Notes on Internet Privacy

Posts and research from the URnetwork team and community.

RSS

Ten Days

Section 702 of the Foreign Intelligence Surveillance Act sunsets June 12, 2026. The Senate adjourned for Memorial Day recess on Friday May 22 and returns Tuesday June 2 — leaving ten calendar days, of which eight are working days, for the chamber to act on §702 reauthorization before the program's authorities expire. The Foreign Intelligence Surveillance Court opinion dated March 17, 2026 — at the center of the negotiated declassification deal that produced the 45-day extension on April 30 — remains classified, the fifteen-day expedited declassification window having lapsed Friday May 15-16 with no Director of National Intelligence or Attorney General action. Senator Ron Wyden's May 19 promise that "I'll have more to say about this next week" arrives Monday May 25, which is Memorial Day. Wyden's earliest in-Senate procedural day is Tuesday June 2 — fourteen calendar days from the May 19 statement, exactly ten days from sunset. Director of National Intelligence Tulsi Gabbard is "working diligently to declassify" per ODNI's May 21 statement; no date is committed. The same Friday the Senate adjourned, Ubiquiti released emergency security updates for three CVSS 10.0 vulnerabilities in UniFi OS affecting approximately 100,000 internet-exposed network gateways; Drupal CVE-2026-9082 was added to CISA's Known Exploited Vulnerabilities catalog with a May 27 federal civilian agency remediation deadline of which one day is Memorial Day; Microsoft Exchange Server's on-premises Outlook Web Access component remains in day 10 today with no permanent patch and the Federal Civilian Executive Branch deadline at May 29; the Megalodon supply-chain attack of May 18 reached its full reporting depth at 5,718 malicious commits across 5,561 GitHub repositories in a six-hour window; the Laravel-Lang supply chain attack ran 700+ malicious versions across Friday and Saturday; the Coinbase Cartel published Panasonic Avionics Corporation and Robinsons Singapore among new victims. The institutional positives ran in parallel: Operation Saffron's sixteen-country takedown of First VPN with 506 user intelligence packets shared and one Ukrainian administrator arrested; Microsoft Digital Crimes Unit's Fox Tempest disruption with 1,000+ certificates revoked; the Kimwolf botnet arrest of 23-year-old Jacob Butler. The recipient-country layer continued accumulating: Iran at Day 86 with the three-tier digital class system charging the general public twelve and a half times the rate of approved professionals for the same bandwidth; Mexico at 37 days to the CURP Biométrica deadline that suspends 127 million unregistered SIMs on July 1; Niger Day 16 of the nine-international-media ban; Burkina Faso Day 19 of the permanent TV5 Monde ban; Tanzania's Commission of Inquiry report on 518 post-election deaths still withheld. Friday the Trail of Bits Monero FCMP++ audit closed; Friday the Zcash NU7 testnet launched; the user-side primitive stack — open clients, open firmware, FIDO2 hardware authentication, censorship-resistant transports, privacy-preserving currencies, local-inference AI, federated identity, self-hosted services, mesh and satellite, post-quantum cryptographic agility — runs continuously on the audit-pipeline architecture. The §702 fight over the next ten days is whether the Senate can see the ruling on a program the executive will not show them. The architecture is the answer that does not require asking. Ten days.

Ten days

The arithmetic is simple.

Friday, May 22, the Senate adjourned for Memorial Day recess. The chamber returns Tuesday, June 2. Section 702 of the Foreign Intelligence Surveillance Act sunsets Friday, June 12.

June 2 to June 12 is ten calendar days. Two of those are weekends. One — June 2 — is the day the chamber gavels back in, traditionally a half-day for procedural votes and committee organization. The effective working window for floor action on §702 reauthorization is approximately eight days.

The 20-day countdown that this publication's Saturday edition documented as "Twenty Days, One Classified Opinion" becomes ten days the moment the Senate's session resumes.

Senator Ron Wyden's May 19 statement promising that "I'll have more to say about this next week" arrives Monday, May 25 — Memorial Day. Wyden's earliest procedural opportunity in chamber is Tuesday, June 2. The interval between Wyden's promised "next week" and the procedural opportunity to act on it is fourteen calendar days.

