The HRW report
On Tuesday, May 12, 2026, Human Rights Watch published the 54-page report "Looking the Other Way: EU Failure to Prevent Surveillance Exports to Rights-Abusing Governments." The report is available at hrw.org/report/2026/05/12/looking-the-other-way.
The report's central finding is that six European Union Member States — Bulgaria, Poland, Finland, Denmark, Estonia, and the Czech Republic — have been the principal commercial spyware exporters operating under the 2021 EU Regulation on Dual-Use Items (Regulation EU/2021/821) since its adoption. The 2021 Regulation introduced authorization requirements for what the legal text describes as "cyber-surveillance items" — Pegasus-class spyware, mobile interception equipment, IMSI catchers, lawful-intercept platforms, and certain network telemetry equipment. The authorization requirement is administered by each Member State's competent authority, with the European Commission and other Member States serving as consultation parties.
HRW's documentary finding is that since 2021, none of the six named Member States has publicly denied an export application for "cyber-surveillance items," despite documented shipments to twenty-plus destination countries including Saudi Arabia, the United Arab Emirates, Egypt, Mexico, Hungary, Türkiye, India, Indonesia, Morocco, Bahrain, and approximately ten others. The destination list is mapped against Freedom House Freedom in the World 2025 ratings and the U.S. State Department's annual Country Reports on Human Rights Practices — the result is that the destination countries are, in HRW's reading, the same countries where commercial spyware deployment has been forensically documented against journalists, lawyers, opposition politicians, and human-rights defenders.
The named vendors include companies previously identified by the Citizen Lab, Amnesty International Security Lab, and Access Now Pegasus Project work — Intellexa (whose Greek-headquartered operations have a Czech operating company and Bulgarian-registered intermediaries); Memento Labs, the rebrand of Hacking Team / RCS Lab whose CEO Paolo Lezzi acknowledged on May 9 that the "Dante" commercial spyware named in the October 28, 2025 Kaspersky ForumTroll disclosure is his company's product; and previously unnamed Bulgarian and Estonian shell entities that HRW links to onward-export of Pegasus-class tooling.
The report's structural framing is that the 2021 EU Regulation is a paper tiger. The harmonized framework requires authorization at the Member-State level, but does not require harmonized rejection criteria, harmonized human-rights screening, harmonized end-use verification, or harmonized public reporting. The Regulation requires Member States to report exports to the Commission, but the Commission's aggregated reporting is delayed by approximately three years and does not name destinations or recipient entities.
HRW's recommendations include: a binding human-rights screening requirement at the Member-State authorization stage; a public registry of denied export applications; a Commission-led harmonized rejection list; mandatory end-use audit by independent verification; and a temporary moratorium on commercial spyware exports to nations rated Not Free on the Freedom House index.
The report names six European capitals: Sofia (Bulgaria), Warsaw (Poland), Helsinki (Finland), Copenhagen (Denmark), Tallinn (Estonia), and Prague (Czech Republic).
What May 12 was
This is the day after the day the four clocks of edition 06 expired. The retrospective is structural.
The FISC § 702 opinion did not publish. Despite the Wyden / Cotton / Warner deal of mid-April that established a court-ordered May 12 publication target for the Foreign Intelligence Surveillance Court's March 17, 2026 opinion on FBI Section 702 query practices, the declassification review remains running. The opinion remains classified. The § 702 sunset is now thirty days away — June 12, 2026. The FBI has continued operating under the second short-term Section 702 patch reauthorization through the sunset, with the lookback-query practice that the FISC opinion is understood to address still operational on a U.S. persons-in-the-foreign-intelligence-database basis. The Wyden, Cotton, and Warner offices issued joint statements late on May 12 expressing concern that the FISC opinion has not been made public on schedule; Senate Intelligence Committee Chair Mark Warner described the lapse as "incompatible with the public oversight commitments made during the spring renewal debate."
Microsoft Patch Tuesday landed with 137 CVEs and zero zero-days — the first 0-day-free Patch Tuesday since June 2024. The headline CVEs include CVE-2026-41089 (Netlogon remote code execution, CVSS 9.8), CVE-2026-41096 (DNS Client remote code execution, CVSS 9.8), CVE-2026-42898 (Dynamics 365 remote code execution, CVSS 9.9), and CVE-2026-41097 (a Secure Boot bypass that doubles as part of the rolling certificate-cliff staging for the June 26 Secure Boot UEFI certificate expiration). Microsoft framed the cycle as "the calmest Patch Tuesday of the year," with Defender Cloud telemetry showing zero in-the-wild exploitation across the May 12 CVE list.
