in ballots increase the potential for fraud.”

In fact, every major study has shown that mail-in voting is safe and secure, but the fact that four justices signed on to Trump’s crusade to get rid of mail-in ballots is highly disturbing and could embolden the president to attempt to take even more drastic steps to make it harder to vote.

Today’s ruling should also not distract from the damage the Roberts Court has already done to voting rights. Its decision in late April, effectively destroying the Voting Rights Act, gave Republicans just enough time to dismantle majority-Black seats held by Democrats in Tennessee, Louisiana, and Alabama. That was followed by a series of orders by the Republican-appointed justices on the shadow docket that expedited the GOP’s efforts to erase Black representation and give their party additional seats before the midterms.

Categories: Political News

Supreme Court Rules Trump Can’t Fire Dem Member of Fed Reserve—For Now

The New Republic - Mon, 06/29/2026 - 07:32

The Supreme Court has blocked President Trump from firing Federal Reserve Governor Lisa Cook, preserving the central bank’s independence for now.

In a 5-4 decision Thursday split across ideological lines, the Supreme Court blocked Trump’s attempt to become the first president to remove a Federal Reserve official since it was created in 1913.

Conservative Chief Justice John Roberts and fellow conservative Justice Brett Kavanaugh joined the court’s three liberal justices to rein in Trump.

Last August, Trump declared that he was booting Cook—the first Black woman on the Federal Reserve board—over claims she committed mortgage fraud with two primary residencies. Cook refused to step down, and sued, stating that “President Trump purported to fire me ‘for cause’ when no cause exists under the law, and he has no authority to do so.”

A lower court ruled that Cook could not be dismissed while her case proceeded. The Department of Justice then requested that the Supreme Court stay that ruling, so that Cook could be removed from her position. The Supreme Court refused.

“No matter the precise definition of cause, or the scope of our review of any such determination, the President failed to afford Cook the procedural protections to which she was entitled by statute,” wrote Roberts, who wrote the majority’s ruling.

The case will now return to a lower court, where Cook will fight to save her job. Cook was appointed by former President Joe Biden, and her term was set to expire in 2038.

In a separate decision Monday, the Supreme Court gave the president more power over independent agencies, ruling that Trump had the authority to fire Rebecca Slaughter. The ruling shifted quite a lot of power from Congress to the president, and has ushered in one of the largest changes to the federal government in decades.

This story has been updated.

Categories: Political News

Microsoft to assist European Commission in defense of EU-US data-sharing agreement

The Register - Mon, 06/29/2026 - 07:29
Microsoft says it is trying to help the European Commission see off a legal threat to the EU-US Data Privacy Framework agreement - relied on by organizations to legally move data between the bloc and the US. In a weekend blog post, the software biz confirmed the Court of Justice of the European Union had granted its application to formally intervene in a case challenging the framework, which has supported data between the two economic super-powers since 2023. Microsoft thinks the case before the court will determine whether its enterprise customers — of which there are many — can continue under the existing pact. “Companies across the globe rely on data flows to manage their people, produce their goods and services, and distribute products to their customers. We understand that data flows trigger questions about differences in legal traditions.” In Redmond's blog post, Jon Palmer, Microsoft corporate veep and chief legal officer, and Cari Benn, chief privacy officer, say the Court found Microsoft has a direct and existing interest in the result, allowing it to intervene in the case. “As an intervener, we can now file legal briefs in support of the European Commission, participate in oral hearings, and share our perspective on the importance of upholding a framework that directly benefits the European economy,” the pair write. The case before the court is an appeal against an earlier ruling which struck down a challenge to the EU-US Data Privacy Framework. In September last year, the EU General Court’s judgment confirmed the data sharing agreements' validity, ruling against the challenge from French parliamentarian Philippe Latombe. He brought the case by arguing the Data Protection Review Court (DPRC) — the US body set up to hear issues related to the Framework — lacked independence. A presidential executive order could disregard the DPRC, he argued. But the General Court disagreed. "It is apparent from the file that the appointment of judges to the DPRC and the DPRC's functioning are accompanied by several safeguards and conditions to ensure the independence of its members," the Court said at the time. Max Schrems, the lawyer and campaigner behind two successful challenges to EU data sharing rules, Safe Harbor (2015) and Privacy Shield (2020), pointed out that Latombe had chosen a targeted and narrow challenge to the current deal. Another challenge based on a broader set of arguments might prove successful, he said. “This was a rather narrow challenge. We are convinced that a broader review of US law – especially the use of Executive Orders by the Trump administration – should yield a different result. We are reviewing our options to bring such a challenge. While the Commission may have gained another year, we still lack any legal certainty for users and businesses,” Schrems said in a blog post. Latombe announced plans to appeal in October last year, although the basis for the appeal is still to be made public. According to law firm WilmerHale, the ECJ has historically been more skeptical than the General Court in assessing US surveillance practices and the adequacy of redress mechanisms. Its prior decisions in the so-called Schrems I and II rulings invalidated frameworks that had also been endorsed by the European Commission, and Latombe’s appeal puts another framework before the European Court of Justice for consideration. Clearly, Microsoft feels the appeal’s chances of success are sufficient for it to step in. ®