The Foreign Intelligence Surveillance Court opinion dated March 17, 2026 — the document at the center of the negotiated declassification deal that produced the 45-day extension on April 30 — remains classified. The fifteen-day expedited declassification window lapsed Friday, May 15-16. The Director of National Intelligence has not declassified. The Attorney General has not declassified. Director of National Intelligence Tulsi Gabbard is "working diligently to declassify" per ODNI's May 21 statement to Breitbart. No date is committed.

The reauthorization debate over the next ten working days will be held on a program whose recent court ruling Congress cannot see.

The recess and the deadline that lapsed

The negotiated architecture behind these arithmetic facts is worth naming clearly.

April 20, 2026 was the original Section 702 expiration. The Senate negotiated a 45-day reauthorization extension to June 12 by unanimous consent. The price of Senator Wyden's withdrawn hold — the condition that allowed unanimous-consent passage — was a 15-day expedited declassification window on the March 17 FISC opinion. Senate Intelligence Committee Chair Tom Cotton (R-AR) and Vice Chair Mark Warner (D-VA) wrote a joint letter to the Director of National Intelligence and the Attorney General on May 1 requesting declassification on the agreed timeline.

The 15-day clock ended May 15-16. The opinion remained classified. The administration did not signal a delay. It simply did not act.

The senate calendar from May 19 forward is the operational fact. Memorial Day recess starts Friday May 22. Pro forma session blocks any controversial unanimous-consent request — any single member can object and halt business. The procedural pathway to a §702 mark-up during recess does not exist. The chamber returns Tuesday June 2.

The Wyden "next week" promise, made Tuesday May 19, naturally referred to the working week of May 25-29. Memorial Day on the 25th and recess across the week mean Wyden's earliest in-Senate procedural day is June 2.

The administration's choice not to declassify on the negotiated deadline produced a window inside which the recess takes the §702 oversight conversation out of the chamber entirely. When the Senate returns, the FISC opinion may still be classified, leaving ten days for floor action on a program whose underlying court ruling Congress cannot see.

That is the structural news today.

The skeptic's case

The Memorial Day recess critique deserves engagement on its strongest form.

The strongest version of the case rests on four claims.

One: Memorial Day recess is the normal Senate calendar. Every Senate session pauses for the Memorial Day week. This is not anomalous; it is institutional rhythm.

Two: the 2024 §702 reauthorization worked across the Senate's normal recess calendar. There is precedent for Senate action on §702 cycling around recess. The pattern is not without precedent.

Three: pro forma sessions can in principle accommodate procedural motions; if Senate Intelligence wanted to act, the pathway exists.

Four: the sunset transition mechanics extend authorities through March 31, 2027. The June 12 hard date is a forcing event, not an operational shutdown of the program.

Each of these is the cleanest form of the case. Each has a response.

Response to Claim 1: the framing is not that recess is anomalous. The framing is that the negotiated 15-day declassification window was designed to end before recess so the Senate could consider the FISC ruling during a working period. The deadline structure assumed the executive would comply. The administration's non-compliance with the negotiated deadline interacts with the normal recess to produce an actionable window — the eight working days from June 2 — that is critically short for legislative consideration of a freshly-disclosed court ruling.

Response to Claim 2: 2024 had different circumstances. The 2024 reauthorization debate happened with a different FISC ruling situation. The negotiated 15-day declassification window in the 2026 cycle was a structural lever that 2024 did not have. The lever has lapsed.

Response to Claim 3: pro forma session blocks controversial UC requests. Any single-member objection halts business. The procedural pathway to a Section 702 mark-up during pro forma does not exist. Senate Intelligence Committee leadership has not signaled intent to use any such pathway, and Cotton's silence since May 15 — silence from the chair of the relevant committee, of the administration's own party — is the structural rupture this publication documented Saturday.

Response to Claim 4: the sunset transition clause is a procedural fact, not a defense of the missed declassification deadline. A clean sunset re-opens the architecture for debate; an executive-favorable extension on the administration's terms — without the negotiated declassification — forecloses it. The political weight of letting §702 lapse, even into the transition window, is the lever Wyden is reaching for. The structural choice between "executive forces an extension on its terms" and "Congress lets §702 sunset, transition into March 2027, and reconsider" is the question the ten-day window will resolve.

