Reading view

There are new articles available, click to refresh the page.

Federal judge issues second order blocking Trump mail-in voting directive

A federal judge has issued a second injunction preventing the United States Postal Service from carrying out President Donald Trump’s executive order focused on mail-in voting.

Judge Indira Talwani had previously ruled that the White House order, which would have essentially placed the federal government in charge of deciding which voters in each state would receive mail-in ballots, was unconstitutional.

The order was part of an ongoing lawsuit between the federal government and 23 states over the order’s legality. The Trump administration has formally petitioned the U.S. Supreme Court to review the case and reverse the decision.

In a new ruling issued Tuesday, Talwani’s said the court “finds it prudent to review the EO now, where less than 90 days pend before the midterms and the millions of citizens who rely on mail voting require clarity as to how or whether they will vote in November.”

“As to those elections occurring before or on November 3, 2026, the court preserves the current electoral status quo, grants the Plaintiffs’ Renewed Motion…enjoins the USPS’s implementation of Section 3 of the EO,” Talwani wrote.

The opinion concluded that the states “are likely to succeed on the merits” in claiming that Section 3 of the executive order violates constitutional separation of powers, and noted that the federal government’s “sole attempts to grapple with the actual merits of Plaintiff Organizations’ constitutional challenge are their briefly presented unitary executive arguments.”

But Talwani wrote that whether the president has ultimate authority over USPS actions is irrelevant if it results in a “facially unconstitutional” act.

“Instead, the court need only determine whether the EO is facially unconstitutional based on the substance of the text’s directives,” the opinion said. “The court has already answered and will again resolve the question clearly and affirmatively. The executive branch has no authority to regulate elections.”

The post Federal judge issues second order blocking Trump mail-in voting directive appeared first on CyberScoop.

Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas

Delta Airlines said Tuesday it’s investigating an incident on a Monday flight where a passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network, leading to severe delays and authorities to board the plane once it arrived at its destination.

Various posts on several social media networks went viral early Tuesday detailing the incident, claiming that passengers on Delta flight 591 from Las Vegas to Atlanta used an unidentified device to create a rogue Wi-Fi network that could be used to steal people’s sensitive data or personal information.

Messages from the plane’s Aircraft Communications Addressing and Reporting System (ACARS) show that the crew informed personnel on the ground that a passenger set up a network called “Delta WiFi Fast” and was “trying to scam the other passengers.”

Morgan Durrant, a Delta spokesperson, told CyberScoop that the cabin crew deactivated the aircraft’s WiFi functionality for approximately 30 minutes, the flight’s safety was never in question and no aircraft operating systems were affected.

“We are fully investigating to gather a complete set of facts, which will take time,” Durrant told CyberScoop. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated. We thank our crew for their professionalism and our customers for their understanding.”

The Atlanta office of the FBI, along with the Federal Aviation Administration, said it was aware of the incident, but did not provide further comment. The Transportation Security Administration referred CyberScoop to the FBI. Homeland Security Investigations did not respond to a request for comment.

The incident bears the hallmarks of an “evil twin attack,” where an attacker deploys a rogue Wi-Fi access point that masquerades as a legitimate, trusted network by cloning its name and network settings. Often paired with deauthentication attacks that forcefully disconnect devices from the real network, the fraudulent hotspot tricks nearby laptops and smartphones into automatically connecting to it instead. Once a device connects to the rogue point, an attacker can monitor unencrypted internet traffic, execute man-in-the-middle attacks, or display spoofed login portals designed to harvest sensitive user credentials and personal data.  

The timing of the incident comes as the annual DEF CON cybersecurity conference concluded in Las Vegas on Sunday. The flight, originally scheduled for Sunday, did not leave Las Vegas until 8:30 a.m. Monday.

Monika Hathaway, head of press for DEF CON, told CyberScoop that Delta nor any federal authorities have reached out about the incident. However, she said this year’s conference had trouble with similar attacks.

“Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations,” Hathaway told CyberScoop. “If we had caught them doing this at DEF CON we would have removed and banned them from the conference.”

The post Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas appeared first on CyberScoop.

NIST wants to overhaul its vulnerability database for the AI age

The National Institute for Standards and Technology is looking for input on how to overhaul its vulnerability reporting process to better meet the challenges of an “evolving cybersecurity landscape increasingly shaped by artificial intelligence and machine-consumable security data.”

In a request for information set to publish Wednesday in the Federal Register, NIST said its National Vulnerability Database, one of the primary ways the federal government coordinates with security researchers to identify and fix software vulnerabilities, must be updated for the AI age.

