Get tomorrow's brief in your inbox
Today: The Supreme Court weighs geofence warrant constitutionality in Chatrie, potentially reshaping digital privacy protections for reverse searches. The FBI warns of Kali365 phishing-as-a-service enabling OAuth token theft to bypass MFA on Microsoft 365 accounts. The European Commission publishes draft guidance on EU AI Act high-risk classification ahead of delayed 2027-2028 compliance deadlines.
CISA Contractor Exposed Credentials to Highly Privileged AWS GovCloud Accounts
A contractor for the Cybersecurity & Infrastructure Security Agency maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and numerous internal CISA systems. Security experts described the public archive as one of the most egregious government data leaks in recent history. The repository included files detailing how CISA builds, tests and deploys software internally.
Canadian Man Arrested for Operating KimWolf DDoS Botnet
Jacob Butler, 23, was arrested in Ottawa on charges of operating the KimWolf botnet after the U.S. Justice Department filed an extradition warrant. The botnet infected over one million devices worldwide, including digital photo frames and web cameras typically behind firewalls. KimWolf was tied to DDoS attacks measured at nearly 30 Terabits per second, a record volume, resulting in financial losses exceeding $1 million for some victims. The botnet issued over 25,000 attack commands and sold access to cybercriminals for DDoS attacks on businesses and Department of Defense IP addresses. Butler was charged with one count of aiding and abetting computer intrusion, facing up to 10 years in prison if convicted.
Meta Settles Kentucky School District Lawsuit Over Addictive Design
Meta settled with Breathitt County School District, the first of at least 1,200 lawsuits brought by school districts against Meta, Snap, YouTube and TikTok for alleged addictive design practices harming students' mental health. The school district had requested more than $60 million to establish a long-term program to combat mental health and academic problems from excessive social media usage. The settlement amount is confidential. Snap, TikTok and YouTube settled late last week. In March, Meta lost two separate jury trials: a California jury awarded $6 million to a girl for social media addiction causing mental health problems, and a New Mexico jury awarded the state $375 million after the attorney general sued claiming Meta threatens children's safety and mental health.
FDA Blocked Publication of Studies Supporting COVID and Shingles Vaccine Safety
The Food and Drug Administration blocked publication of several studies supporting the safety of vaccines against COVID and shingles in recent months. FDA scientists worked with data firms to analyze millions of patient records for the studies, which found side effects of the shots to be rare. In October, scientists were directed to withdraw two COVID shot studies that had been accepted for publication in medical journals. In February, top FDA officials did not sign off on submitting study abstracts on Shingrix (a shingles vaccine) to a drug safety conference. One withdrawn study examined 4.2 million COVID vaccine recipients for 17 conditions including brain swelling, blood clots, stroke and heart attacks, finding rare cases of fever-related seizures and myocarditis. The study concluded "the benefits of vaccination outweigh the risks."
Department of Justice Dismisses Charges Against ICE Protesters After Judicial Revelation of Improper Prosecutorial Conduct
The Department of Justice dismissed charges against four protesters (the "Broadview Four") arising from an incident outside an ICE holding facility in Broadview, Illinois, after a federal judge revealed improper prosecutorial conduct at a May 21 hearing. The case originated from Operation Midway Blitz and reflected the politicization and overreach of federal immigration enforcement under the Trump administration.
$2 Million Alera Group Data Breach Class Action Settlement
Individuals affected by the 2024 Alera Group data breach may qualify for compensation under a $2 million class action settlement.
Roblox Class Action Claims Children Worked 40-Hour Weeks for Little or No Pay
A class action lawsuit alleges Roblox Corporation "deliberately built a multi-billion-dollar empire on the unpaid and underpaid labor of children." The complaint claims children worked 40-hour weeks creating games for little or no pay.
Pfizer Class Action Alleges Website Tracked Users Despite Cookie Opt-Outs
Pfizer faces a class action lawsuit alleging it secretly tracked users' activity on its website and shared their information with third-party advertising and analytics companies despite promising users they could opt out of tracking technologies.