Foxconn confirmed Nitrogen ransomware the same day, May 12. The disclosure: eight terabytes and approximately eleven million files exfiltrated. The Nitrogen extortion group alleges that the trove includes Intel, Apple, Nvidia, Google, and Dell project data — contract-manufacturer drawings, supplier engineering specifications, internal project schedules, and unredacted email threads. North American Foxconn factories were disrupted for approximately one week ending May 9. The implication is that the contract-manufacturer layer is a cross-customer aggregator — a single compromise reaches multiple OEM customer perimeters simultaneously, the way Itron's smart-meter breach reached every utility customer of every Itron-using utility (edition 06).
Instructure paid ShinyHunters the day before the May 12 deadline. On May 11, Instructure reportedly transferred a sum that has not been publicly disclosed, in exchange for what ShinyHunters has called "shred logs" for the 3.65 to 6.65 terabyte trove. The trove covers approximately 275 million records across 8,809 educational institutions. This is the first major U.S. education-sector ransom payment to a named extortion group on a breach of this scale. The U.S. House Subcommittee on Cybersecurity, Information Technology, and Government Innovation announced a hearing for May 18 to examine "the operational and policy implications of education-sector ransom payments to extortion groups."
The Sysco / Qilin extortion remains unresolved. Qilin posted three internal document samples on May 12 as proof-of-access. No payment confirmation has been made. No full leak has been released. Sysco's SEC Item 1.05 (Form 8-K) cybersecurity-incident disclosure has not been filed as of today, May 13.
Today
Today, May 13, 2026, Palo Alto shipped the PAN-OS CVE-2026-0300 fix.
Four days late.
The Cybersecurity and Infrastructure Security Agency's emergency Known Exploited Vulnerability deadline for federal civilian executive branch agencies was May 9 — the day before this past Saturday. Federal IT operations spent the four-day gap deploying configuration-only mitigations on internet-facing firewalls: disabling the User-ID component, restricting Captive Portal exposure, removing perimeter firewalls from the public path entirely. Palo Alto's fix — released for PAN-OS 11.1.x and 10.2.x as hotfix patches — closes the unauthenticated buffer overflow that produced root remote code execution.
The four-day gap is the most aggressive Known Exploited Vulnerability deadline cadence in CISA Binding Operational Directive 22-01 history. The federal civilian executive branch operated for four days on configuration mitigations because the vendor patch did not yet exist. The regulatory clock was structurally ahead of the vendor patch clock.
Today is also Dirty Frag day seven. The CVE-2026-43500 (Linux kernel RxRPC) half of the May 7 Dirty Frag chain disclosed by Hyunwoo Kim remains unpatched. Microsoft Security Blog's May 8 in-the-wild confirmation has held: active exploitation continues. The kernel.org commit log for the rxrpc subsystem shows three patches in the May 9-12 window that address related issues but do not close the specific use-after-free in the rxrpc_io_thread path that the chain exploits. Upstream resolution remains pending. Distribution-level backports — Ubuntu, RHEL, CentOS Stream, AlmaLinux, openSUSE Tumbleweed, Fedora — have not shipped.
The pattern: the "calmest Patch Tuesday of the year" coexists with active in-the-wild exploitation of an unpatched universal Linux local privilege escalation, with Foxconn confirming an eight-terabyte ransomware exfiltration on the same day, with Palo Alto shipping a critical edge-firewall RCE fix four days after the federal compliance deadline. The operational reality across the ecosystem is that vendor patch cycles still trail the threat cycle and the regulator cycle.
Tomorrow
Tomorrow, May 14, 2026, two clocks land.
Judge Araceli Martínez-Olguín convenes the Bartz v. Anthropic fairness hearing at 2:00 p.m. Pacific in Courtroom 12 of the San Francisco Federal Courthouse. The $1.5 billion settlement covers 482,460 registered copyrighted works at approximately $3,000 per work. The unsealed objections filed in April flag three structural concerns:
- Foreign-works exclusion. The settlement structure is bounded by U.S. Copyright Office registration. Many authors whose works were ingested into Anthropic's training corpus have non-U.S. nationalities and have registered their copyrights under their home jurisdiction's regime. The objection argues that the foreign-works exclusion creates an under-counted claim universe and that the settlement structure should be expanded to include the foreign-registered universe.