The skeptic's case is real. The response is structural. The reauthorization turns on whether Congress can see what the court ruled.

What the court found

The substance of the FISC opinion — what Congress wants declassified and what the public still cannot see — is the load-bearing news under the recess countdown.

Reporting that surfaced through the New York Times on April 9 and was characterized in further detail through Brent Skorup's American Prospect piece on May 11 frames the operative finding: the FBI's "filtering tool" used to query Section 702 data ran in a way that U.S.-person queries were not counted, tracked, or audited as required under the recertification's procedural commitments. The Department of Justice became aware of the issue in August 2024. The March 17 FISC opinion approved the program's recertification while documenting concerns about the FBI's query practices.

Wyden's May 19 statement names the specific reported pattern: more than 14,000 U.S.-person communications queried without warrants, including communications of U.S. journalists, members of Congress, and grand jurors. The Skorup conceptual scaffold captures the legal question: whether all FBI queries against the §702 database count toward §702 oversight numbers, or only queries returning information about U.S. persons. The narrower definition has been the IC's historical reporting practice. The broader definition is the operative legal question. The FISC opinion is the operative document on which definition holds.

What the public has been told: the FISC raised concerns about how the FBI runs queries. What the public has not been told: what the court's ruling on that pattern actually says.

That is what classification has held back from the Section 702 reauthorization debate. The ten days from June 2 are the window inside which that ruling either becomes public or remains classified through the sunset vote.

The patch wave

The same Friday the Senate adjourned, the institutional vendor-pipeline layer logged the upper-bound week-on-week tempo this publication has been documenting.

Three CVSS 10.0 UniFi vulnerabilities. Ubiquiti released emergency security updates Friday for three maximum-severity flaws in UniFi OS affecting approximately 100,000 internet-exposed network gateways. The vulnerabilities allow unauthenticated remote code execution against the gateway management plane. UniFi devices are widely deployed at small and mid-sized business networks, prosumer home networks, and edge sites of large enterprise networks. Patches available; deployment cadence depends on operator action.

Drupal CVE-2026-9082 active exploitation. CISA added Drupal CVE-2026-9082 to the Known Exploited Vulnerabilities catalog Friday May 22 with a Federal Civilian Executive Branch remediation deadline of May 27 — Wednesday — of which one day (Monday) is Memorial Day. Mass exploitation observed: approximately 15,000 attempts across 65 countries during the disclosure window. Drupal powers a significant portion of federal and enterprise web infrastructure.

Exchange OWA day 10. Microsoft Exchange Server CVE-2026-42897 — the Outlook Web Access spoofing flaw rooted in cross-site scripting — remains in day 10 of active exploitation with no permanent patch. The Federal Civilian Executive Branch deadline is May 29, five days from today. Microsoft has shipped automatic mitigation only for customers with the Exchange EM Service enabled; manual mitigation steps for everyone else. The vendor patch cycle is trailing the regulator clock for the third consecutive week.

Microsoft Defender twin zero-days. CVE-2026-41091 (Elevation of Privilege) and CVE-2026-45498 (Denial of Service) are both in CISA KEV with a June 3 FCEB deadline — ten days from today. The security tool itself in the federal active-exploitation catalog. Microsoft patches rolling out.

Cisco Secure Workload CVE-2026-20223 — CVSS 10.0. Disclosed Thursday May 21. Out-of-band Cisco PSIRT advisory; emergency patch same day.

Megalodon supply chain attack. The May 18 GitHub supply-chain compromise — first reported earlier in the week and reaching full reporting depth Friday — pushed 5,718 malicious commits across 5,561 GitHub repositories in a six-hour window through compromised maintainer accounts. The attack pattern was an automated commit-spray operation that exploited GitHub Actions workflow tokens. Most repositories affected were small open-source projects; downstream blast radius is the concern.

Laravel-Lang supply chain compromise. Across Friday and Saturday, attackers published 700+ malicious versions of the popular Laravel internationalization package. The attack chain reaches into PHP application dependencies across the Laravel ecosystem. Mitigation requires manual dependency audit at every downstream operator.

