Tuesday
On Tuesday, May 12, 2026, four separate clocks expire on the same day.
The first is a court order. On March 17, 2026, the Foreign Intelligence Surveillance Court — the same court that for fifteen years held the legal authority over FBI surveillance under Section 702 of the Foreign Intelligence Surveillance Act — issued an opinion on the bureau's query practices. Per the Cotton-Warner letter Senator Wyden released on May 1, the intelligence community committed to complete its declassification review and release the opinion within fifteen days — by about May 15. The clock is sixty days. Tuesday is day sixty. The opinion will be redacted before publication, but the redactions themselves are governed by the FISC, not the executive branch.
The second is a security patch cycle. Microsoft Patch Tuesday — the May 12 release of cumulative security updates — lands in what Zecurit's vulnerability tracker calls the "final comfortable deployment window" before the June 26, 2026 expiration of the long-standing Microsoft Secure Boot UEFI certificate, which has chained the boot integrity of billions of Windows installations since 2012. The Secure Boot certificate is not a software bug. It is the cryptographic root of trust for hardware-anchored boot integrity. Its replacement requires firmware-level changes on hundreds of millions of devices, and the operational window before June 26 has been progressively compressed by IT teams as the certificate-replacement project has slipped through Q1 and into Q2.
The third is a ransom deadline. On May 8, 2026, the ShinyHunters extortion group set a new deadline of end of day May 12 for Instructure, the operator of Canvas — the learning management system used by 8,809 institutions worldwide and, per Wikipedia's tracker, the largest education-sector security breach on record. The trove claimed: 3.65 terabytes, approximately 275 million records, including private student-teacher messages, grades, and behavior records. The defacement of approximately 330 Canvas login pages on May 6-7 — via the Free-For-Teacher vector — was the proof-of-access. Instructure has not paid as of May 9.
The fourth is also a ransom deadline. On May 6, 2026, the Qilin ransomware group posted Sysco — the world's largest foodservice distributor, supplying restaurants, hospitals, schools, prisons, and military bases — with a May 12 deadline. Sysco is approximately $77 billion in annual revenue and operates the foodservice cold chain for roughly fifteen percent of the U.S. institutional food market. Internal documents were attached as proof.
These are not four related events. They are four unrelated events that have arrived at the same Tuesday.
Today
Today is Saturday, May 9, 2026. The federal cybersecurity calendar has a separate deadline today.
On May 6, 2026, the Cybersecurity and Infrastructure Security Agency added Palo Alto PAN-OS CVE-2026-0300 to the Known Exploited Vulnerabilities catalog. The flaw — an unauthenticated buffer overflow in User-ID / Captive Portal, with CVSSv4 score 9.3 — produces root remote code execution on PA-Series and VM-Series firewall hardware. The CISA Binding Operational Directive 22-01 deadline for Federal Civilian Executive Branch agencies to remediate is today, May 9.
Palo Alto's vendor fix is scheduled for May 13. The CISA deadline pre-dates the vendor fix by four days.
This is the most aggressive Known Exploited Vulnerability deadline CISA has issued in the four-year history of the BOD-22-01 program. The operational implication is that FCEB agencies cannot install a patch. They are required, by Saturday, to deploy configuration-only mitigations — disabling the User-ID component or the Captive Portal feature, restricting management access to non-Internet networks, or removing the firewall from the perimeter entirely — on internet-facing edge firewalls. Across the federal civilian executive branch, that is several hundred named appliances at minimum. The mitigation is regulator-side; the patch is vendor-side; the user (in this case, federal IT operations) is in between.
On May 8, 2026, CISA added a second entry. Ivanti Endpoint Manager Mobile CVE-2026-6973 — authenticated administrative remote code execution, CVSS 7.2, exploited in "very limited" environments per Help Net Security's reporting — has an FCEB deadline of May 10 (Sunday).
The pattern is two aggressive KEV deadlines in 48 hours.
The Diameter Downgrade
Today is also a commercial spyware day.