- Group-registration undercounting. Many U.S. registered works are group-registered under collective authorship structures (anthologies, periodicals, course materials). The settlement structure attributes the per-work payout to the registered claimant, which in group-registration cases may be a publisher or institutional rights-holder rather than the underlying authors. The objection argues that this creates a publisher-bias in the settlement distribution.
- Coercive notice. The opt-out window of the class settlement is short relative to the structural difficulty of identifying whether a given author's work is included in the Anthropic training corpus. The objection argues that the notice is coercive in the sense that authors who cannot determine inclusion within the window default to inclusion and lose their right to bring individual infringement actions.
The hearing's outcome will set precedent for the parallel AI-training-data settlement structures that OpenAI, Google, Meta, Cohere, Mistral, and the open-source ecosystem will need to negotiate or litigate. If Judge Martínez-Olguín approves the structure, it becomes the template. If she does not, the template returns to negotiation.
The European Central Bank closes Digital Euro Payment Service Provider applications at 17:00 CEST. The application call was published March 5, 2026. The ECB has indicated it will select between ten and thirty PSPs for a twelve-month pilot beginning in the second half of 2027. The digital euro is designed as a programmable central-bank-issued retail currency. The "programmable" element means that PSPs can enforce limits, conditions, and traceability on individual transactions in software at the protocol layer.
The companion regulatory frame: MiCA enters full enforcement on July 1, 2026, when any unlicensed Crypto-Asset Service Provider serving EU customers must cease operations. The Travel Rule's zero-threshold provision has been operational since December 2024, requiring full originator-and-beneficiary data on every CASP transfer. Penalties under MiCA reach 12.5% of global annual turnover with executive personal liability.
The SEC and CFTC issued a joint interpretation on March 17, 2026, that explicitly names Bitcoin, Ethereum, Solana, XRP, and Chainlink as digital commodities — the U.S.-side cryptocurrency regulatory clarity arriving the same month the EU-side programmable euro regulatory infrastructure formalizes.
The recipient-side counter, where the policy clocks are unevenly running, is the open-foundation primitive stack.
The recipient countries
The HRW report names the exporters. The recipient countries are where the exported tooling deploys. Today, the recipient picture is:
Iran. Day 75 of the blackout. The longest internet shutdown on record. Iran HRM's May 9 "Infrastructure of Silence" report documents the "Internet Pro" white-SIM tier issued by IRGC-linked Mobile Communications of Iran (MCI) — a whitelisted SIM caste that grants access to a curated set of state-approved sites and government services. Tier-2 SIMs (the default) lose access to the global internet entirely. The economic loss is approximately $35.7 million per day; NetBlocks placed cumulative losses above $1.8 billion at day 48, the last published figure. The May 10 CNN deep-dive on "Internet Pro" describes queue times at SIM-conversion offices in Tehran of three to four hours and the emergence of a parallel grey-market resale of converted Tier-1 SIMs for premium prices.
Russia. The April 15, 2026 ISP VPN-detection law is operational. Yandex, VK, Sberbank, and Gosuslugi are all blocking VPN-tunneled traffic at the application layer — a coordinated deputization of major private platforms to enforce the VPN-detection requirement. The pre-Victory-Day mobile shutdowns rolled across more than 21 oblasts from May 4 through May 9, peaking with a full Moscow mobile and SMS shutdown on May 9. ATMs in affected regions were down because they depend on cellular backhaul. The Roskomnadzor justification — drone strike defense — has been challenged by the Meduza independent press in exile, who note that drone coordination uses dedicated FPV control protocols not GSM voice or SMS.
Pakistan. The NCCIA Punjab has booked 41 and arrested 13 journalists, bloggers, and activists under amendments to the Prevention of Electronic Crimes Act between May 3 and May 7. The Pakistan Press Foundation's May 5 report logged 233 press-freedom incidents from January 2025 through April 2026.
Burkina Faso. Reporters Without Borders' May 6 report documented the secret detention of journalist Atiana Serge Oulon in a clandestine Ouagadougou facility, where Le Monde, the Washington Post, and Africanews have corroborated that he was beaten with tree branches over a period of weeks. Burkina Faso's April 15 dissolution of 118 NGOs and Niger's April 23 suspension of 2,900 of 4,700 registered NGOs frame the Sahel civic-space contraction.