Coinbase Cartel publication. Friday May 22 the Coinbase Cartel extortion group published Panasonic Avionics Corporation and Robinsons Singapore among new victims on its dark-web leak portal. The pattern matches the ShinyHunters / Anodot / TeamPCP cadence: SaaS-vendor compromise yielding downstream tenant breaches.

The Friday-Saturday wave is upper-bound, not typical. Three CVSS 10.0 disclosures across two vendors plus active mass exploitation of a fourth federally-mandated CVE plus a 5,718-commit supply chain attack plus the Laravel-Lang 700+ malicious version compromise plus the Coinbase Cartel publication cycle is what an "off-shift weekend" looks like when institutions are weekday-anchored and adversaries are continuous.

The FCEB deadlines this clusters around: Drupal May 27 (with Memorial Day removed), Exchange May 29 (Friday following recess return), Defender June 3 (post-recess). All three remediation windows land inside the ten-day post-recess working period the §702 reauthorization debate is also operating under.

The institutional positives

The institutional architecture is not failing universally this week. Three positives ran in parallel with the patch wave.

Operation Saffron. A sixteen-country law-enforcement coordination operation seized the First VPN service infrastructure, including 33 servers across multiple jurisdictions. Approximately 5,000 user accounts compromised. 506 user intelligence packets shared with national law enforcement agencies via FBI FLASH-20260521-001 (May 21). One Ukrainian administrator arrested. Phobos ransomware-as-a-service operational connection. The takedown is the second VPN-service seizure of 2026 — the legal frame is that the service was a known ransomware affiliate infrastructure, not a privacy tool.

Microsoft Fox Tempest takedown. Tuesday May 19, Microsoft Digital Crimes Unit disrupted a signing-as-a-service criminal operation that had been selling fraudulent code-signing certificates for approximately one year. More than 1,000 fraudulent certificates revoked at takedown. Customers paid $5,000-$9,000 per certificate. Operational connection to Rhysida and Vanilla Tempest ransomware affiliates. Microsoft's seizure orders affected approximately 92 internet domains.

Kimwolf botnet arrest. Krebs on Security broke the story Thursday May 21: 23-year-old Jacob Butler arrested in connection with the Kimwolf botnet that produced the record 30 Tbps DDoS attack of late 2025. Federal indictment unsealed. The Cloudflare-recorded 30 Tbps single-source DDoS event was the largest single-source attack in recorded history.

The institutional architecture produces coordinated takedowns when it operates. The asymmetry is that takedowns require multi-jurisdiction coordination over multi-week or multi-month timelines, while the threat side iterates inside the inter-takedown window. The structural pattern: positives ship slowly through institutional cooperation; failures ship continuously through asymmetric tempo.

The recipient-country layer

The architectural pattern that this publication has been documenting accumulates regardless of the U.S. Senate calendar.

Iran — Day 86. The Internet Pro / commercial-VPN three-tier architecture continues operational. Approved IRGC- and MCI-affiliated professionals receive whitelisted bandwidth at approximately €0.20 per gigabyte. The general public is forced to commercial VPN at approximately €75 per month — roughly 12.5 times the per-bandwidth rate. The framing as "digital apartheid" continues to circulate in international press. Time magazine published a piece this week (May 21) on Iran's internet costs under the "Strait of Hormuz" framing. Cumulative economic damage exceeds $1 billion per Iranian government statistics; the Quincy Institute estimate is closer to $5.2 billion cumulative. The white-internet whitelist tier — for accessing only domestic-state-approved services — remains operational at scale.

Mexico — 37 days to CURP Biométrica. Approximately 127 million mobile phone lines must register face, fingerprint, and iris biometric CURP by June 30 or face suspension July 1. No public registration statistics released this week. Mexican civil society's constitutional challenge continues without an effective stay. Telecom carrier compliance posture remains heterogeneous: AT&T led at 29 percent registration, Bait at 28 percent, Telcel at 19 percent, Movistar at 16 percent per the most recent reported figures. Telcel lost 1.2 million line additions in Q1 2026 — a measurable user-pushback signal in the largest carrier in Latin America.