In the Tech Generation revival published today of Kaspersky's October 28, 2025 ForumTroll APT disclosure, Memento Labs CEO Paolo Lezzi publicly admits that the Dante commercial spyware named in the Securelist write-up is his company's product. He blames "a careless government customer using an old version." The Chrome zero-day targets identified in Securelist were in Russia and Belarus. Memento Labs, the Italian spyware vendor formerly known as Hacking Team and later as RCS Lab, has joined the publicly-named-spyware vendor list: NSO Group, Paragon Solutions, Intellexa, Variston (wound down 2025), Memento Labs.
The Citizen Lab "Bad Connection" report of April 23, 2026 named two campaigns running concurrently. STA1 — the team's designation for a state-aligned actor — runs a Diameter-to-SS7 downgrade attack via a "combined attach" procedure abuse, spoofing operator identity across nine countries to act as a "ghost operator" on victim sessions. STA2 — the team's designation for a separate actor — runs SIMjacker zero-click SMS attacks via the S@T (SIM Application Toolkit) browser applet still present on millions of legacy SIM cards. Citizen Lab describes the combined campaign as "likely affecting thousands of devices." On May 3, Haaretz reported that several Israeli telecom carriers were among the operators spoofed by STA1. The Mobile Verification Toolkit, iVerify, and Lookout — the three primary forensic tools available to investigative journalists and at-risk users — cannot detect Diameter-layer or SS7-layer attacks. They detect device-side compromise. STA1 and STA2 are carrier-side compromise.
On April 28, 2026, TechCrunch reported that Paragon Solutions — now operationally embedded inside Immigration and Customs Enforcement under a $2 million contract — still has not, one year on, answered Italian prosecutors' formal request for information about the Graphite spyware deployment against confirmed victims journalist Francesco Cancellato, Luca Casarini, and Giuseppe Caccia. The formal request was channeled through the Israeli government in the normal mutual legal assistance flow.
On April 24, 2026, Senator Ron Wyden led 30 lawmakers in an oversight letter on commercial spyware. The letter has not received a response.
The commercial spyware industry is not "captured." It is integrated.
The Mobile Country
The mobile carrier layer is the state's primary control surface in jurisdictions with no carrier alternative.
Iran's internet blackout, on day 71 since the February 28 shutdown, has hardened into "Internet Pro." The Iran Human Rights Monitor's May 9 report, "Infrastructure of Silence," documents the policy: tier-2 SIM cards (the default) lose access to the global internet entirely; tier-1 "Internet Pro" SIMs — issued by Tasnim and three other state-aligned telecoms upon presentation of national identification, business documentation, and a written purpose — are whitelisted to a subset of approved sites including state media and government services. The reported cost is $35.7 million per day in foregone digital-economy activity. NetBlocks placed cumulative losses above $1.8 billion at day 48; no later cumulative figure has been published. The whitelist itself is administered by a national filtering committee whose membership is not public. Reports filed with Access Now in early May describe queue times of three to four hours at SIM-conversion offices in Tehran and Mashhad.
Russia rolled pre-Victory-Day mobile shutdowns across more than 21 regions from May 4 to May 9. The justification given by Roskomnadzor was drone strike defense — mobile networks can be used to coordinate ground-launched FPV drones. Reuters, Meduza, and Al Jazeera Russia bureau have reported that ATMs in affected regions are down because they depend on cellular backhaul. Russia's April 15, 2026 law requiring all ISPs and mobile carriers to implement VPN-detection at the network layer formally activates state-side enforcement of the carrier-as-perimeter posture.
On May 5, 2026, Sudan's MTN Sudan suspended all Khartoum relay stations over fuel and electricity. Internet Society Pulse reports Khartoum down at the carrier-radio layer. The shutdowns coincide with the secondary-school exam window.
In Pakistan, the National Cybercrime and Cyber-Investigation Agency Punjab booked 41 and arrested 13 journalists, bloggers, and activists under amendments to the Prevention of Electronic Crimes Act in the week ending May 7. The Pakistan Press Foundation's May 5 report logged 233 press-freedom incidents from January 2025 through April 2026.