Tanzania. The Commission of Inquiry report on the post-October-2025-election violence — Amnesty International's April 23 surfacing confirmed 518 dead and 2,390 injured during a five-day complete internet blackout — remains officially withheld by the Tanzanian government. Human Rights Watch's May 5 "Missed Opportunity" report criticizes the continued withholding. X remains suspended in Tanzania.
Egypt, UAE, Saudi Arabia, Bahrain, Morocco. The five Arab destination countries named in HRW's report continue to operate as commercial-spyware-deployment environments at scale. The Citizen Lab, Amnesty Security Lab, and Access Now Pegasus Project documentation since 2018 covers thousands of targeted devices in these jurisdictions.
The recipient countries do not have carrier-layer alternatives. The recipient-country user does not have access to the regulator who could authorize or deny the EU-side export application. The recipient-country user is the deployment target.
The architectural counter is the user-controlled primitive stack.
The user side
Naming the exporter is regulatory accountability. The user-controlled primitive stack is the technological accountability response. They run in parallel.
Open clients with user-held keys. Signal, Tuta, Proton, Threema, Briar 1.5.17 (released March 12, 2026 — runs over Bluetooth, Wi-Fi, and Tor; functions during network shutdowns), Cwtch, Session, Matrix homeserver. Where the recipient country does not have access to the EU-side regulator, the recipient-country user has access to open-source clients with user-held cryptographic keys. The Meta Instagram E2EE termination on May 8 demonstrated that even existing E2EE can be regulatorily compelled away from a major platform. Open clients with user-held keys do not have the architectural surface for this compulsion.
Open firmware on user-inspectable chips. GrapheneOS, CalyxOS (Android 16 test build released May 4, 2026), /e/OS, LineageOS, OpenWRT. The Citizen Lab "Bad Connection" report of April 23 documented two carrier-side surveillance campaigns — STA1 Diameter-to-SS7 downgrade across nine countries, STA2 SIMjacker zero-click via the legacy S@T browser SIM applet — that are invisible to the Mobile Verification Toolkit, iVerify, and Lookout. The May 9 Memento Labs CEO admission that the "Dante" commercial spyware is his company's product confirmed the device-side reality. Open-firmware mobile devices expose cache and notification-database behavior to user inspection. Closed-firmware operating systems do not.
FIDO2 hardware authentication. On May 7, 2026 — FIDO Alliance World Passkey Day — FIDO published that five billion passkeys have been deployed across the global ecosystem. YubiKey, Nitrokey, SoloKey shipments continue. Yubico has shipped more than 30 million hardware keys lifetime. OpenAI added passkeys and hardware keys to ChatGPT on May 4 with a co-branded YubiKey C NFC / C Nano two-pack at approximately $68. Hardware-bound credentials survive SIM compromise; SS7 and Diameter ghost-operator attacks do not bridge to hardware-key-protected accounts because the second factor does not live on the SIM.
Censorship-resistant transports. Tor Browser 15.0.13 released May 7, 2026. V2Ray VLESS+Reality. Shadowsocks-2022. Trojan. WireGuard with obfsproxy. URnetwork peer-to-peer overlay. URnetwork's February 19, 2026 MCP server release lets agentic clients establish VPN sessions over the peer-to-peer overlay, abstracting the transport entirely from the carrier layer. Iran's "Internet Pro" tier and Russia's April 15 VPN-detection law are the threat model.
Privacy-preserving currencies on user-custody primitives. Bitcoin BIP324 v2 is default-on since Core 27.0; the majority of global Bitcoin peer-to-peer traffic is now encrypted. BIP352 silent payments (Core 28.0+) is in active deployment. Monero is in active FCMP++ Trail of Bits audit; the audit started May 11 and runs through May 22. FCMP++ replaces ring signatures with full-chain membership proofs whose anonymity set is the entire UTXO set — more than 150 million transaction outputs as of the audit start. Zcash Crosslink Milestone 5 completed per the May 10 ZecHub digest.