Russia — Day 39 of ISP VPN-detection enforcement. Per Meduza and Roskomsvoboda continued tracking, the April 15 mandate continues operational at major service providers. 22 of Russia's 30 most popular Android apps now monitor VPN status at the application layer. Telegram remains blocked; MAX state messaging app continues to be pushed. The April update to Telegram disguising traffic as browser traffic continues to be the operational counter for users.

Niger — Day 16. The May 8 Observatoire Nationale de la Communication suspension of nine international media outlets — France 24, Radio France International, Agence France Presse, TV5 Monde, Jeune Afrique, Mediapart, LSI Africa, TF1 Info, and France Afrique Média — remains operative. Niger is the second-worst jailer of journalists in sub-Saharan Africa per the December 1, 2025 Committee to Protect Journalists census.

Burkina Faso — Day 19. The May 5 permanent ban on TV5 Monde remains in effect. RSF's May 6 report documented continued detentions including journalist Atiana Serge Oulon.

Pakistan — PECA 689 cases. Pakistan Press Foundation continues tracking. The April 29 Freedom Network report documented continued press freedom contraction.

Tanzania — Commission of Inquiry report withheld. The April 23 CoI report — 518 dead, including 502 civilians, 16 security personnel, 21 children in post-October-29-2025 election violence — remains withheld from public release. X (Twitter) remains suspended in Tanzania.

Hong Kong — NSL coerced decryption. Hong Kong's national security law now operationalizes coerced decryption against individuals. The architectural property: device-level access to encrypted contents at the lawful-process layer.

Each regime on its own clock. Each pattern accumulating. The common architectural property: intermediary-layer control of the carrier, the platform, the registry, the broadcaster, the device, or the report.

The protocol pipeline

The same Friday the Senate adjourned, the user-side protocol layer shipped two consequential events.

Trail of Bits Monero FCMP++ audit closed Friday May 22. The 11-day engagement (May 12-22) on the FCMP++ 1a/1b production integration in monero-project/monero closed without immediate public findings — standard practice is a 2-6 week post-engagement publication window. The protocol change replaces the 16-decoy ring signature with a full-chain membership proof whose anonymity set is the entire UTXO set, approximately 150 million transaction outputs — approximately a 9.4 million-fold expansion in sender-side anonymity. Mainnet hard fork target H2 2026, contingent on audit-clearance remediation.

Zcash NU7 testnet launched Friday May 22. Shielded Labs activated the testnet for NU7 — the next consensus upgrade after the protocol's prior major changes. The Crosslink Milestone 4 architecture (PoW + BFT finality, Vitalik Buterin's February 6 donation supported the upgrade) continues. The testnet activation is the operational precursor to the mainnet activation expected later in 2026.

Tor Browser 15.0.14 — May 19 release. The standard cadence security release. Tor Project announced crowdfunding for ten internet freedom projects around the same period — sustained donation-funded development of the censorship-resistant transport layer.

Discord DAVE end-to-end encryption. The May 19 default-on rollout to approximately 200 million monthly active users continues to roll out across regions; the largest single-week deployment of E2EE infrastructure to a non-niche user base since Signal's default-on adoption.

Bitcoin BIP352 silent payments — Core 28.0+ adoption. Spring 2026 series continues rolling out. BIP324 v2 encrypted P2P (default-on since Core 27.0) is now the majority of global Bitcoin peer-to-peer traffic.

Signal Sparse Post-Quantum Ratchet (SPQR) + PQXDH + Double Ratchet — the Triple Ratchet. Signal's post-quantum hardening continues iterating.

npm staged publishing — merged May 22. The 2FA-gated publishing pipeline closed a class of maintainer-account-compromise attacks of the kind that produced the Megalodon and Laravel-Lang waves. Package-registry-layer defense against the supply-chain attacks the patch wave column documents.

GrapheneOS monthly releases continue. GrapheneOS 2026050900 (May 9) and the May 4 CalyxOS 7.2.1.0 baseline.

Other ongoing. YubiKey 5.8 firmware. eIDAS 2.0 BBS+ selective disclosure IETF finalization in progress. ML-KEM, ML-DSA, SLH-DSA standards live since August 2024.

The protocol pipeline shipped two major consensus-layer developments (Monero audit close, Zcash NU7 testnet) on the same Friday the Senate adjourned. The user-side primitive stack runs continuously on the audit-pipeline architecture, on the Friday tempo, regardless of the institutional calendar.