Reporters Without Borders' May 6 exposé documented the secret detention of Burkinabé journalist Atiana Serge Oulon in a Ouagadougou villa, where Le Monde, the Washington Post, and Africanews corroborate he was beaten with tree branches over a period of weeks.
The architectural pattern is the same across each country: there is no architectural alternative to the carrier layer for ordinary residents. The state controls the radio. The state controls the SIM. The state controls the VPN-detection middlebox. The user has no fallback unless they have one architecturally distinct from the carrier.
Education
The Canvas / Instructure breach is the largest education-sector security incident ever publicly disclosed.
The numbers per the May 8 ShinyHunters drip release: 3.65 terabytes, approximately 275 million records, 8,809 institutions. The ShinyHunters group, the same group that has been running the third-party-SaaS-aggregator extortion wave attributed since April to the post-Salesforce vector chain, defaced approximately 330 Canvas instances' login pages on May 6-7 — the proof-of-access display. CNN's Brian Fung first reported the defacements publicly on May 7 at 1:20 p.m. PDT, after a college student in Mississippi posted a screenshot to TikTok of a Canvas login screen that read, in red Arial: "Mr. Cannon, sorry for the inconvenience this caused, but our offer is fair. — ShinyHunters."
By May 8, the disclosed trove scale was confirmed by KrebsOnSecurity. Krebs verified the institution count by cross-checking the ShinyHunters file manifest against Instructure's published customer list, finding 8,809 distinct institutional identifiers — including the entire University of California system, Cornell, Brown, Stanford, MIT (which uses Canvas for cross-listed K-12 outreach programs), and roughly seventy-five percent of named K-12 public school districts in California, Texas, Florida, and New York. The TIME Magazine breakdown on May 8 noted: "Per institution, the breach exposes private student-teacher messages, grade history, behavior records, and IEP / 504 disability accommodations notes."
The new deadline ShinyHunters set is end of day May 12. Instructure has not paid as of May 9. The cadence — May 6 missed deadline, May 7 defacement, May 8 trove dump, May 12 new deadline — is the playbook ShinyHunters has run on Cushman & Wakefield (commercial real estate), Pitney Bowes (mail logistics), Canada Life (insurance), Carnival (cruise), Zara (apparel), 7-Eleven (retail), Mytheresa (luxury), and Hallmark (consumer goods) since late April.
Sysco
On May 6, 2026, the Qilin ransomware group — the same group whose 2024-2025 wave hit Synnovis, NHS London, and Change Healthcare — listed Sysco on its leak site with a May 12 ransom deadline.
Sysco is the world's largest foodservice distributor: approximately $77 billion in annual revenue, operations in 90 countries, the foodservice cold chain for restaurants, hotels, hospitals, K-12 school cafeterias, college dining services, prison commissaries, and U.S. military mess operations. Roughly fifteen percent of the U.S. institutional food market depends on Sysco's logistics. The internal documents Qilin attached as proof include shipping schedules and supplier-relationship records.
Qilin has continued through May 8 and 9: Imex International (Egyptian shipping), Exco Technologies (Canadian automotive manufacturing), CAD-IT UK (industrial engineering), DL Cohen Construction (US construction), and on May 9, Lindabury (New Jersey law firm).
The Akira group ran a parallel May 7 victim drop: Grau GmbH (Hamburg retail and manufacturing), Elia Law Firm APC (San Diego), Punch & Associates Investment Management (US asset management), Réseau Radiologique Romand (Swiss radiology network), Clinical Registry Solutions (US healthcare-data services), and Pipestone (US agriculture).
The PEAR extortion group — a name new to the May 6-9 window — appeared in four healthcare-sector disclosures per HIPAA Journal: Western Orthopaedics (Colorado), Community Health Systems (California), Tri-Cities Gastroenterology (Tennessee), and Integrated Pain Associates (Texas).
