ZeroHour

Search: “2026-elections”

18 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Supreme Court denies Trump request to allow USPS mail ballot changes

Supreme Court denied the Trump administration's emergency request to implement USPS mail ballot changes before the 2026 midterms, calling it arbitrary and capricious.

The U.S. Supreme Court rejected 7-2 the Trump administration's petition to change how the U.S. Postal Service handles mail-in ballots for the 2026 midterm elections. Justice Ketanji Brown Jackson wrote the administration was unlikely to succeed, while Justice Brett Kavanaugh cited unreasonably short timelines for state election officials. The blocked executive order would have required USPS citizenship verification, barcode tracking of ballot envelopes, and DHS-compiled "State Citizenship Lists"; a whistleblower alleged a rushed effort to install three restrictive IT verification systems. Justices Alito and Thomas dissented, arguing states and organizations lacked standing.

CyberScoop · 2d agoPolicy & legal

Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail

A whistleblower alleges USPS is rushing untested IT systems that could reject thousands of mail-in ballots ahead of the 2026 midterm elections.

A whistleblower complaint released by Sen. Richard Blumenthal says USPS is deploying three new, largely untested IT systems — including the Federal Ballot Mail Portal — that could reject entire ballot batches over single scan errors. The systems were developed in weeks without standard testing or interoperability checks, and USPS allegedly continued work despite court injunctions against its rule changes. House Oversight Democrats demanded USPS halt implementation, and election experts warn the design could lead to new lawsuits and mass ballot denials.

CyberScoop · 15d agoPolicy & legal

Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone

Citizen Lab and SHARE Foundation confirm a Serbian student activist's iPhone was infected with NSO Group Pegasus via a zero-click iMessage exploit.

Forensic analysis found high-confidence infection indicators on the activist's iPhone during December 2025 and January 2026, using an iMessage zero-click exploit the Citizen Lab believes was patched as of iOS 18.4.1, released April 2025. The target was among at least 14 Apple Threat Notification recipients in Serbia's student movement, civil society, and opposition politics documented by the SHARE Foundation. Targeting occurred ahead of key 2026 election cycles; Amnesty Tech also confirmed a new NoviSpy version on another student movement member's device.

Infosecurity Magazine · 13d agoThreat actor in the wild

Pegasus and NoviSpy Used Against Serbian Protesters

Citizen Lab confirmed zero-click Pegasus infected a Serbian student activist's iPhone, part of the largest documented Serbian spyware wave targeting at least 14 people.

The Citizen Lab, with the SHARE Foundation, confirmed a Serbian student protest movement member's iPhone was infected with NSO Group's Pegasus via an iMessage zero-click exploit between December 2025 and January 2026; Apple patched the exploit in iOS 18.4.1. SHARE Foundation has documented at least 14 targeted individuals since early 2026, including student activists, civil society figures, an opposition MP and a local councilor, coinciding with the March 2026 local elections. SHARE and Amnesty Tech also found a new NoviSpy variant on a student activist's Android phone after Serbian authorities seized it during police questioning.

Security Affairs · 13d agoThreat actor in the wild

Security Vulnerability in a Voting System

A four-year-old vulnerability letting anyone recover ballot casting order was demonstrated with AI coding agents against Georgia's May 2026 primary data.

A previously disclosed vulnerability in ballot scanners used across 21 US states, including Georgia, allows recovery of the order in which ballots were cast. Nearly four years after the original disclosure, a researcher pointed AI coding agents at the vulnerability paper and used only public data — county early-voting lists and cast-vote record (CVR) files — to analyze voter behavior in Georgia's May 2026 primary. The demonstration required no access to voting machines, networks, source code, or non-public records.

Schneier on Security · 12d agoResearch in the wild

July 2026 Cyber Attacks Statistics Infographic

Hackmageddon's infographic condenses July 2026's 188 confirmed cyber attacks into a visual breakdown of actors, entry vectors, targets, and geography.

Hackmageddon published a one-page infographic summarizing 188 confirmed cyber attacks observed in July 2026. It visually maps attacker motivation, infection and entry vectors, targeted sectors, and geographic distribution for the month. It is a companion piece to the site's detailed monthly statistics report.

Hackmageddon · Aug 13, 2026Industry

6 Months on Alert: Get H1 2026 Cyber Risk Report for SOCs and MSSPs

ANY.RUN's H1 2026 report details 15 threat trends including 437% growth in fake CAPTCHA phishing and 90.7% rise in Adobe infrastructure abuse.

The report draws on interactive sandbox submissions from over 700,000 analysts and 16,000 SOC teams between January and June 2026. Attacks abusing Adobe infrastructure grew 90.7% versus H2 2025 while RMM-related attacks rose 26.5%, and custom fake CAPTCHA phishing grew 437% from Q1 to Q2 2026. ANY.RUN argues static IOCs are losing effectiveness as dead drop resolvers hide the final C2 until execution.

ANY.RUN · 1d agoResearch

1-15 August 2026 Cyber Attacks Timeline

Hackmageddon logged 108 confirmed cyber incidents for August 1-15, 2026, led by malware and public-facing application exploits.