The weekend off-shift

The asymmetric pattern this week — patch wave concentrated Friday, recess starting Friday, FCEB deadlines clustered around the post-recess return — is the operational form of a structural property this publication has been naming for several editions.

Institutions are weekday-anchored. Vendor patch cycles, CVE disclosure protocols, federal IT staffing, congressional sessions, regulatory deadlines, court proceedings — all clustered Monday through Friday, with sharp drop-offs over weekends and through holidays. CISA's workforce has been reduced approximately one-third post-government-shutdown; weekend staffing was already minimal and is now critical.

The threat side has no equivalent constraint. Ransomware deployment is weekend-heavy across the industry's tracking data, with the asymmetric exploitation window between Friday's patch-tempo close and Monday's response cycle producing the most-exploited window of the week. The Sysdig PraisonAI CVE-2026-44338 research from this week — 3 hours, 44 minutes from disclosure to working exploit during a weekend window — is one operational data point in the pattern.

The mean-time-to-exploitation versus mean-time-to-remediation gap is widest over weekends. Sunday is the threat side's high-leverage day.

This pattern compounds when institutional schedules close in unusual ways. Memorial Day recess removes a full work week from the §702 reauthorization window. FCEB deadlines for Drupal (May 27) include Memorial Day in the remediation calendar. The post-recess return to chamber on June 2 has only ten calendar days until §702 sunset.

The structural conclusion: the architecture that does not depend on institutional schedule is the one that ships through the asymmetric window without losing tempo.

The architecture that does not depend on schedule

The closing argument is simple.

Congress is in recess. The executive will not declassify. The FCEB clock ticks. The patch wave runs. The supply chain compromises spread. The Megalodon attack pushed 5,718 commits across 5,561 repositories in six hours while the Senate gaveled out.

The user-side primitive stack ran continuously through the same Friday window.

Open clients with user-held keys. Signal, Tuta, Proton, Threema, Briar 1.5.17, Cwtch, Session, Matrix homeserver, Discord DAVE for ~200M MAU. The end-to-end-encrypted layer's defense against server-side data-exfiltration via SaaS supply-chain attacks like Anodot or Megalodon is structural.

Open firmware on user-inspectable chips. GrapheneOS Pixel 6+ Android 16. CalyxOS Android 16. e/OS. LineageOS. OpenWRT. Carrier-layer attack-surface inspection that closed firmware does not allow.

FIDO2 hardware authentication. 5 billion passkeys deployed on FIDO Alliance World Passkey Day May 7. YubiKey 30M+ lifetime shipments. Hardware-bound credentials that replace biometrics in the wake of breaches like NYC Health + Hospitals' 1.8 million fingerprint exposure.

Censorship-resistant transports. Tor Browser 15.0.14 (May 19). URnetwork peer-to-peer overlay. V2Ray VLESS+Reality. Shadowsocks-2022. Trojan. WireGuard with obfsproxy. URnetwork's February 19 MCP server release lets agentic clients establish VPN sessions over the peer-to-peer overlay, abstracting transport from the carrier layer. The overlay does not appear in any public-service operator registry — not in §702, not in Iran's Internet Pro tier, not in Russia's April 15 ISP VPN-detection law.

Privacy-preserving currencies on user-custody primitives. Bitcoin BIP324 v2 default-on encrypted P2P traffic now majority of global Bitcoin. Bitcoin BIP352 silent payments in Core 28.0+. Monero FCMP++ Trail of Bits audit closed Friday — mainnet H2 2026. Zcash Crosslink Milestone 4 / NU7 testnet launched Friday.

Local-inference AI on user-controlled compute. DeepSeek V4 Pro (MIT, browser-runnable). Mistral Medium 3.5. Qwen 3.6 Max Preview. GLM-5.1. OpenAI Privacy Filter (Apache 2.0, browser-runnable via transformers.js + WebGPU). The architectural counter to cloud-hosted services where the third-party log path is the legal-process attack vector.

Federated identity with selective disclosure. W3C Verifiable Credentials 2.0 (Recommendation since May 2025). eIDAS 2.0 BBS+ IETF finalization. Privacy Pass. The Mexican CURP Biométrica threat model.