The Iranian state-aligned threat group MuddyWater (MOIS-attributed) is per SecurityWeek running a campaign that masquerades as "Chaos ransomware" — using Microsoft Teams social engineering to obtain initial access and then deploying what appears, to the victim, as criminal ransomware. The intent is plausible deniability: the victim sees ransomware, the actor obtains intelligence access.
The ransomware-economy cadence has not slowed.
Dirty Frag
On May 7, 2026, security researcher Hyunwoo Kim published a proof-of-concept exploit chain dubbed "Dirty Frag" — chaining CVE-2026-43284 (a use-after-free in the Linux kernel's xfrm-ESP path) and CVE-2026-43500 (a logic flaw in the RxRPC implementation) — into a single-command unprivileged-to-root local privilege escalation on Linux kernels 6.4 through 6.11. The chain affects Ubuntu, Red Hat Enterprise Linux, CentOS Stream, AlmaLinux, openSUSE Tumbleweed, and Fedora. The chain runs in approximately two seconds on commodity hardware.
On May 8, the Microsoft Security Blog confirmed in-the-wild exploitation. The detection narrative: "limited in-the-wild activity using the su command after the initial Dirty Frag root acquisition." Microsoft's signal is significant because Microsoft is not a Linux vendor; the detection came from Microsoft Defender for Endpoint telemetry on Linux servers in enterprise environments where the agent is deployed.
The "Linux is safe" mythology was already weakened by the April 23 RxRPC compromise (the same subsystem) and the February PaperHexagon glibc exploitation chain. Dirty Frag is the second universal Linux root chain disclosed in 90 days.
The architectural lesson: kernel-side privilege boundaries are a hardness assumption, not a guarantee. Userspace-only sandboxing (containers, seccomp, AppArmor, SELinux) is the user-side response, but only if applied — most deployed Linux servers are root-privileged for operational simplicity.
Capture by another name
On May 4, 2026, the Federal Trade Commission filed its final settlement with Kochava — the Idaho data broker that for five years served as the test case for whether the FTC could bring location-data sales under Section 5 unfair-or-deceptive-acts authority. The settlement: permanent injunction on Kochava's sensitive-category location-data sales. No monetary fine. The FTC's authority to require disgorgement was, in this case, not exercised.
On May 7, 2026, the Council of the European Union and the European Parliament reached a provisional agreement on the "Digital Omnibus" — a package of amendments to the EU AI Act. The Omnibus shifts the deadline for high-risk obligations from August 2, 2026 to December 2, 2027, and shifts the deadline for general-purpose AI obligations to August 2, 2028. The Parliament inserted, over the Commission's objection — and largely as a response to the Grok deepfake controversy of the late winter — a first-ever EU-law-level prohibition on AI nudifier applications, with a compliance date of December 2, 2026.
On May 4, 2026, the third trilogue of the EU CSAR / Chat Control regulation under the Danish presidency dropped the mandatory client-side scanning requirement that had been the regulation's most controversial provision. The fourth trilogue is scheduled for May 11, 2026. Per the EFF's commentary, the regulation as it now stands requires only voluntary detection of CSAM material on non-end-to-end-encrypted channels, with judicial authorization required for any active probe.
In October 2025, U.S. District Court Judge Phyllis Hamilton reduced the WhatsApp-versus-NSO punitive damages award from $167.2 million to approximately $4 million, citing a 9:1 ratio cap. The judgment is now in Ninth Circuit appellate posture. NSO Group is now controlled by a U.S. investor group with former Trump ambassador David Friedman as executive chairman; the January 2026 transparency report was stripped of customer-termination figures. In December 2025, the Treasury quietly delisted three Intellexa Specially Designated Nationals.
The pattern across these five separate processes is the same. Regulatory enforcement is softening at the precise points where it would otherwise impose operational costs on the actors named. AI Act high-risk obligations slip sixteen months. Chat Control's mandatory client-side scanning is dropped. Kochava is enjoined but not fined. NSO's punitive damages are reduced 40-fold. Intellexa SDNs are delisted.