Texas Attorney General Ken Paxton Accused of Forum Shopping in Tylenol Lawsuit
In October, Texas Attorney General Ken Paxton sued pharmaceutical companies Johnson & Johnson, Kenvue Brands and Kenvue Inc. in Panola County, repeating claims that Tylenol was linked to autism and ADHD in children. The case was filed in Panola County (population 23,000, carried by Trump by 67 points), not Austin or large counties with extensive experience handling complex litigation. Defense attorney Kim Bueno accused Paxton's office of forum shopping. ProPublica and The Texas Tribune identified at least 30 cases filed by Paxton over the past nine years with tenuous connection to the counties where they were filed. In a 2017 legal brief, Paxton wrote that forum shopping "has the pernicious effect of reducing confidence in the fairness and neutrality of our Nation's justice system."
Jackson Hewitt and Intuit Accused of Violating Military Lending Act with Excessive Fees
Jackson Hewitt Inc. and Intuit Inc. have each been hit with class action lawsuits over claims they unlawfully extract value from their military customers through excessive fees in violation of the Military Lending Act.
Grubhub Sued Over Wage Theft and Unlawful Facial Scans of Drivers
A class action lawsuit accuses Grubhub of misclassifying delivery drivers as independent contractors while also unlawfully collecting biometric data through facial scans.
EU Commission Publishes Draft Guidance on EU AI Act High-Risk Classification
The European Commission published draft guidance on the classification of "high-risk" AI systems under the EU AI Act, with practical examples of systems that would and would not fall within each category. The draft guidance is open for stakeholder feedback until June 23, 2026, before the Commission adopts the final version. The publication follows a delay to implementation: compliance obligations for stand-alone high-risk AI systems (Annex III) now take effect December 2, 2027 (previously August 2026), and rules for high-risk AI systems embedded in regulated products (Annex I) apply from August 2, 2028. Providers of high-risk AI systems must comply with Chapter III requirements including risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity.
House Democrats Propose Legislation to Address Supreme Court Shadow Docket
Rep. Jamie Raskin (D-MD) unveiled a package of legislation to shine a spotlight on the Supreme Court's shadow docket and demystify the justices' secretive and often unexplained emergency orders. The legislation would require the Supreme Court to issue public legal justification for orders issued from the emergency pool within seven days.
Supreme Court Decision: Actuaries Can Use Up-to-Date Assumptions in ERISA Pension Calculations
In M&K Employee Solutions v. Trustees of the IAM National Pension Fund, a unanimous Supreme Court held that ERISA provisions governing the calculation of withdrawal liability from an underfunded multiemployer pension plan do not require that actuaries use assumptions adopted prior to the measurement date. Justice Ketanji Brown Jackson authored the opinion, concluding that actuarial assumptions are "tools actuaries use to calculate the plan's [unfunded future obligations]" rather than hard data that must be frozen on the measurement date. The statute requires actuaries to make calculations "as of" the measurement date, meaning factual inputs about the plan must be fixed on that date, but actuarial assumptions (like discount rates) can be selected after the measurement date.
FBI Warns of Kali365 Phishing-as-a-Service After April Microsoft 365 Attacks
The FBI published an advisory on Kali365, a Telegram-based Phishing-as-a-Service platform enabling cybercriminals to capture legitimate OAuth tokens and bypass multi-factor authentication (MFA) on Microsoft 365 environments. First seen in April 2026, Kali365 provides AI-generated phishing lures, automated campaign templates, real-time targeted tracking dashboards and OAuth token capture capabilities. Hackers send phishing emails impersonating trusted cloud productivity and document-sharing services containing codes and instructions to visit legitimate Microsoft verification pages. When victims enter the code, they unknowingly authorize the attacker's device to access their account. With the OAuth access and refresh tokens, hackers can access Microsoft 365 services like Outlook, Teams and OneDrive without needing a password or additional verification. Arctic Wolf obtained access to the Kali365 system, finding it offered three tiers ranging from $250 for 30 days to $2,000 for 365 days.