Self-hosted services. Matrix homeserver. Forgejo. Mailcow. Jitsi. Nextcloud. Mautic. SuiteCRM. Moodle. Open edX. Federation bounds supply-chain blast radius — the DBIR +60 percent supply-chain trend.

Mesh and satellite at the carrier layer. Briar (Bluetooth, Wi-Fi, Tor). Bridgefy. Meshtastic. Reticulum. GoTenna PRO. Starlink. The carrier-independent layer against Iran day 86, Niger day 16, Burkina Faso day 19, Russia day 39.

Cryptographic agility. ML-KEM. ML-DSA. SLH-DSA. Signal Triple Ratchet (Sparse Post-Quantum Ratchet + Double Ratchet + PQXDH). FIPS 140-2 sunset September 21 — 120 days from today. Q-Day target 2029.

Both pipelines ran this week. The institutional layer ran failing — declassification not happening, FCEB deadlines compressed by recess, patch wave at upper-bound tempo. The user-side stack ran shipping — Monero audit closed, Zcash NU7 testnet launched, Tor 15.0.14 released, Discord DAVE rolling out, npm staged publishing merged.

The §702 fight over the next ten days is whether the Senate can see the ruling on a program the executive will not show them. The architecture is the answer that does not require asking.

Ten days.

The Senate returns Tuesday June 2.

The FISC opinion may still be classified.

The user-side primitive stack ships regardless.


URnetwork is a peer-to-peer overlay for censorship-resistant transport. The February 19, 2026 MCP server release lets agentic clients establish VPN sessions over the peer-to-peer overlay, abstracting transport from the carrier layer. URnetwork does not appear in the public-service operator registry of any of the statutes named in this article.

https://ur.io

Further Discussion

Ten Days

**Position.** Section 702 of the Foreign Intelligence Surveillance Act sunsets June 12, 2026. The Senate adjourned for Memorial Day recess on Friday May 22 and returns Tuesday June 2 — leaving exactly ten calendar days, of which approximately eight are working days, for the chamber to act on §702 reauthorization before the program's authorities expire. The Foreign Intelligence Surveillance Court opinion dated March 17, 2026 — the document at the center of the negotiated declassification deal that produced the 45-day extension on April 30 — remains classified. The fifteen-day expedited declassification window lapsed Friday May 15-16 with no Director of National Intelligence or Attorney General action. ODNI told Breitbart May 21 that Director Tulsi Gabbard is "working diligently to declassify" — no date committed. Senator Ron Wyden's May 19 promise that "I'll have more to say about this next week" arrives Monday May 25 — Memorial Day. Wyden's earliest in-Senate procedural day is Tuesday June 2 — fourteen calendar days from the May 19 statement, exactly ten days from sunset. The skeptic's case engages cleanly: Memorial Day recess is the normal Senate calendar, 2024 §702 reauthorization worked across recess, pro forma session can technically accommodate motions, sunset transition mechanics extend authorities through March 31, 2027. The structural responses: the negotiated 15-day declassification window was designed to end before recess so the Senate could consider the FISC ruling during a working period; the administration's non-compliance interacts with the normal recess to produce a critically compressed actionable window; the 2024 cycle did not have the lapsed-declassification structural lever the 2026 cycle had; pro forma session blocks controversial UC requests against any single-member objection; the transition clause is a procedural fact, not a defense of the missed declassification. The reauthorization debate over the next ten working days will be held on a program whose recent court ruling Congress cannot see. The architecture is the answer that does not require asking — the user-side primitive stack that ships continuously through audit-driven open-source community governance, regardless of whether the Senate can see one classified opinion. **Headline candidates.** - Ten Days · The Recess That Becomes Ten Working Days - Memorial Day Becomes Wyden's Next Week - Twenty Days Becomes Ten · The Senate Goes Home - The Recess Pin · The Court Ruling Stays Classified **Kicker.** Ten calendar days from June 2 to June 12. Eight working days. Wyden's "next week" arrives Memorial Day. The Senate returns to ten days and a classified opinion. The architecture is the answer.