Supreme Court Tells Trump to Give It Up Already on E. Jean Carroll

The New Republic - Mon, 06/29/2026 - 07:22

The Supreme Court on Monday rejected President Donald Trump’s appeal of the E. Jean Carroll verdict, in which he was found guilty of sexually abusing and then defaming Carroll.

This means Trump will still be required to pay Carroll $5 million.

Carroll, a former writer, accused Trump of sexually assaulting her in a Bergdorf Goodman dressing room in 1996. When she spoke out publicly against him, he posted on social media that the case was “a complete con job” and a “Hoax and a lie.” In 2022, she sued him for both sexual abuse and defamation, seeking damages, and the jury agreed with Carroll that Trump was liable.

Trump’s lawyers appealed the case, arguing that the jury heard “highly inflammatory” evidence—including testimony from two other women who claimed Trump assaulted them, and the infamous Access Hollywood tape.

The Supreme Court justices did not provide any explanation for why they rejected Trump’s appeal. But, they may consider another similar case. A separate jury found Trump liable for defaming Carroll in 2024, and he was ordered to pay the writer $83.3 million—Carroll’s lawyers argued that a significant settlement was the only way to get Trump to stop attacking her. Trump’s lawyers have said they plan on appealing that verdict to the Supreme Court as well.

However, that case is solely focused on defamation. Carroll’s claims that Trump sexually abused her in the ’90s have been affirmed by a jury, and Trump has now run out of ways to contest them.

This story has been updated.

Categories: Political News

Supreme Court Kills Republican Effort to Demolish Mail-In Voting

The New Republic - Mon, 06/29/2026 - 07:20

The Supreme Court has demolished Republicans’ efforts to delegitimize mail-in ballots, upholding a Mississippi law that allows a grace period to count ballots received after Election Day.

In a 5-4 decision Monday split across ideological lines, the court ruled that ballots are valid up to five days after Election Day, so long as they were postmarked before it. Justice Amy Comey Barrett and Chief Justice Roberts were the two conservatives who sided with the liberal justices, and Barrett authored the majority opinion.

Eighteen states and territories, including Mississippi, currently allow for mail-in ballots to be received after Election Day. That includes big Democratic states like California, Illinois, and New York. The ruling also protects states and territories that allow a grace period for ballots returning from overseas, such as for military service members.

“The Constitution’s Elections Clause empowers state legislatures to ‘prescrib[e]’ the ‘Times, Places and Manner of holding’ congressional elections. Congress may ‘override’ most of these choices,” Barrett wrote for the majority. “By ‘default,’ however, ‘responsibility for the mechanics of congressional elections’ belongs to States. As Alexander Hamilton put it, the Constitution lodges power over congressional elections in state legislatures ‘primarily’ and in Congress ‘ultimately.’”

Mail-in voting is a very basic, safe tactic that Trump himself has even used, despite crusading against it as fraudulent. By upholding it, the court has protected voting rights for thousands of Americans voting at home and abroad.

This story has been updated.