NIST is concerned that as large language models become more capable of finding and exploiting vulnerabilities at scale, the NVD’s process must be updated.

“The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent,” the RFI states.

NIST believes AI hacking tools are contributing to recent trends in vulnerability reporting. The NVD has seen increased volume and complexity of disclosed vulnerabilities, inconsistent data quality, increased reliance on automation and machine-readable security data, and “demand for near real-time vulnerability enrichment” from defenders facing faster threats.But NIST believes these challenges also present an “opportunity to transform the vulnerability management ecosystem” through proactive reforms and NVD innovation.

That’s where the public comes in. NIST is posing a series of questions that must be answered before a larger strategy can be developed. Many of their questions focus on better integrating automation – AI or otherwise – into the process.

The agency asked for insight on how defenders could better leverage automation in the vulnerability reporting process; which capabilities, products and processes would help more quickly disseminate information to stakeholders, how to build transparency and auditability into AI-driven decisionmaking, and what role AI should play in automated vulnerability remediation.

“NIST intends to support a future-ready vulnerability management ecosystem that is continuous, contextual, and automated, while enabling cybersecurity practices to respond appropriately to real-world threats and business priorities,” the RFI states.

The NIST effort to revamp its vulnerability database comes a month after the Trump administration rolled out a new federal clearinghouse, overseen by the Department of Treasury, for sharing AI threat information between government and the private sector called “Gold Eagle.”

It’s not clear how Treasury’s process will interact with NIST’s database. The White House also partnered with Carnegie Mellon’s Software Engineering Institute to create the Vulnerability Information and Coordination Environment, (VINCE) which will collect and distribute reports on AI-discovered vulnerabilities.

The post NIST wants to overhaul its vulnerability database for the AI age appeared first on CyberScoop.

Signal adds an extra layer of security to make sure you're actually chatting with the right person

Signal has introduced a new layer of security to help make sure no one has secretly interfered with your encrypted chats. The chat app is favored by diplomats, activists, and journalists for its security. It uses end-to-end message encryption and “safety numbers” – cryptographic fingerprints associated with the keys securing a conversation – which users can compare to verify they have the expected encrypted connection with a contact. But in theory, someone could still intercept messages by corrupting the centralized directory of accounts and posing as somebody else – a classic "man in the middle" attack. Everything would still be encrypted, just going to the wrong place. To fight this possibility, Signal announced a new feature called Automatic Key Verification (AKV) on Tuesday. From a user perspective, AKV is easy: Tap on a Signal contact’s profile, navigate to the “View Safety Number” screen, and tap on the “Verify automatically” button. It will then show a green checkmark to verify that the contact’s public encryption key matches what Signal’s key transparency system expects. Behind the scenes, however, Signal has developed a new architecture for detecting whether someone has tampered with the public keys associated with an account to intercept messages, as that would require a change to the public encryption key and, in turn, the safety number that a user might not recognize. Ledgers and trees and third parties, oh my! Signal described the new system as serving as a ledger of public keys in which every change a user makes to their information (e.g., linked phone number) leads to a new iteration of the ledger. Accompanying that ledger is an index, allowing Signal users to verify the information in the ledger about themselves or their contacts to make sure it hasn’t been altered by a malicious third party seeking to intercept messages. This ledger lives on an “open-source key transparency server” Signal created for the AKV process, the company said. “When Signal users register, change their phone number or username, or re-create their account, Signal records the changes in a log tree ('the ledger') and facilitates searching through the log tree with prefix trees ('the index books'),” Signal said in the announcement. Digging through an index is hardly automatic, however, so Signal combs the index on the user's behalf to verify the information they’re retrieving about a contact is the most up-to-date. Up-to-date doesn’t mean it’s accurate, however, which is where third-party auditors come in. Cloudflare and security firm Trail of Bits serve as Signal’s AKV third-party auditors, according to the announcement. Their role in the whole thing is to verify that Signal’s own key transparency server isn’t compromised. Per the announcement, third-party auditors check the index to ensure entries don’t appear to have been altered. If those checks come out clear, the auditor signs the response to indicate that the keys being provided are the same for both users, thus eliminating the possibility of a man-in-the-middle attack. Yet again we have a security shortcoming, as auditors can guarantee the index and key transparency server hasn’t been tampered with, but can’t verify the accuracy of the data they contain, which is where the final part of the puzzle comes in: Monitoring. “There are two ways for customers to interact with the ledger: looking up someone else’s address, and looking up their own,” Signal explained. “Monitoring requires Alice and Bob [your usual cryptographic placeholders] to do both of these things on a regular basis, each detecting a different kind of tampering.” Alice and Bob are each able to monitor their own ledger entries via the Signal app, which periodically checks it automatically, and they can verify their connection’s data is correct through the View Safety Number “Verify Automatically” button we mentioned earlier. “These two kinds of monitoring, combined with third-party auditing, form a complete detection system: auditing guarantees that Alice and Bob are looking at the same data, and monitoring guarantees that both of them are regularly checking that data for accuracy,” Signal explained. Security is never simple AKV still ultimately leaves Signal users on the hook for their security: If you want to be truly sure your contact is who they say they are, you’ll need to hit that verify button every time you want to chat. It’s also worth pointing out that this won’t always work for all Signal users. “Your Signal app automatically verifies your own phone number and username data in the log,” the announcement said. “But to verify this for someone else, you need to have their phone number.” In other words, if you don’t have your contact’s phone number through Signal or a matching entry in your phone’s address book, you can’t use AKV to verify the encryption key associated with that contact. AKV can also be disabled for users who don’t want a third party involved in verifying their identity, in which case Signal recommends relying on good old fashioned safety number or QR code verification. Nothing in the cryptographic verification space is ever easy, is it?®

