Supreme Court denies Trump request to allow USPS mail ballot changes
Supreme Court denied the Trump administration's emergency request to implement USPS mail ballot changes before the 2026 midterms, calling it arbitrary and capricious.
The U.S. Supreme Court rejected 7-2 the Trump administration's petition to change how the U.S. Postal Service handles mail-in ballots for the 2026 midterm elections. Justice Ketanji Brown Jackson wrote the administration was unlikely to succeed, while Justice Brett Kavanaugh cited unreasonably short timelines for state election officials. The blocked executive order would have required USPS citizenship verification, barcode tracking of ballot envelopes, and DHS-compiled "State Citizenship Lists"; a whistleblower alleged a rushed effort to install three restrictive IT verification systems. Justices Alito and Thomas dissented, arguing states and organizations lacked standing.
The EU CRA's Real Question: What Shipped, and When Did You Know?
ActiveState argues the EU CRA's 24-hour ENISA exploit-notification duty, effective September 11, 2026, makes current SBOMs and provenance visibility a legal necessity.
An ActiveState essay warns that the EU Cyber Resilience Act's reporting obligations take effect on September 11, 2026, requiring manufacturers of products with digital elements sold into the EU to notify ENISA within 24 hours of learning a vulnerability is actively exploited, with a fuller report within 72 hours. The law's engineering requirements only apply from December 11, 2027, leaving a visibility-first runway, and Article 13 requires the SBOM to stay current unlike one-time artifacts generated under US Executive Order 14028. The author contrasts the 24-hour notification clock with an industry-average 55 days to remediate high or critical vulnerabilities and recommends automated SBOM regeneration or consuming pre-vetted, attested open source components.
Risky Bulletin: Russia starts blocking DoH and DoT
Russian users report blocks on DoH and DoT servers, including Cloudflare 1.1.1.1 and Google 8.8.8.8, in an apparent censorship crackdown.
Russian internet users began reporting failures connecting to DNS-over-HTTPS and DNS-over-TLS servers, suggesting a government crackdown on the two privacy protocols. The blocks reportedly cover Cloudflare's 1.1.1.1 and Google's 8.8.8.8 resolvers; Roskomnadzor has not officially confirmed the action. The agency tested a similar block in March on Beeline's network and had named DoH for blocking as early as 2021. The bulletin also briefly notes state-sponsored phishing of EU officials, a DDoS against Norway's Digdir, the ReliaQuest/ShinyHunters dispute, and older ransomware and breach disclosures.
The Government is Monitoring Anti
Fusion center bulletins reveal US law enforcement monitoring anti-Flock social media accounts and warning police ahead of the DeFlock Week of Action against license plate readers.
Public records requests by 404 Media and journalist Dan Boguslaw exposed intelligence bulletins from fusion centers in Colorado, Wisconsin, and Florida tracking anti-Flock sentiment, camera vandalism videos, and the DeFlock National Week of Action against automated license plate readers scheduled for August 16-22. The bulletins highlight Instagram accounts like Nomark.Project posting daily camera takedowns, and a device found during a June 25 traffic stop that could locate Flock cameras. Police are advised to increase patrols around ALPR locations and warned about upcoming DeFlock events, including 11 Florida cities signed up. DeFlock creator Will Freeman said the project never called for vandalism and that over 100 surveillance contracts have been canceled through civic engagement.