Friday Tempo

**Position.** The same Friday May 22 the Senate adjourned for Memorial Day recess, the institutional vendor pipeline logged the upper-bound week-on-week tempo this publication has been documenting. Three CVSS 10.0 UniFi OS vulnerabilities disclosed by Ubiquiti — affecting approximately 100,000 internet-exposed network gateways. Drupal CVE-2026-9082 added to the CISA Known Exploited Vulnerabilities catalog with a May 27 Federal Civilian Executive Branch remediation deadline of which one day is Memorial Day — approximately 15,000 mass-exploitation attempts observed across 65 countries. Microsoft Exchange Server OWA CVE-2026-42897 in day 10 today of active exploitation with no permanent patch and the FCEB deadline at May 29 — five days from today. Microsoft Defender twin zero-days CVE-2026-41091 and CVE-2026-45498 in CISA KEV with a June 3 FCEB deadline post-recess. Cisco Secure Workload CVE-2026-20223 disclosed Thursday at CVSS 10.0. The Megalodon supply-chain attack reached full reporting depth at 5,718 malicious commits across 5,561 GitHub repositories in a six-hour window. The Laravel-Lang supply chain compromise ran 700+ malicious versions across Friday and Saturday. The Coinbase Cartel published Panasonic Avionics Corporation and Robinsons Singapore as new victims on its dark-web leak portal. The institutional positives ran in parallel: Operation Saffron's sixteen-country takedown of First VPN with 506 user intelligence packets shared and a Ukrainian administrator arrested; Microsoft Digital Crimes Unit's Fox Tempest disruption with 1,000+ fraudulent code-signing certificates revoked; the Krebs-broken Kimwolf botnet arrest of 23-year-old Jacob Butler for the record 30 Tbps DDoS attack. The same Friday: the Trail of Bits Monero FCMP++ Trail of Bits audit closed (eleven-day engagement on the protocol change replacing 16-decoy ring signatures with full-chain membership proofs across approximately 150 million UTXO outputs — roughly 9.4 million-fold anonymity-set expansion); the Zcash NU7 testnet launched (Shielded Labs activation of the next consensus upgrade after Crosslink Milestone 4); Tor Browser 15.0.14 (May 19) released with security updates; Discord DAVE end-to-end encryption continued rolling out to approximately 200 million monthly active users; Bitcoin BIP352 silent payments continued adoption in Core 28.0+; npm staged publishing (2FA-gated) merged as defense against the maintainer-account-compromise attack class that produced the Megalodon and Laravel-Lang waves. The recipient-country layer continued accumulating: Iran Day 86 with the three-tier digital class system charging the general public 12.5 times the rate of approved professionals; Mexico 37 days to the CURP Biométrica suspension deadline that would cut 127 million unregistered SIMs on July 1; Niger Day 16 of the nine-international-media ban; Burkina Faso Day 19 of the TV5 Monde permanent ban; Russia Day 39 of the ISP VPN-detection mandate; Tanzania Commission of Inquiry report on 518 post-election deaths still withheld; Hong Kong national security law now operationalizing coerced decryption against individuals. The pattern: institutions are weekday-anchored, the threat side is continuous, the mean-time-to-exploitation versus mean-time-to-remediation gap is widest over weekends, and Sunday is the threat side's high-leverage day. The structural conclusion: the architecture that does not depend on institutional schedule is the one that ships through the asymmetric window without losing tempo. The user-side primitive stack — open clients, open firmware, FIDO2 hardware authentication, censorship-resistant transports, privacy-preserving currencies, local-inference AI, federated identity with selective disclosure, self-hosted services, mesh and satellite, post-quantum cryptographic agility — runs continuously on the audit-pipeline architecture. Both pipelines run. The architecture is the choice. **Headline candidates.** - Friday Tempo · While the Senate Adjourned, the Wave Ran - The Weekend Off-Shift · Why Sunday is the Threat Side's Day - Three CVSS 10s, One Sunset · The Same Friday - The Patch Wave the Recess Compressed **Kicker.** Same Friday: Senate gaveled out. Three CVSS 10s, Drupal active exploitation, Exchange day 10 no patch, Megalodon 5,718 commits in 6 hours, Monero audit closes, Zcash NU7 testnet launches. Both pipelines ran. The architecture is the choice.

Comics

#1Ten Days
#2Friday Tempo