Concurrently, the regulatory compulsion at the user side — Apple Declared Age Range API live in Utah on May 6 and Louisiana on July 1; Mexico CURP Biométrica's June 30 deadline tying ~127 million mobile lines to face, fingerprint, and iris biometrics; TAKE IT DOWN Act platform compliance May 19; Section 702 reauthorization on its second short-term patch; ICE Project SAFE HAVEN $12.2 million Edge Ops LLC contract — is intensifying.
The vacated patch is the operator-side. The intensified compulsion is the user-side. The asymmetry is the article.
The user side
The architectural counter to the May 12 window is the user-controlled primitive stack. The primitives do not depend on which way May 12 goes.
Open clients with user-held keys at the messaging layer. Signal Foundation continues maintenance of the Signal protocol implementation; Tuta, Proton, and Threema operate independent E2EE messaging; Briar, Cwtch, and Session operate trustless variants; Matrix homeservers permit federated self-hosting. The Roblox $35.8 million state-AG settlement of April 21 demonstrated that even existing E2EE can be regulatorily compelled away from a major platform. Open clients with user-held keys do not have the surface for this compulsion. Briar 1.5.17, released March 12, runs over Bluetooth, Wi-Fi, and Tor; it functions during network shutdowns because it does not depend on the carrier layer to forward messages.
Open firmware on user-inspectable chips. GrapheneOS, CalyxOS, /e/OS, LineageOS, OpenWRT. The DarkSword iOS attack chain documented by iVerify, Lookout, and Google TAG on March 18-19 left an estimated 220-270 million iPhones on exposed iOS versions (18.4 through 18.6.2). Open-firmware mobile devices expose cache and notification-database behavior to user inspection; closed-firmware operating systems do not.
FIDO2 hardware authentication. YubiKey, Nitrokey, SoloKey. On May 4, OpenAI added passkeys and hardware keys to ChatGPT — co-branding a YubiKey C NFC / C Nano two-pack at approximately $68. Yubico has shipped more than 30 million YubiKeys lifetime. Hardware-bound credentials survive SIM compromise; SS7 / Diameter ghost-operator attacks like STA1 do not bridge to hardware-key-protected accounts because the second factor is not on the SIM.
Censorship-resistant transports. Tor 15.0.10, V2Ray VLESS+Reality, Shadowsocks-2022, Trojan, WireGuard with obfsproxy, URnetwork peer-to-peer. URnetwork's February 19, 2026 MCP server release lets agentic clients establish VPN sessions over the peer-to-peer overlay, abstracting the transport from the carrier layer. State-mandated platform blocking does not affect transport-layer obfuscation. Iran's "Internet Pro" tier and Russia's April 15 VPN-detection law are the threat model.
Privacy-preserving currencies on user-custody primitives. Bitcoin BIP324 v2 (default-on since Core 27.0; majority of global BTC P2P traffic now encrypted) and BIP352 silent payments (receive and send in Core 28.0+; BIP376 and BIP392 added in 2026; Nunchuk added SP support). Monero is in active FCMP++ integration; the Trail of Bits audit runs May 11 through May 22, replacing ring signatures with full-chain membership proofs whose anonymity set is the entire UTXO set. Zcash Crosslink Milestone 4 has launched feature nets; the shielded pool is at all-time-high 5,030,093 ZEC (approximately 30 percent of supply). Operator-blacklist money is operator-pathway money; user-custody currencies do not have the surface.
Local-inference AI on user-controlled compute. DeepSeek V4 Pro (released MIT-licensed April 22, 1.6 trillion parameters / 49 billion active, 1-million-token context, 27 percent of single-token FLOPs vs V3.2 at 1M context); Mistral Medium 3.5 (April 29, 77.6 percent SWE-Bench Verified); Llama 4 Scout; Gemma 4; Qwen 3.6; Kimi K2.6; GLM-5.1; OpenAI Privacy Filter (April 22, Apache 2.0, 1.5B total / 50M active params, browser-runnable via transformers.js + WebGPU). Where there is no third-party log, there is nothing to subpoena. The OpenAI v NYT 20-million-log production order issued January 5 by Judge Sidney Stein is the threat model.