Categories: Political News

Robot hand company settles Tesla trade secret suit and announces $11M raise

TechCrunch - Mon, 06/29/2026 - 07:00
The startup, Proception, is taking a unique approach to collecting training data to tackle one of the hardest problems in robotics: hands.
Categories: Nerd News

Todd Blanche’s strategy of ignoring the courts isn’t working out so well

Daily Kos - Mon, 06/29/2026 - 07:00

Acting Attorney General Todd Blanche seems to be getting a bit high on his own supply, deciding that those pesky lower courts can’t tell him what to do. Bold strategy, Todd. Let’s see if it pays off. Well, it’s not paying off for him when it comes to the Epstein files, that is for sure. Earlier this year, independent journalist Katie Phang sued Blanche over his complete refusal to follow the…

Source

Categories: Political News

AI may be good at finding security vulnerabilities, but it can't beat human stupidity

The Register - Mon, 06/29/2026 - 06:45
KETTLE AI commands all the headlines nowadays, but the biggest security story of the week is all about human laziness and poor password habits – just like the good old days. This week on the Kettle, host Brandon Vigliarolo is joined by US editor Avram Piltch and security editor Jessica Lyons to talk about the Klue breach, which was blamed on a "compromised legacy credential" that ought to have been deleted a while ago. The hole allowed cybercriminals to access the SalesForce environments of hundreds of companies, say researchers. The incident has caused trouble for security firm Huntress, which admitted to the breach early on, and the situation over there wasn't caused by AI either. That said, AI is playing a role in what's being described as "the summer from hell" by one security professional, but while top-tier AI models are spotting troublesome vulnerabilities, the amount of damage they've managed to cause pales in comparison to what one lazy sysadmin can cause by poorly managing passwords. You can listen to the latest episode of The Kettle by clicking on the player above, as well as on Spotify, Apple Music, or YouTube, or read the transcript of the latest episode below. It's been lightly edited for clarity. Brandon (00:01) Welcome to the latest episode of The Register's Kettle Podcast. I'm your host, Brandon Vigliarolo, and this week we have some rather interesting security stories to talk about concerning yet another Salesforce data breach affecting a whole bunch of companies, the new extortion gang behind them, and the trouble the whole thing has spelled for one of the first companies to point the whole thing out. This week I'm joined by US editor Avram Pilch and security editor Jessica Lyons to talk about this whole mess and more. Welcome to you both. Jessica Lyons (00:29) Good to be here. Avram Piltch (00:30) Hey. Brandon (00:30) Jess, let's start with that Salesforce supply chain attack that you wrote about this week. I understand there was a market intelligence connector of some sort that was behind the incident, right? Jessica Lyons (00:41) Right. So there's this company named Klue, and they provide market intelligence to more than 250,000 users worldwide. And they integrate with Salesforce. And so apparently what happened, on around June 11th, somebody used compromised legacy credentials linked to the Salesforce integration, and then by that they were able to obtain OAuth tokens and then were able to access customers' Salesforce data, Klue customers' Salesforce data from that. Brandon (01:21) Okay, was it data that Klue had on their customers in their Salesforce environment, or they pivoted to the customers' environments as well? Jessica Lyons (01:29) It was through the integration with the Salesforce databases. Brandon (01:34) That's not great. A lot of companies were exposed, and a lot of them in your article you mentioned were security companies. Is that right? Jessica Lyons (01:42) There were a ton of security ones, and then LastPass, this huge password manager. We don't know how many; Klue didn't say. Huntress, which is one of the security companies who was involved in this and who came out on the forefront and said, "Yeah, we were one of the compromised organizations," said it was hundreds. And out of 250,000 users, it could be pretty comprehensive. Avram Piltch (02:12) Do you think this makes Huntress look good? Jessica Lyons (02:17) I think it was admirable that they came out, especially as a security company, and said "we were one of the companies who were victimized." I think that's how any company should respond if they're among the companies affected. Especially if you're a security firm, you have an obligation to be transparent and tell your customers what happened. Brandon (02:43) Legally, in the United States at least, if you've got a breach, you've got to report these things to the government. There's all kinds of cybersecurity reporting standards in place. They are contradictory and overlapping sometimes, but they're there. What kind of data was exposed, Jess? Jessica Lyons (02:57) It was basically CRM data. It wasn't any of the companies' internal IP or anything like that. It was CRM data for pretty much every single company involved across the board. The cybercrime group behind this hack did leak the Huntress data a few days later. And we've heard that they're actually deleting the stolen data from LastPass. That's what LastPass is saying. We don't know if this data is actually not going to exist anymore or if they're just handing it off for other attacks or to other organizations. But it involves CRM data. Brandon (03:49) CRM data then, customer data, from the affected companies too. I'm assuming no financial information was exposed? Jessica Lyons (03:52) No, no financial information. Avram Piltch (04:02) So relatively not that bad for Huntress's reputation when you think about it. Jessica Lyons (04:08) They specifically said it's our business contacts, price quotes, and other sales related data and messaging. They said no threat data, passwords, payment card information, or engineering data related to Huntress Agent or telemetry are affected. That's pretty standard across the board. The companies who did get more specific in their disclosures about what was taken basically lost business data, leads, and contacts. Brandon (04:46) For LastPass, was it just CRM records or were consumers of their password managers affected too? Jessica Lyons (04:55) LastPass customers' data was affected. It was some sale-related data, but