421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one

This is an epic month for Microsoft patches, though not a record-setting one. Redmond addressed 421 bugs in its own products this month - about 200 fewer CVEs than last month, but likely the new norm with AI-assisted vulnerability disclosures and fixes. The big news is that North Korea’s Lazarus Group (and possibly other miscreants) found and attacked one of these flaws as a zero-day in early June. The bug, tracked as CVE-2026-68820, is a use-after-free in the Windows Ancillary Function Driver for WinSock. “A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition,” Redmond warned, adding that successful exploitation could allow an attacker to execute code with SYSTEM-level privileges, and with no user interaction required. Microsoft credited Check Point researchers Moshe Marelus and David Driker with finding and reporting CVE-2026-68820, and the security shop’s threat intel lead told us that his analysts first observed attackers - namely North Korea’s Lazarus Group - battering this CVE at the beginning of June. “We are familiar with one successful implementation of the CVE - but we assume it was used widely in the campaign,” Sergey Shykevich, director of threat intelligence at Check Point, told The Register. He’s talking about Operation Dream Job, a long-running campaign targeting organizations worldwide, especially those in the defense sector, and attributed to Lazarus, an umbrella term for Pyongyang's government-sponsored goons who specialize in cryptocurrency theft, extortion attacks, and IT worker scams. It’s probably best known for the Sony Pictures Entertainment hack in late 2014 and the WannaCry ransomware outbreak in 2017, although the group has been active since at least 2009. Lazarus’ DreamJob campaigns have been around since 2020, and they use social engineering to lure job seekers with fake offers for high-profile positions, then trick the victims into clicking on malicious links or opening malware-laced documents. The goal in these attacks involves stealing IP and other sensitive data, conducting cyber spying missions, and collecting financial information. When Dream Job and Patch Tuesday collide This new wave of attacks focuses on the defense sector in Europe and India with dream jobs impersonating Lockheed Martin and privacy-tech firm Enveil. Attackers created at least three fake Enveil sites, and some even ranked as the top search result, making them even more believable to job seekers - and harder to spot a phish. “In this campaign, the threat actor expanded its delivery method by leveraging impersonation websites and search engine optimization (SEO) techniques to distribute the trojanized applications, increasing its credibility and helping it evade some phishing-based detections,” Check Point researchers said in a Tuesday blog. These attacks involve Lazarus distributing a modified PDF viewer called SecurityPDF designed to execute malicious payloads embedded within attacker-crafted PDF files when the user opens them. The PDFs, when opened, execute a never-before-seen backdoor that Check Point named Troy. And during the intrusions, the Norks exploited CVE-2026-68820 as a zero-day to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit. “We will not be disclosing full technical details of the vulnerability in this article, as it was patched on the August 11 Patch Tuesday fix,” the researchers wrote. “At a high level, the exploit takes advantage of how afd.sys handles a socket is created when it is accessed concurrently by several threads at once.” Shykevich told us that “this campaign shows that this actor continues to develop new tools (like Troy), and finding and implementing new vulnerabilities in Windows to evade detection.” Best of the rest Redmond lists one of the other 421 Microsoft CVEs as publicly known. It’s CVE-2026-62832, an elevation-of-privilege flaw, and the Windows giant says exploitation is “more likely,” so patch this one sooner. “An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive,” according to the security advisory. “Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required.” While CVE-2026-68820 and CVE-2026-62832 are the only vulnerabilities that Microsoft considers “notable” in its August patch cycle, Trend Micro’s Zero Day Initiative highlights five others, including one that came through ZDI’s bug reporting program and another that was successfully exploited at ZDI’s Pwn2Own contest in Berlin. All five of these should be considered notable and exploitable, so give those a read, too. CVE-2026-62893, a critical flaw in Windows Deployment Services TFTP Server that leads to remote code execution without user authentication or user interaction, is the one disclosed through ZDI. “TFTP has no auth mechanism and is available remotely vid UDP port 69,” ZDI bug boss Dustin Childs wrote. “UDP port 69 should be blocked at your perimeter, but this could easily be used by attackers for lateral movement within an enterprise. Again, test and deploy this one quickly if you’re using WDS for deployments in your enterprise.” Meanwhile, CVE-2026-62911, one of the many Exchange bugs in this month’s release, was demonstrated at ZDI’s Pwn2Own in Berlin. It allows a privilege escalation via an authentication bypass, and exploitation would allow an attacker to “take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments,” according to Microsoft, which oddly deemed “exploitation less likely.” Childs calls BS on this. “Ignore Microsoft’s exploitability and Exploit Code Maturity ratings,” he wrote. “We handed them working exploits, so this is a real threat.” ®

DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi

A passenger on a Delta Air Lines flight from Las Vegas to Atlanta after DEF CON is suspected of jamming the in-flight Wi-Fi and broadcasting an unauthorized network in what could amount to a federal offense. It seems like someone forgot the old truism "what happens in Vegas stays in Vegas." News of the incident began circulating late Monday when flight watchers spotted Aircraft Communications Addressing and Reporting System (ACARS) messages from the crew of Delta Flight 591 indicating that something was up with the Wi-Fi and that they suspected a passenger was to blame. “HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX,” the first notice read. Several minutes later, the flight crew followed up with a second message stating they had little additional info at the time, but pointing the blame at “A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS” who “WERE ABLE TO JAM OUR WIFI” and broadcast their own signal. From there, the timeline and truth of the situation get a bit fuzzy, with accounts on social media differing as to what happened next. A poster on X speculated that the culprit was trying to phish for passenger credentials by setting up the fake Wi-Fi network, while a Facebook post shared to Reddit claimed that the incident involved a deauthentication attack that kicked users off the legitimate network before bringing up their own, which included a fake landing page, possibly using a device like a Wi-Fi Pineapple, which can broadcast fake networks, perform deauth attacks, and the like. A commenter in a thread on the Hacking subreddit (linked above) claimed to have been at the terminal in Las Vegas and said the individual was doing the same thing to airport Wi-Fi. The Facebook and X posts both claimed that law enforcement was waiting at the gate, though a post in the Delta subreddit included a comment from someone claiming to have been on the flight who didn’t see any police waiting at the gate. Regardless of what actually transpired once the plane landed, Delta Air Lines confirmed the incident to The Register. “We are fully investigating to gather a complete set of facts, which will take time,” a Delta spokesperson told us in an email. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated.” Delta further noted that the safety of the plane, crew, and passengers was never in question, and no aircraft systems were affected. The airline also told us that there was no hack of any Delta system, including the in-flight Wi-Fi, though it did confirm that an unauthorized Wi-Fi network was broadcast onboard the aircraft for a short period of time. Some of the confusion over the possible deauthentication attack may have come from the cabin crew deactivating the in-flight Wi-Fi for around 30 minutes due to the incident, Delta explained. The airline reiterated that the flight was leaving following the wrap-up of Black Hat and DEF CON, suggesting it suspected an attendee was behind the bad decision. We asked the Atlanta Police’s airport division if it was involved at all, and a representative told us they were unaware of the incident. Atlanta’s Department of Aviation declined to provide any comment on the matter. Based on Delta’s comment, it’s not clear whether the incident involved deliberate interference with authorized Wi-Fi communications, but if investigators determine that it did, the penalties could be severe. According [PDF] to the Federal Communications Commission, intentional Wi-Fi blocking can violate the Communications Act’s section 333. A willful and knowing violation punishable under the Act’s general criminal provision could carry a penalty of up to one year in prison and/or a fine of up to $10,000 upon conviction. If this wannabe hacker with a penchant for choosing the worst possible target in the world is stupid enough to have been caught doing this before (and let’s be frank - if you’re going to try jamming the Wi-Fi on a commercial airplane, you’re not that bright), that prison term could extend to up to two years. ®

❌