Local-inference AI on user-controlled compute. DeepSeek V4 Pro (released MIT-licensed April 22, 1.6 trillion parameters / 49 billion active, 1-million-token context, 80.6 percent SWE-Bench Verified). Mistral Medium 3.5 (April 29, 128 billion parameters). Qwen 3.6 Max Preview (April 27). GLM-5.1 (April 7-8, 744 billion mixture-of-experts, top-ranked open-source LMArena entry). OpenAI Privacy Filter (April 22, Apache 2.0, 1.5 billion total / 50 million active parameters, browser-runnable via transformers.js plus WebGPU). Where there is no third-party log, there is nothing to subpoena. The OpenAI Deployment Company launched May 11 and the Anthropic Claude Cowork generally available May 12 are the corporate-side deployment of agentic AI into the SCIM / OpenTelemetry / Intune identity-and-device-management plane. The user-side counter to corporate AI deployment is local-inference AI on user-controlled compute.
Federated identity with selective disclosure. W3C Verifiable Credentials 2.0 (Recommendation status May 2025); eIDAS 2.0 BBS+ selective disclosure (IETF finalization in progress); Privacy Pass; the W3C VC Working Group operating under a new April 2026 charter targeting Render Method and Confidence Method Recommendation in September 2026; the EU Digital Identity Wallet rollout deadline December 2026 (all 27 Member States must provide). The Mexican CURP Biométrica's June 30 deadline — tying approximately 127 million mobile lines to face, fingerprint, and iris biometrics — is the threat model.
Self-hosted services. Matrix homeserver, Forgejo, Mailcow, Jitsi, Nextcloud, Mautic, SuiteCRM, Moodle community, Open edX. Federation bounds the blast radius of any single vendor compromise. The Canvas / Instructure 8,809-institution single-perimeter ransom is the threat model — federation does not have a single-vendor single-perimeter exposure.
Mesh and satellite at the carrier layer. Briar, Bridgefy, Meshtastic, Reticulum, GoTenna PRO, Starlink. The Iran "Internet Pro" tier, the Sudan Khartoum tower power-out, the Russia 21-oblast Victory-Day cuts are the threat model. The Tanzania 518-dead commission-of-inquiry finding is the moral anchor.
Cryptographic agility ahead of the September 21 FIPS 140-2 sunset. ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205) standards live since August 2024. Pre-emptive post-quantum-secure primitive deployment is the only path through the FIPS sunset without rolling back to non-validated state.
The clocks running
| Date | Event | |---|---| | May 13, today | Palo Alto PAN-OS CVE-2026-0300 fix released (4 days after FCEB deadline) | | May 14 | Bartz v. Anthropic fairness hearing ($1.5B); Digital euro PSP applications close | | May 18 | US House Subcommittee hearing on Canvas ransom payment | | May 19 | TAKE IT DOWN Act platform 48-hour takedown compliance | | May 22 | Monero FCMP++ Trail of Bits audit ends | | May 26 | UK Online Safety Act consultation closes | | May 27 | Meta annual meeting (NLPC AI privacy proposal) | | June 12 | Section 702 sunset | | June 26 | Microsoft Secure Boot UEFI certificate expires | | June 30 | Mexico CURP Biométrica deadline | | July 1 | Apple Declared Age Range API live in Louisiana; MiCA full CASP enforcement | | Aug 2 | EU AI Act GPAI enforcement powers activate | | Dec 2, 2026 | EU AI Act Article 5 (CSAM / NCII ban) compliance per Digital Omnibus | | Sep 21 | FIPS 140-2 certifications → Historical (PQC sunset) | | Oct 5-12 | Roman Storm Tornado Cash retrial | | Dec 2026 | EU Digital Identity Wallet deployment deadline (27 Member States) | | Dec 2, 2027 | EU AI Act Annex III high-risk obligations (slipped from Aug 2026) | | Aug 2, 2028 | EU AI Act Annex I high-risk obligations (slipped from Aug 2026) |
Closing
Sofia. Warsaw. Helsinki. Copenhagen. Tallinn. Prague.
Six European capitals are now named in a Human Rights Watch report as the principal commercial spyware exporters operating under the failed 2021 EU Dual-Use Regulation. Twenty-plus destination countries — Saudi Arabia, the UAE, Egypt, Mexico, Hungary, Türkiye, India, Indonesia, Morocco, Bahrain, and ten or more others — receive the exports.
Yesterday was the Tuesday we wrote about on Saturday. The FISC opinion did not publish. Canvas paid. Sysco is stuck. Foxconn confirmed eight terabytes. Patch Tuesday was calm but Dirty Frag still runs and Palo Alto's fix shipped today, four days late.