also the intruders took customers' names, phone numbers, email addresses, and physical addresses, plus some case support data and then also sales-related data. Brandon (05:13) Right. If you're a LastPass customer, you might want to go in and reset that Master Vault password now. Jessica Lyons (05:18) Big yes, yes, definitely. Brandon (05:22) This didn't involve Shiny Hunters, who've been the de facto kings of Salesforce attacks recently. They weren't involved, right? Jessica Lyons (05:29) Right. No, they weren't involved in that. I think it was what everybody assumed is that you've got Salesforce and you've got OAuth tokens and that just screams Shiny Hunters. They weren't involved. It was a new group called Icarus. They're a new data theft and extortion crew, and they're modeled in the same mold here as Shiny Hunters and Scattered Spider. I was wondering though, is this just a front? According to Shiny Hunters, no, they were not involved. They told me that they were kind of bummed (laughs) that this other group was able to do this. And if it had been them, they would have definitely publicized the fact that it was Shiny Hunters who did this. Brandon (06:15) Yeah, they're not exactly publicity shy. So … I I love the fact that we've got an inside line to them too, that you can be like, "Hey, was this you guys in any way?" And they're like, "No, no, we wish it was." Jessica Lyons (06:26) I think the actual response was, "We wish." Brandon (06:29) Not much is known about Icarus. I think you mentioned a couple of different countries that their IPs might have been linked to, but those very well could have been Tor or VPN exit nodes. We don't even know where they're located. Jessica Lyons (06:43) No, we don't know much about them. Their leak site has been active since late April. We've seen different IP addresses in Europe, but we don't know much about this group at all. Brandon (06:53) These groups change and move so rapidly. Who knows who they are? Are they ransoming this data? Do we know? Jessica Lyons (07:08) Yes, they were ransoming and then leaking some of the data outright. Brandon (07:20) Okay, that's standard MO for a lot of these groups. Speaking of Huntress's early identification of this, that opened up a bit of a Pandora's box for them. Because they had a jilted ex-employee who wasn't thrilled with the response, which you also wrote about. What happened there? Jessica Lyons (07:22) Right. So after Huntress came out and and they said Huntress believes in radical transparency about security incidents, including when it affects our company. That was about the Klue breach. They said that in their blog. A former security operations analyst posted their response on his LinkedIn page along with a Pinocchio GIF. And that just kind of started this whole mess. He says that he was threatened by the company with legal action. He made it very clear this has nothing to do with the Klue incident. He says this stems from an earlier incident that he found out about in December, and because of that incident, he resigned from the company. What he's alleging, and again this is all allegations at this point, is that another Huntress employee who still works for the company passed communications from US law enforcement to a cyber criminal. Now this alleged cyber criminal, according to the ex-employee, is actively targeting his family and him. He says that he can no longer work at Huntress because of this. He says in the next few weeks he's going to provide more proof, including communications and phone calls about what happened here. He says also that this alleged insider was caught by the FBI. I don't know if that means arrested, I don't know if that means questioned, but still continues to work at Huntress. Brandon (09:30) I'm assuming there's no DoJ notice of anything that ties to an arrest of someone who could be involved. Jessica Lyons (09:37) Not at Huntress. No. Not at Huntress. Brandon (09:40) What has Huntress had to say about this whole thing? Jessica Lyons (09:42) The CEO responded to me and also responded on a Reddit post. He acknowledges the concerns raised by this former employee. He said that because of our work as researchers, sometimes we need to communicate with possible cyber criminals to gather intel that supports our partners and customers. He says that he appreciates the former employee's concerns and will continue to investigate the instance. He said a little bit more directly on Reddit that he doesn't understand and he firmly disagrees with these accusations and the insider narrative. Another thing that the former employee also brought up that Huntress is prioritizing an IPO over the safety of its partners, customers, and team members. He said that "sure AF" isn't the case. He's made it very clear that the company disagrees with all of these accusations and they're continuing to work with law enforcement. He said some of this involves legal proceedings, so they can't be completely public about everything. It sounds like a continuing story that we're going to learn more about in the weeks ahead. Brandon (11:15) If this ex-employee has documents to prove his allegations, that's pretty serious. Obviously, yes, you do have to interact with some of the people that you're defending against at a security firm, but passing law enforcement communications to them – I don't see a very good reason for that. Jessica Lyons (11:22) Right. Avram Piltch (11:36) Could this be a misunderstanding about what the employee was doing? Jessica Lyons (11:44) It potentially could, but if he has these communications between law enforcement and the Huntress employee, I don't know how that could be a misunderstanding. It's one thing to talk with cyber criminals, but it's another thing to be passing them information about legal proceedings.... Brandon (12:09) Yeah, or potential operations. We'll see what comes of that. It's going to be interesting to follow that thread. These two stories aside, it seems like we've got a really busy cybersecurity summer so far, even though it is usually a lull. Jess, you were talking about that with one of your sources, right? Jessica Lyons (12:13) Right. Normally everything slows down in the summer, and I was talking to a source and they said they're already calling it the "summer of hell." For the security folks out there, that's pretty accurate. I think a lot of that has to do with AI, to be perfectly honest. Brandon (12:48) Right. Squidbleed, which you wrote about recently, was a Mythos-discovered