Federated identity with selective disclosure. W3C Verifiable Credentials 2.0 (Recommendation status May 2025; 7 specs); eIDAS 2.0 BBS+ selective disclosure (IETF finalization in progress); Privacy Pass; the W3C VC Working Group operating under a new April 2026 charter targeting Render Method and Confidence Method Recommendation in September 2026. The Mexican CURP Biométrica is the threat model: don't upload identity to the centralized state biometric registry.
Self-hosted services. Matrix homeserver, Forgejo, Mailcow, Jitsi, Nextcloud, Mautic, SuiteCRM, Moodle community, Open edX. Federation bounds the blast radius of any single vendor compromise. The Canvas / Instructure 8,809-institution blast radius is the threat model.
Mesh and satellite at the carrier layer. Briar; Bridgefy; Meshtastic; Reticulum; GoTenna PRO; Starlink. The Iran "Internet Pro" tier and the Sudan Khartoum tower power-out are the threat model. The Tanzania 518-dead commission-of-inquiry finding from April 23, 2026 is the moral anchor — when shutdown enables state violence, the carrier-independent layer matters.
The clocks running
| Date | Event | |---|---| | May 9, today | CISA FCEB PAN-OS CVE-2026-0300 deadline (4 days before vendor fix) | | May 10 | CISA FCEB Ivanti EPMM CVE-2026-6973 deadline | | May 11 | EU Chat Control trilogue 4; Monero FCMP++ Trail of Bits audit begins | | May 12 | FISC March 17 opinion court-ordered public; MS Patch Tuesday; Canvas / Instructure ransom deadline; Sysco / Qilin ransom deadline | | May 13 | Palo Alto PAN-OS vendor fix | | May 14 | Bartz v. Anthropic fairness hearing ($1.5B); Digital euro PSP applications close | | May 19 | TAKE IT DOWN Act platform compliance | | May 22 | Monero FCMP++ Trail of Bits audit ends | | May 26 | UK Online Safety Act age-verification consultation closes | | May 27 | Meta annual meeting (NLPC AI privacy proposal) | | June 12 | Section 702 sunset (full reauthorization) | | June 26 | Microsoft Secure Boot UEFI certificate expires | | June 30 | Mexico CURP Biométrica deadline | | July 1 | Apple Declared Age Range API live in Louisiana; MiCA full CASP enforcement | | Aug 2 | EU AI Act GPAI enforcement powers activate | | Sept 21 | FIPS 140-2 certifications → Historical (PQC sunset) | | Oct 5-12 | Roman Storm Tornado Cash retrial | | Dec 2026 | EU Digital Identity Wallet deployment deadline (27 Member States) |
Closing
Today is Saturday. Today the federal civilian executive branch is deploying configuration mitigations because Palo Alto's patch is four days away. Today Iran's "Internet Pro" caste system is in operational production at three to four hours of queue time in Tehran. Today Memento Labs has admitted Dante. Today Russia's 21 oblasts are dark on the carrier layer. Today Sudan's Khartoum is dark on the radio layer. Today Pakistan has 13 journalists in custody. Today RSF is publishing the Burkina Faso villa.
On Tuesday, the FISC opinion will become public — or it will not. Patch Tuesday will land. Canvas will pay the ransom — or it will not. Sysco will pay the ransom — or it will not.
The Tuesday clocks are real. They will tick.
The user-controlled primitive stack is also real. It does not depend on Tuesday.
The May 12 window is one day. The primitive stack is the response that runs every day.