Hackmageddon recorded 108 confirmed incidents between August 1-15, 2026, with cybercrime accounting for 90 of them (83.3%). Malware was the dominant vector with 26 incidents (24.1%), and exploitation of public-facing applications (MITRE ATT&CK T1190) was the leading initial access vector in 36 classified incidents. Cyber espionage motivated 15 incidents, and Public Administration was the most-targeted sector with 25 of 139 sector mentions.

Hackmageddon · 14d agoResearch 2 sources

Upcoming Speaking Engagements

Bruce Schneier lists upcoming 2026 speaking engagements at LAcon V, Elevate Festival, CanSecWest, and events in Anaheim, Toronto, Vancouver, and Montreal.

Bruce Schneier posted his upcoming schedule, including LAcon V in Anaheim, an online League of Women Voters event on September 22, 2026, Elevate Festival in Toronto (September 22-24), CanSecWest 2026 in Vancouver (September 30-October 1), and ATTENTION: Democracy, Rebuilt in Montreal (October 21-23, 2026).

Schneier on Security · Aug 15, 2026Industry

ICE Wants the Country’s Voter Data

ICE seeks a federal contractor to access national voter registration and history files, citing fraud detection ahead of the midterm elections.

Procurement records reviewed by 404 Media show ICE seeking a federal contractor to provide access to US voter registration and voter history data to help detect fraud. Observers question whether the data will support immigration enforcement actions ahead of the midterms, given the administration's use of fraud as a pretense. The paywalled article provides few further details.

404 Media · 22d agoPolicy & legal

Key lawmaker suggests action on AI safety legislation will wait until 2027

House Energy and Commerce Chairman Brett Guthrie declined to commit to a 2026 vote on the FRONTIER Act, pushing AI safety legislation toward 2027.

House Energy and Commerce Chairman Brett Guthrie said he would not pledge a timeline for a committee vote on the bipartisan FRONTIER Act, signaling action likely waits until 2027. The bill, co-sponsored by Jay Obernolte and Lori Trahan, has support from OpenAI, Anthropic, and lawmakers across party lines. At the same event, White House adviser David Sacks endorsed Elon Musk's proposal for cross-industry pre-release model testing, while Hugging Face CEO Clem Delangue argued existing cyberattack liability suffices but urged mandatory disclosure of AI-agent attacks. The debate follows incidents of rogue AI agents launching cyberattacks, including roughly 700 OpenAI agents hacking Hugging Face's platform.

The Record · 5h agoAI policy

Intelligence Insights: August 2026

Red Canary's August 2026 Intelligence Insights report covers new threat actor debuts, departures, and threats targeting the blockchain sector.

Red Canary published its August 2026 Intelligence Insights, a monthly threat intelligence roundup. This edition highlights newly emerged threat actors, groups that ceased or reduced activity, and danger on the blockchain, likely threats to cryptocurrency and blockchain ecosystems.

Red Canary · 27d agoThreat actor

Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense

Mexico's 2025-2030 Cybersecurity Plan sets a national roadmap to counter threats including ransomware and build durable cyber defenses.

Mexico published its 2025-2030 national Cybersecurity Plan, outlining the country's threat landscape — with ransomware highlighted as a key risk — and a roadmap for strengthening national cyber defenses. The plan defines priorities for building durable defensive capabilities over the five-year period.

Recorded Future · 23d agoPolicy & legal

A California county wants to hire Tina Peters to help run its elections

Shasta County, California plans to hire Tina Peters, convicted of stealing voting system software, as assistant registrar of voters.

Shasta County registrar of voters Clint Curtis said he plans to hire former Mesa County clerk Tina Peters as assistant registrar after Colorado Governor Jared Polis commuted her nine-year sentence for seven felonies, including identity theft, breaking into an election office, and stealing voting system software. Senators Alex Padilla and Adam Schiff asked California Secretary of State Shirley Weber to provide maximum oversight to prevent Peters from improperly accessing ballots, voting systems, or data of over 100,000 registered voters. The county board of supervisors recently censured Curtis after investigations found he was verbally abusive or physically threatening toward staff.

CyberScoop · 28d agoPolicy & legal

Proofpoint 2026 Voice of the CISO Report Finds Cyber Resilience Improving, While AI Expands the CISO Mandate

Proofpoint's 2026 survey of 1,600 CISOs finds improving cyber resilience, rising human risk, and expanding AI responsibilities without added resources.

Proofpoint released its 2026 Voice of the CISO report, a Censuswide-conducted survey of 1,600 CISOs across 16 countries fielded in May 2026. Expected material cyberattacks fell from 76% to 61% year over year and material data loss declined from 66% to 53%, but 79% of CISOs now identify human risk as their biggest vulnerability and GenAI security concerns jumped 18 points to 78%. The report also finds 79% of CISOs expect to manage AI-related risks without proportional resources, and 85% say boards are evaluating cyber risk through a commercial lens.

Proofpoint Threat Insight · 8d agoIndustry