vulnerability discovered that was old and potentially serious. Jessica Lyons (12:51) Definitely. It's been around since 1997. It was discovered by Mythos, but it was also discovered even before then by IL Security, a European startup. They have their own model that they said found this before Mythos did. You've got this 29-year-old vulnerability, it's existed since 1997. It's in Squid, which is an open source web proxy server. It's a parsing bug and it essentially allows users to access the proxy's active memory. There are a couple key points: it's only unencrypted traffic, so it's cleartext HTTP, and it also requires that Squid has the file transfer protocol, FTP server gateway features turned on. So you have to be using this older vintage technology and protocols. FTP is pretty outdated at this point. Brandon (14:07) It's a vulnerability, but maybe not a serious one. Jessica Lyons (14:11) It's serious if these two conditions are met, because then it's going to expose your password, session tokens, and API keys. Brandon (14:15) Hopefully there are not too many environments where this is the case, but we know from writing about stories like this that every time you say this is a very rare case on old software, you can easily find examples. Avram Piltch (14:33) If you're still using FTP and HTTP on your servers, then you're letting yourself in for a big security problem. That probably isn't your only problem. Brandon (14:39) Yeah, you don't want to say asking for it, but yeah. AI might be discovering these and other problems. We've seen multiple open source projects shut down bug reports because they're getting flooded with AI-discovered issues, some of which are completely legitimate. It feels like this is the summer of AI and cybersecurity convergence. The Trump administration is now haranguing OpenAI, just as much as they've been putting pressure on Anthropic not to go public with models that could be a threat. It feels like a big moment for cybersecurity, and a lot of it's being driven by AI. What do you guys think about the current moment of this pairing? Jessica Lyons (15:23) It's a perfect storm because you have these models that are really good at finding vulnerabilities and developing exploits. That's leading to a bunch of internally, with security companies finding their own bugs and pushing out patches, so then all the sysadmins need to work extra hard. Plus open source, which is a huge issue here, you have all of these bug hunters looking for and finding all kinds of vulnerabilities on open source projects. They push those to maintainers who a lot of times are volunteers themselves and they're not getting paid. There's maybe one of them for this huge project. They have this huge backlog of AI-enabled threat reports that they need to deal with. It's just coming at people from all ends here and yeah, a lot of that's because of the AI models. Brandon (16:35) Is NIST still backed up with the national vulnerability database? Last I heard they were some months behind. Not only that, but we've got a lot of big threats out there that might not be being made public because they're buried too. It's quite the mess. So before we wrap up, I did wanna touch on, like you mentioned, Jess, and and we've seen this in a number of stories that Avram's written recently for the Pwned column. AI is creating a headache for a lot of people, but there's still a group of people that are stuck dealing with this and it's sysadmins, right? It's the security professional, it's the sysadmins, NShuman human problems can still be kind of the root of this. Avram, you wrote a number of stories in your Pwn column that it was it was like all these problems, these security problems come back to bad password hygiene, administrator laziness. I mean, what are some of the things you've kind of seen? Avram Piltch (17:35) Hubris. There was a CEO that wanted to make sure that he could get in and change anybody in the company's email. We could talk about whether that's a good policy in the first place, but his method of doing it was to have an Excel file on his desktop with all of the usernames and passwords of all the employees so that if he sent out an email he shouldn't have, he could go into their inboxes and delete it. But conversely that was a wonderful target for people outside the company to find all the names and passwords they needed, even though there's software out there that will allow an admin to go into an inbox anyway. This was completely unnecessary, but things like that are constantly happening. We had another incident where somebody hadn't deleted a former employee's username and password, perhaps their password was in a breach somewhere or somebody guessed it. But Greg from auditing hadn't worked there in like ten years, but somebody used his credentials to break into a city's water system and start trying to interfere with things having to do with the water supply. The best AI in the world isn't needed to find these problems and couldn't be used to prevent them. The human element is still the biggest problem in security. Maybe when I have my agent talk to your agent, they will be much better behaved than when people get involved. But coming up in a future Pwned column, I talked to a red teamer who said he's basically able to break into almost any facility by acting like he belongs there. Brandon (19:51) That's a classic trick. It's the same thing I've said for a long time about security: you've got new tricks that come up, you've got new things like AI, but there's nothing new under the sun at the end of the day. The best way to gain access to a system isn't to swordfish your way in a la Huge Jackman, it's a con. It's lying, putting on a reflective vest, and having a clipboard. It's relying on password breaches and people being bad about their password hygiene. That's what happened with the Clue issue: an old password that was in a breach somewhere that someone used to get into the system. Nothing new under the sun. Jessica Lyons (20:26) Yeah, we see that all the time. Brandon (20:34) And it's probably going to keep being that way, and I bet we are probably going to be talking about it on the Kettle for months and years to come. Invariably, until AI fully takes over the computer world and we're all just sitting in our WALL-E couches being perpetually entertained by all these sentient machines. But until then, we will be here to talk about these things. Thanks for joining me, guys, and we will see you all again soon. ®

