Get tomorrow's brief in your inbox
Today: Supreme Court vacated Alabama redistricting ruling eight days before primary, forcing use of maps previously found to violate the Voting Rights Act and Fourteenth Amendment. Congress launched inquiry into surveillance pricing at 25 major retailers including Amazon, Target, and Walmart. Education technology firm Instructure paid ransom to ShinyHunters after breach exposed data from 9,000 Canvas customers.
Instructure Pays Ransom After Canvas Platform Breach
Instructure confirmed it paid ransom to the ShinyHunters cybercriminal group following two intrusions into its Canvas learning management platform. ShinyHunters initially breached the system on May 1, stealing information from 9,000 Instructure customers including names, email addresses, student IDs, and messages between students and professors. On May 7, the group defaced the platform with a ransom message, temporarily shutting down access for millions of students ahead of final exams. Instructure stated the ransom agreement includes data return, digital confirmation of destruction, and a commitment that no customers will be individually extorted. House Homeland Security Committee Chairman Andrew Garbarino announced a congressional investigation, criticizing Instructure's failure to remediate vulnerabilities between the first and second breach. Garbarino requested a briefing by May 21 addressing both intrusions, data volume, containment steps, and coordination with federal law enforcement and CISA.
Federal Prosecutors Drop Election Fraud Charges in Puerto Rico Drugs-for-Votes Scheme
Federal prosecutors in Puerto Rico prepared November 2024 indictments against prison gang members and corrections staff for a drugs-for-votes scheme benefiting then-gubernatorial candidate Jenniffer González-Colón, but supervisors in the U.S. Attorney's Office directed them to exclude voting-related counts. Investigators documented Los Tiburones gang leaders selling drugs to inmates in exchange for votes, threatening violence and withholding drugs to ensure compliance with corrections employees facilitating the scheme. Despite solid evidence and ongoing work to determine campaign involvement, lead prosecutor Jorge Matos was told to halt the investigation after Trump took office. The December indictment charged 34 defendants with drug distribution, money laundering, and firearms possession but included no election fraud charges despite describing the drugs-for-votes scheme. Violating Puerto Rico's vote-buying laws carries fines up to $250,000 and two years imprisonment under 18 U.S.C. § 597.
$870,000 Endue Software Data Breach Settlement
Class action settlement provides up to $2,500 compensation or two years of free credit monitoring for individuals affected by Endue Software data breach.
Supreme Court Vacates Alabama Redistricting Ruling Eight Days Before Primary (Louisiana v. Callais)
The Supreme Court vacated a federal district court ruling blocking Alabama's 2023 congressional map and remanded for reconsideration in light of Louisiana v. Callais. The district court issued a 571-page ruling finding the map violated both the Voting Rights Act and the Fourteenth Amendment's Equal Protection Clause. Justice Sotomayor dissented, noting the majority ignored the constitutional violation. The order came eight days before Alabama's primary election, contradicting the Court's December rationale in the Texas redistricting case where Justice Alito cited voter need for "certainty" months before elections. The Supreme Court previously ruled in 2023 that Alabama's maps violated the Voting Rights Act, leading to the rejected 2023 revision. The Callais decision effectively eliminated Section 2 of the Voting Rights Act as a tool to challenge discriminatory redistricting.
Johnson & Johnson Asbestos Talc Trial
Three families presented evidence at California trial alleging Johnson & Johnson knowingly concealed asbestos risks in talc-based baby powder products for decades. The plaintiffs' relatives died from ovarian cancer allegedly caused by asbestos-contaminated talc products.
BISSELL Defective Steam Cleaner Class Actions
Two class action lawsuits accuse BISSELL of selling defective handheld steam cleaners posing serious burn hazards despite issuing recalls with inadequate remedies.
Hanes Marketing Email Class Action Proceeds
Federal judge ruled class action against Hanesbrands over allegedly misleading marketing emails under Washington state law can proceed.
Yelp Unpaid Boot-Up Time Class Action
Former Yelp employee filed class action alleging the company failed to pay hourly workers for time spent waiting for computers to boot up before shifts, constituting off-the-clock work under wage and hour laws.
FCC Equal Time Rule Enforcement Against ABC (The View Appearance)
The FCC under Chairman Brendan Carr demanded ABC-owned Houston affiliate KTRK file a petition for declaratory ruling explaining why it didn't file equal opportunity paperwork for a February 2 appearance by Texas Democrat James Talarico on The View. KTRK's petition, signed by former Bush-era Solicitor General Paul Clement, argued The View received a bona fide news exemption in 2002 under longstanding FCC interpretations designed to minimize First Amendment problems. The petition stated the FCC's enforcement creates a chilling effect on free speech and violates the First Amendment. The View's exemption has been valid for over 20 years, consistent with FCC policy exempting talk shows since 1984. Evidence suggests the Carr FCC coordinated with right-wing affiliates to manufacture the controversy. The FCC also threatened to pull ABC's eight broadcast licenses over Jimmy Kimmel criticism of the president.
European Union Surveillance Technology Export Controls Failing
Human Rights Watch report documented European companies in Bulgaria, Poland, Finland, Denmark, Estonia, and Czech Republic sold surveillance technology to over two dozen countries with documented human rights abuses despite EU's 2021 updated export rules. France, Greece, Spain, Germany, and Italy refused to share trade records or ignored freedom of information requests. The 2021 regulation expanded the definition of surveillance technology, mandated human rights considerations for customer countries, and created reporting requirements for European Commission review. Bulgaria emerged as top exporter, selling to UAE, Azerbaijan, and other authoritarian regimes. The European Commission plans to evaluate the rules in September 2026.