Supreme Court Chatrie Case Could Reshape Digital Privacy for Geofence Warrants
The Supreme Court is weighing whether geofence warrants are legal under the Fourth Amendment in United States v. Chatrie. Geofence warrants direct tech companies to provide the location history of people in a certain area to identify unknown suspects. Petitioner Okello Chatrie was charged with robbery after law enforcement obtained a geofence warrant directed at Google. Google has stated it has been served with geofence warrants covering exceptionally large areas across multiple days. Lawyer Adam Unikowsky argued the case is the first involving digital privacy to hit the Supreme Court since 2018 and could have major implications for other types of police tools involving large amounts of data. Legal scholars believe the ruling could address the constitutionality of reverse keyword searches (police checking which people searched for particular search terms) and reverse AI searches (searching everyone's AI chats for questions probative of whether a person has committed a crime).
France's Hadopi Copyright Enforcement Law Partially Struck Down
La Quadrature du Net, a French digital rights organization, successfully challenged portions of France's Hadopi copyright enforcement system on grounds incompatible with the EU's General Data Protection Regulation and ePrivacy Directive. The French Conseil d'État struck down provisions authorizing the storage of personal data (IP addresses, civil identity and downloaded material) needed for Hadopi's graduated response system. Since its launch in 2010, Hadopi issued 2 million first notices and 200,000 second notices for alleged copyright infringement, but only collected €87,000 in fines while costing French taxpayers €82 million to operate.
Trump Administration's Anti-Weaponization Fund Uses DOJ Settlement Authority for Political Purposes
The Trump administration created a $1.776 billion "Anti-Weaponization Fund" through a settlement in the Trump family's lawsuit against the IRS and Department of Treasury, including a promise of blanket immunity from government liability for President Trump and his family. Legal scholar Aziz Huq explained the fund reflects a broader historical pattern of administrations using federal settlements for political purposes and is a misuse of loosely drafted settlement authority statutes. Huq argued any meaningful remedy will likely require congressional action, as courts may lack a clear path to challenge the fund.
Gun Rights Groups Ask Supreme Court to Block Maryland's Ban on Firearms at Sensitive Places
A coalition of gun rights groups filed a petition for review asking the Supreme Court to block a Maryland law that bars even concealed-carry permit holders from carrying firearms at "sensitive places" such as state parks, museums and mass transit. The groups contend "the heart of the Second Amendment's right to bear arms is personal protection" and that states can abridge that right in locations only when the state itself provides security.
European Governments Shift Away from International Encrypted Messaging Apps
European governments are shifting away from international encrypted messaging apps for domestic platforms where they can maintain sovereign control, according to the Seriously Risky Business cybersecurity newsletter. The shift reflects concerns about reliance on foreign-controlled encryption platforms for government communications.
Geofence warrants and reverse searches: Monitor the Supreme Court's Chatrie ruling for implications on location data retention policies and law enforcement request procedures. The decision will shape Fourth Amendment protections for reverse searches including keyword and AI chat queries.
OAuth token phishing (Kali365): Implement Conditional Access policies restricting OAuth token grants based on device compliance, location and risk signals. Enable alerts for new OAuth token grants, suspicious device registrations and inbox rules configured by third-party apps. Train users on phishing lures impersonating DocuSign, Adobe and SharePoint.
EU AI Act high-risk classification: Providers of AI systems must assess whether their systems fall within high-risk categories based on intended purpose by December 2, 2027. Review product documentation and promotional materials for clarity on intended use cases. Submit feedback on draft guidance by June 23, 2026.
Biometric data collection: Organizations using biometric authentication for workforce management must review state biometric privacy laws (Illinois BIPA, Texas CUBI, Washington HB 1493) for consent and disclosure requirements following the Grubhub lawsuit.
Exposed credentials on public repositories: Organizations with federal contracts should audit all public code repositories for exposed credentials, particularly AWS keys and internal system access tokens. Implement automated secret scanning on all repositories following the CISA contractor leak.