I Went to Trump’s Great American State Fair So You Don’t Have To

The New Republic - Mon, 06/29/2026 - 06:23

The opening weekend of the Great American State Fair in Washington, D.C., was, to put it simply, miserable. It was extremely muggy, with rain pouring down seemingly every hour. A child rolled around in the grass, crying and screaming, “I. WANT. TO. GO. HOME!!!” Creed’s “Higher” blared over the loudspeakers, and a sparse crowd milled about the various exhibitions. The bare-bones setup—flimsy, fake two-dimensional columns that looked like something Wile E. Coyote would run into while chasing the Road Runner—left much to be desired, as America’s 250th anniversary was celebrated with kitsch and ennui rather than grandeur and appreciation. 

More than anything, the event lacked energy—and people. There wasn’t any line or wait to get in. The vibe was more conference-like than celebratory, and the state exhibits varied wildly in effort and presentation. Utah and Guam had particularly involved setups, while others like South Carolina felt totally sterile. Connecticut and Maine shared a space that looked like the waiting room of a pediatrician’s office, while Hawaii and Alaska didn’t have anyone attending to visitors. There were $25 pretzels, an AI George Washington, an interactive “Loyalist or Patriot?” test, and a whiteboard wall full of messages from attendees, one of which read “a felon and predator resides at 1600 Pennsylvania Ave!!”

