Get tomorrow's brief in your inbox
Today: Mt. Baker Imaging settles data breach class action for $3.3 million. CISA faces $700 million budget cut and one-third staff reduction while Sen. Warner warns of "dangerous underestimation" of cybersecurity threats. GitHub rejected vulnerability reports on design flaws now exploited by supply-chain worm infecting 516 packages and 200+ developer accounts.
Mt. Baker Imaging and Northwest Radiologists Data Breach Settlement
Mt. Baker Imaging and Northwest Radiologists agreed to a $3.3 million class action settlement following a data breach affecting patient information. The settlement provides benefits to individuals whose personal health information was compromised in the breach. Healthcare providers continue to face significant liability exposure from data breaches, with settlement amounts reflecting the sensitive nature of protected health information under HIPAA.
Kroger Agrees to $1.25M Settlement Over Bread Calorie Mislabeling
The Kroger Co. agreed to pay $1.25 million to resolve a false advertising lawsuit brought by California prosecutors. The settlement addresses allegations that Kroger misrepresented calorie counts on several store-brand bread products. This enforcement action demonstrates state attorneys general are actively pursuing false advertising claims under consumer protection statutes, particularly for health-related product labeling.
Haitian TPS Termination Case: Motion to Dismiss Based on New Evidence
Haitian citizens challenged the Trump administration's termination of Temporary Protected Status (TPS), asking the Supreme Court to dismiss the case after discovering that then-Secretary of Homeland Security Kristi Noem's July 1 notice "relied on a knowingly false statement" about consulting with the State Department. New documents obtained by the plaintiffs show Noem had not actually consulted with State as claimed, that the termination decision was based on an unprecedented rationale (national interest rather than country conditions), and that a political appointee issued an eleventh-hour verbal directive overriding career officials' recommendation to extend Haiti's TPS designation. The motion argues the court should send the case back to lower courts for fact-finding rather than rule on the merits while facts continue to unfold.
Supreme Court Declines Review of Tariff Challenge, Paving Way for New Trump Action
The Supreme Court declined to hear HMTX Industries, LLC v. United States, a challenge to tariffs imposed under the 1974 Trade Act. Challengers argued the act does not allow tariffs to be "dramatically ratcheted up" amid a trade war. The justices' refusal to review the lower court ruling upholding China tariffs could embolden the administration to replace emergency tariffs previously invalidated earlier this year. The decision follows the court striking down other Trump tariffs imposed under the International Emergency Economic Powers Act approximately four months ago.
Supreme Court Rejects 98-Year-Old Judge's Suspension Challenge
The Supreme Court refused to take up Judge Pauline Newman's bid to end her suspension from the U.S. Court of Appeals for the Federal Circuit. Newman, who turns 99 on Saturday, was indefinitely prevented from taking new cases after refusing colleagues' demands for mental fitness testing. By rejecting the petition for review, the justices left in place a D.C. Circuit ruling that federal district judges lack authority to hear lawsuits challenging judicial misconduct decisions.
Supreme Court Denies Texas Death Row Inmate's Hypnosis Testimony Appeal
The Supreme Court rejected Charles Flores' effort to force the Texas Court of Criminal Appeals to reconsider his conviction under the Texas "junk science" law. Flores argued his 1999 conviction should be overturned because testimony from a key witness was improperly influenced by hypnosis performed by the investigating police officer. The Texas Court of Criminal Appeals held that Flores failed to meet the law's requirement that new evidence be previously unavailable.
Warner Warns of CISA Budget Cuts and Staffing Gaps
Sen. Mark Warner (D-VA) sent CISA Acting Director Nick Andersen a letter expressing alarm over a $700 million cut to CISA's proposed fiscal year 2027 budget and the elimination of approximately one-third of agency staff. Warner characterized the cuts as a "dangerous underestimation of the threats facing our nation." The letter details widespread staffing shortages, with five of ten CISA regional directors serving in acting capacities, and reports reduced responsiveness to state and local officials. Warner introduced the Guaranteeing Universal Access to Cybersecurity Act to fund the MS-ISAC information sharing and analysis center after former DHS Secretary Kristi Noem stopped federal funding and blocked state and local governments from using federal grants to participate. CISA has been without a permanent director since January 2025, after nominee Sean Plankey withdrew following months of Senate delays.
FBI Raids Ohio Voter Registration Group Offices
The FBI raided the offices of the Ohio Organizing Collaborative, seizing computers and other materials from the Cleveland office. Approximately 25 FBI agents executed warrants that appeared to focus on the group's 2024 voter registration efforts. The group registered more than 100,000 Ohioans in 2024 and was active in organizing against Republican redistricting efforts. Dozens of federal officers from the FBI and HSI conducted home visits to organization members without warrants. The DOJ cited a 2017 case where a canvasser pleaded guilty to fraudulently registering over three dozen people, though no credible accusations of recent registration fraud have been raised since then. Federal law enforcement also seized voter records in Georgia as part of what appears to be belated action against officials who refused to alter 2020 election results.