Copy.Fail Linux Kernel Vulnerability (CVE Pending)
Researchers at Theori disclosed a local privilege escalation vulnerability in the Linux kernel on April 29, 2026 with working proof-of-concept. The vulnerability abuses the kernel crypto API (AF_ALG sockets) and splice() to write four bytes at a time into the page cache of files the attacker does not own. The exploit works unmodified across Ubuntu, RHEL, Debian, SUSE, Amazon Linux, and Fedora without requiring race conditions or distribution-specific offsets.
End-to-End Encrypted RCS Arrives for Apple-Android Messaging
Apple released iOS 26.5 supporting end-to-end encryption for Rich Communication Services (RCS), enabling encrypted conversations between Android and iPhone default messaging apps. Both Apple and Google now support GSMA RCS Universal Profile 3.0, which implements Messaging Layer Security protocol for encryption. Encryption requires carrier support for both RCS and encrypted messages. Neither Google, Apple, nor cellular carriers have access to message contents under the implementation. Metadata collection and storage continues unless users enable Apple's Advanced Data Protection on iOS. Google Messages encrypts message text in backups but not media. RCS end-to-end encryption remains in beta on Apple devices pending carrier rollout and Google Messages updates. Conversations display a lock icon and "Encrypted" label when all parties have compatible software and carrier support.
Meta Eliminates Instagram End-to-End Encrypted DMs
Meta discontinued Instagram's opt-in end-to-end encryption feature, reversing years of public promises to provide encryption across its platforms by default. Meta blamed low adoption, stating "very few people were opting in" despite the four-step optional process few users knew existed. Meta directed users to WhatsApp for encrypted messaging while abandoning encryption development for Instagram and Facebook Messenger group messages. The 2023 Meta announcement promised thoughtful implementation of default end-to-end encryption across Messenger and Instagram DMs, and a 2022 white paper emphasized the importance of trusted private spaces.
Congressional Inquiry Into Surveillance Pricing by Food Retailers
House Energy and Commerce Committee Ranking Member Frank Pallone (D-NJ) launched inquiry into surveillance pricing practices at 25 major food retailers including Albertsons, Stop and Shop, Amazon, Whole Foods, CVS, Target, Walgreens, Walmart, and Wegmans. Pallone's letter demands disclosure of customer data elements used to set prices, whether AI or machine learning algorithms determine pricing, third-party data sources, and customer opt-out availability. The inquiry follows New York's November law requiring companies to disclose AI-based pricing using personal data. Target began posting pop-ups stating prices were "set by an algorithm using your personal data" after the law took effect. FTC's January 2025 report documented businesses charging variable prices based on consumer data including geolocation, demographics, shopping habits, and mouse movement patterns.
Supreme Court True Threats Doctrine Applied to James Comey Indictment
Federal grand jury indicted former FBI Director James Comey under 18 U.S.C. § 871 (threatening the President) and 18 U.S.C. § 875 (interstate threat communications) for May 2025 Instagram post showing seashells spelling "86 47" on North Carolina beach. Indictment alleges the image constituted threat to harm President Trump, citing "86" as mob term meaning "kill him." Prosecution requires proving Comey's speech qualified as "true threat" under First Amendment doctrine. Watts v. United States (1969) established true threats must be distinguished from protected political hyperbole and require contextual analysis including conditional nature and audience reaction. Virginia v. Black (2003) clarified true threats are statements where the speaker means to communicate serious intent to harm. Legal analysts identified First Amendment hurdles for the prosecution given ambiguous nature of the post.
Guarantee Clause as Post-Callais Redistricting Tool
Following Louisiana v. Callais gutting of Voting Rights Act Section 2, legal scholars propose using the Constitution's Guarantee Clause as alternative tool to combat partisan and racial gerrymandering. The Guarantee Clause requires the United States to guarantee each state a "Republican Form of Government." Rucho v. Common Cause (2019) held extreme partisan gerrymandering is nonjusticiable political question but acknowledged Congress can regulate congressional districting under the Elections Clause. Rucho explicitly stated the Court was not condoning excessive partisan gerrymandering and recognized states can address it independently. The Guarantee Clause provides potential framework for challenging redistricting that eliminates meaningful minority representation and undermines multiracial democracy. Congress retains authority under Elections Clause to mandate ranked choice voting, multimember districts, or proportional representation for congressional elections.
Educational technology vendors: Conduct incident response capability audits of all third-party platforms with student data access. Update vendor contracts to require breach notification within 24 hours, evidence of vulnerability remediation before service restoration, and contractual liability for ransom payments. Review FERPA compliance implications of vendor data breaches before final exams and enrollment periods.
Retailers using algorithmic pricing: Prepare for state disclosure requirements modeled on New York's AI pricing transparency law. Document all data elements used in pricing algorithms, third-party data sources, and customer opt-out procedures. Audit algorithms for disparate impact under state consumer protection statutes. Retain counsel for anticipated congressional inquiries from House Energy and Commerce Committee.
Linux system administrators: Apply Copy.Fail kernel security updates immediately across all distributions including Ubuntu, RHEL, Debian, SUSE, Amazon Linux, and Fedora. The local privilege escalation vulnerability works unmodified without race conditions. Audit systems for unauthorized privilege escalation and review crypto API usage in containerized environments.
Organizations using Instagram for business communications: Migrate confidential communications to WhatsApp or Signal immediately. Meta eliminated Instagram's end-to-end encryption feature. Update social media policies to prohibit sharing sensitive information via unencrypted Instagram DMs. Review GDPR and CCPA data subject access request procedures for previously encrypted Instagram conversations now accessible to Meta.
Broadcast licensees: Review FCC bona fide news exemptions granted before 2020 and prepare First Amendment defenses for equal time enforcement targeting political commentary. Document exemption history and preserve correspondence showing selective enforcement patterns. Budget for increased legal costs defending against politically motivated license challenges.