References (3 sources)
References
- CISA KEV catalog (May 6, May 8): https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Palo Alto Networks CVE-2026-0300 advisory: https://security.paloaltonetworks.com/CVE-2026-0300
- Help Net Security on Ivanti EPMM CVE-2026-6973 (May 8): https://www.helpnetsecurity.com/2026/05/08/ivanti-epmm-zero-day-cve-2026-6973/
- CNN on Canvas / Instructure (May 7): https://www.cnn.com/2026/05/07/us/canvas-hack-strands-college-students-finals-week
- TIME on Canvas / Instructure (May 8): https://time.com/article/2026/05/08/canvas-cyber-attack-shinyhunters-hack-what-to-know/
- KrebsOnSecurity on Canvas: https://krebsonsecurity.com/2026/05/canvas-breach-disrupts-schools-colleges-nationwide/
- Citizen Lab "Bad Connection" (April 23): https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/
- TIME on FISC March 17 opinion (April 27): https://time.com/article/2026/04/27/fisa-fbi-spying-surveillance-fisa-court-congress-wyden/
- BleepingComputer on Dirty Frag (May 7): https://www.bleepingcomputer.com/news/security/new-linux-dirty-frag-zero-day-with-poc-exploit-gives-root-privileges/
- Microsoft Security Blog on Dirty Frag ITW (May 8): https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/
- Council of the EU AI Act provisional agreement (May 7): https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/
- FTC v. Kochava final settlement (May 4): https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-ban-kochava-subsidiary-selling-sensitive-location-data-settle-charges-they-sold-location-data
- EFF on EU CSAR / Chat Control trilogue 3: https://www.eff.org/deeplinks/2026/04/eu-parliament-blocks-mass-scanning-our-chats-whats-next
- TechCrunch on Paragon non-cooperation (April 28): https://techcrunch.com/2026/04/28/paragon-is-not-collaborating-with-italian-authorities-probing-spyware-attacks-report-says/
- Securelist on ForumTroll / Dante: https://securelist.com/forumtroll-apt-hacking-team-dante-spyware/117851/
- Iran HRM "Infrastructure of Silence" (May 9)
- Access Now KeepItOn 2025 Annual Report (March 31): 313 shutdowns in 52 countries
- Cybernews on Sysco / Qilin (May 6): https://cybernews.com/news/sysco-qilin-ransomware-claim-food-supplier/
- HIPAA Journal on May 2026 healthcare ransomware
- BleepingComputer on cPanel CVE-2026-41940 mass exploitation
- THN on DAEMON Tools supply-chain (Kaspersky May 6): https://thehackernews.com/2026/05/daemon-tools-supply-chain-attack.html
- BleepingComputer on JDownloader site swap: https://www.bleepingcomputer.com/news/security/jdownloader-site-hacked-to-replace-installers-with-python-rat-malware/
- Trail of Bits / Monero FCMP++ audit announcement
- Apple Developer News (Age Range API): https://developer.apple.com/news/?id=f5zj08ey
- Council on EU AI Act Digital Omnibus
- News/Media Alliance letter to Common Crawl (April 29)
- OpenAI Privacy Filter release notes (April 22): https://openai.com/index/introducing-openai-privacy-filter/
- DeepSeek V4 release (April 22): https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro
- Bartz v. Anthropic settlement hearing: https://anthropiccopyrightsettlement.com/dates
- URnetwork MCP server (February 19)
- Briar 1.5.17 release notes (March 12)
- Mexico CURP Biométrica deadline (June 30): https://idtechwire.com/mexico-clarifies-rules-linking-biometric-curp-to-sim-registration-ending-anonymous-mobile-numbers-by-mid-2026/
- The Register on Cushman & Wakefield (May 5): https://www.theregister.com/security/2026/05/05/cushman_wakefield_confirms_vishing_cyberattack/
- TechRadar / HaveIBeenPwned on ShinyHunters mass-leak (May 6-8)
- DHS hacktivist leak of ICE contractor data (March 2): https://techcrunch.com/2026/03/02/hacktivists-claim-to-have-hacked-homeland-security-to-release-ice-contract-data/
- Jacobin on ICE Project SAFE HAVEN $12.2M Edge Ops contract: https://jacobin.com/2026/04/ice-contract-ai-surveillance-immigrants
- Reporters Without Borders on Burkina Faso (May 6)
- Pakistan Press Foundation 2025-2026 report
- Internet Society Pulse on Sudan MTN Khartoum (May 5)