Tomorrow Judge Martínez-Olguín rules on the $1.5 billion settlement that will or will not become the template for how AI training data gets compensated. Tomorrow the ECB closes the digital euro PSP application window.
The recipient countries — Iran on day 75, Russia at 21 oblasts, Pakistan with 13 arrests, Burkina Faso with the Ouagadougou villa, Tanzania with the withheld commission, Egypt and the UAE and Saudi Arabia and Bahrain and Morocco at the receiving end of the Sofia-Warsaw-Helsinki-Copenhagen-Tallinn-Prague pipeline — do not have access to the European regulator. Their users do not have the carrier-layer alternative.
The user-controlled primitive stack is the architectural response.
Open clients. Open firmware. Hardware keys. Censorship-resistant transports. Privacy-preserving currency. Local-inference AI. Federated identity with selective disclosure. Self-hosted services. Mesh and satellite. Cryptographic agility.
Naming the exporter is one accountability. The primitive stack is the other.
Both run.
References (2 sources)
References
- Human Rights Watch, "Looking the Other Way" (May 12, 2026): https://www.hrw.org/report/2026/05/12/looking-the-other-way/eu-failure-to-prevent-surveillance-exports-to-rights
- CISA KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Palo Alto Networks CVE-2026-0300 advisory: https://security.paloaltonetworks.com/CVE-2026-0300
- Council of the EU AI Act provisional agreement (May 7): https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/
- Microsoft Security Blog on Dirty Frag (May 8): https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/
- Citizen Lab "Bad Connection" (April 23): https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/
- TechCrunch on Paragon non-cooperation (April 28): https://techcrunch.com/2026/04/28/paragon-is-not-collaborating-with-italian-authorities-probing-spyware-attacks-report-says/
- Securelist on ForumTroll / Dante: https://securelist.com/forumtroll-apt-hacking-team-dante-spyware/117851/
- CNN on Canvas / Instructure (May 7): https://www.cnn.com/2026/05/07/us/canvas-hack-strands-college-students-finals-week
- TIME on Canvas / Instructure (May 8): https://time.com/article/2026/05/08/canvas-cyber-attack-shinyhunters-hack-what-to-know/
- KrebsOnSecurity on Canvas
- Foxconn / Nitrogen ransomware (May 12)
- BleepingComputer on Dirty Frag (May 7)
- ECB Digital Euro PSP application call: https://www.ecb.europa.eu/euro/digital_euro/applicants/html/index.en.html
- Bartz v. Anthropic settlement: https://anthropiccopyrightsettlement.com/
- TIME on FISC March 17 opinion (April 27): https://time.com/article/2026/04/27/fisa-fbi-spying-surveillance-fisa-court-congress-wyden/
- Iran HRM "Infrastructure of Silence" (May 9)
- HRW Tanzania "Missed Opportunity" (May 5)
- RSF on Burkina Faso Oulon (May 6)
- Pakistan Press Foundation 2025-2026 report
- Internet Society Pulse on Sudan
- Reporters Without Borders Pakistan PECA report
- FIDO Alliance World Passkey Day (May 7) — 5 billion passkeys
- Tor Browser 15.0.13 release notes (May 7)
- CalyxOS Android 16 test build (May 4)
- DeepSeek V4 release (April 22): https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro
- Mistral Medium 3.5 release (April 29)
- Anthropic Claude Cowork GA (May 12)
- OpenAI Deployment Company launch (May 11)
- Trail of Bits / Monero FCMP++ audit (May 11-22)
- TRM Labs on DPRK 76% of 2026 crypto-hack value
- TechRadar / HaveIBeenPwned on ShinyHunters mass-leak (May 6-8)
- DHS hacktivist leak of ICE contractor data (March 2): https://techcrunch.com/2026/03/02/hacktivists-claim-to-have-hacked-homeland-security-to-release-ice-contract-data/
- Jacobin on ICE Project SAFE HAVEN: https://jacobin.com/2026/04/ice-contract-ai-surveillance-immigrants
- Lever News on Edge Ops scrubbed site: https://www.levernews.com/the-ice-surveillance-firm-with-missing-executives-and-phantom-clients/
- BleepingComputer / TheRecord / Krebs on TeamPCP npm "Mini Shai-Hulud" (May 11)