“It feels more like a campaign event than a fair,” said M., a D.C resident who didn’t want to be named and was visiting with his wife and son. “There was potential here. I think that the state exhibits they had, some of them were very well done, others didn’t really have much effort put into them.… My four-year-old enjoyed the carousel, but I think that if this was done a little bit more thoughtfully it could’ve been really fun. I’ve been going to state fairs for most of my life, I’m from Minnesota. And so seeing what a really thought-out, well-done state fair looks like—it’s an incredible experience.”   

Bit of a flimsy set up at the Great American State Fair pic.twitter.com/4H1YauQgp4

— Malcolm Ferguson (@malc_ferg) June 29, 2026

“Kind of disappointing they don’t have anywhere to sit, especially if you get food—you’re just standing,” said Virginia resident Anita, as we were being ushered out of the “rain-or-shine” event Sunday afternoon due to the weather. “Right now, we’re being postponed because of lightning. Where are we all supposed to go? We drove two hours, we’re not just gonna go jump in the car. It’s kinda sad there’s not a backup plan.”  

“I think if [Trump] wanted to make a bigger splash, he should’ve gotten Disney, or somebody who knows how to do this,” said Haven, another D.C. resident attending the fair. 

While many states and artists opted out of the event, corporations did not. The presence of companies like Northrop Grumman, United Health Group, Chime, and others was very apparent.

“I understand that people are advertising here, that there’s sponsors,” said a visitor named Ryan. “Coming in and seeing SpaceX, or like Micron was kind of like, ‘Oh, I wasn’t expecting that.’ But it’s America, so maybe I should’ve.” 

When asked about defining American moments of their lifetimes, attendees’ answers were about as bleak as the scene, as almost all the answers included 9/11, Covid-19, and pretty much every war the U.S has been in. “The Revolutionary War, World War II, the Vietnam War, the Iraq War,” said Haven. “It’s a shame you think of war first.” 

Of course, not everyone was underwhelmed by the fair.

“I know how much [President Trump] loves the country, so I’m not the least bit surprised that they’re going all out,” said Nicki Hannigan, in her seventies, who came all the way from Grand Rapids, Michigan, with her husband, Jack.

“There’s not a weed in this grass!” Jack said. “I don’t know if anybody’s noticed that, but that takes some doing. If the administration can do that well, they can do a lotta stuff well.” 


A mother and her two kids stand in an empty Connecticut both. A man observes the empty Maine booth.

“Well” is relative, as the event has been shrouded in tumult as Trump took over. What was originally supposed to be a weeks-long blockbuster festival to celebrate the nation turned into a politically charged event, where even B- and C-list artists like Flo Rida, Milli Vanilli, Vanilla Ice, and the Commodores dropped out. Soon, nearly a dozen states did too, as it became more and more obvious that Trump was using this event for partisan purposes. As everyone bailed, Trump petulantly declared the fair would instead be kicked off with a rally that he would headline—but even that didn’t get much of a turnout. That timeline of chaos still felt prescient, as the haphazard, thrown-together nature of the event stood out more than anything. And that distracted from what people were actually there for: to celebrate the anniversary of their country.

Some attendees were able to acknowledge Trump’s heavy-handed involvement in the 250th while trying to remain appreciative of what the event represented. 

“I don’t really take [Trump] into consideration. He’s gonna be gone in three years, dead in ten,” said Scott. “He’s not gonna take away my joy of this event. He’s the president, but he’s not God—even though he thinks he is. I wasn’t gonna come to this, but then I thought, ‘Ya know, I’m not gonna let him take it away.’” 

I wish I shared that optimism. 

Categories: Political News

Pocket raises $11M in bet on rising demand for AI note-taking devices

TechCrunch - Mon, 06/29/2026 - 06:16
Pocket sells a $129, credit card-shaped puck, which sticks to the back of your phone, and promises unlimited recordings, transcriptions and to-do items.
Categories: Nerd News

Pages