UK Announces Social Media Ban for Under-16s
UK Prime Minister Keir Starmer announced plans to ban under-16s from social media platforms including Snapchat, TikTok, YouTube, Instagram, Facebook and X, following Australia's model. The UK ban will not apply to YouTube Kids or messaging services like WhatsApp and Signal. Platforms that fail to take reasonable steps to exclude children under 16 face multimillion-dollar fines. Starmer stated the government will go further than Australia by preventing strangers from contacting children on gaming and livestreaming platforms, and considering overnight curfews and breaks in infinite scrolling for those under 18. Enforcement action will target tech companies, not children. More details are expected next month. Australia's ban has been widely criticized as ineffective, with most teens bypassing restrictions and losing access to important communities.
India Temporarily Blocks Telegram Over Medical Exam Cheating Fears
India temporarily blocked access to Telegram nationwide until June 22 ahead of the National Eligibility cum Entrance Test for Undergraduate courses (NEET-UG) rerun. The government also directed Telegram to disable its message-editing feature in India until June 30. Authorities said scammers exploited the editing feature by posting fake exam questions before the test and later replacing them with real questions, making it appear they had leaked the exam in advance. Indian cyber authorities removed a "substantial number" of Telegram channels advertising fraudulent access to leaked papers for up to several thousand dollars. Telegram founder Pavel Durov criticized the ban, stating it "punishes 150 million ordinary Telegram users in India" while the real leaks came from insiders. Telegram challenged the order in New Delhi court, arguing the restrictions are unlawful and disproportionate. The company said it had removed more than 900 links containing illegal NEET-related content and cooperated with authorities.
White House Forced Anthropic to Shut Down AI Models Over Six-Year Trump Grudge
The Trump administration forced Anthropic to shut down Fable 5 and Mythos 5 models not due to genuine security concerns but because Anthropic asked cybersecurity expert Katie Moussouris to review a jailbreak, and the administration considered her a "radical Democrat." White House officials confirmed that the decision was based on optics and Moussouris receiving a shout-out from Chris Krebs, whom Trump fired in 2020 for confirming the election was secure. Moussouris had determined the jailbreak was actually useful for cybersecurity defenders to fix and patch flaws rather than a weaponized tool. The Axios report suggests the real issue was that "Anthropic has not done a great job at trying to speak to the administration and appreciate the ideological differences." Dozens of prominent cybersecurity experts have criticized the shutdown.
Flock Cameras Used for Stalking by Police Officers
Over a dozen cases nationwide involve police officers using the Flock surveillance camera system to illegally and obsessively stalk individuals. Flock automated license plate readers (ALPRs) are deployed in communities across the United States. The cases demonstrate the risks of law enforcement access to persistent surveillance infrastructure without adequate oversight and audit controls.
GitHub Dismissed Security Reports on Flaws Now Exploited by Supply-Chain Worm
GitHub rejected two formal vulnerability reports identifying design flaws that enabled variants of the Shai-Hulud supply-chain worm to infect 516 malicious packages across npm, PyPI, and RubyGems, compromise over 200 developer accounts, and affect more than 3,000 GitHub repositories. Deep Specter Research submitted the reports through GitHub's HackerOne bug disclosure channel. The first report concerned GitHub allowing commit timestamps to be backdated, letting attackers make malicious changes appear as routine edits from years earlier. GitHub responded that commit timestamps are client-supplied metadata by design and the security issue is compromised credentials, not the timestamp feature. The second report addressed commit author impersonation, where attackers freely set author name, photo, and username fields to make malicious commits appear from trusted engineers. GitHub stated arbitrary author metadata is a git property, not a GitHub vulnerability, and pointed to GPG/SSH commit signing and Vigilant Mode as available mitigations. GitHub does record which account actually pushed commits in its Events API, but this data is not displayed on commit pages and expires from public view after 90 days. The worm has been linked to breaches at the European Commission, AI recruiting firm Mercor, the LiteLLM package, GitHub itself, and Red Hat.
Healthcare data breach exposure: Review breach notification procedures, verify business associate agreements are current, ensure patient data encryption at rest and in transit, and conduct breach response tabletop exercises. Mt. Baker Imaging's $3.3 million settlement demonstrates ongoing liability from HIPAA breaches.
Product labeling accuracy: Audit nutrition labels and health claims for accuracy. Kroger's $1.25 million settlement shows state AGs actively pursuing false advertising under consumer protection statutes.
GitHub supply-chain security: Enable GPG/SSH commit signing and Vigilant Mode. Implement code review processes that verify actual pusher accounts. Scan repositories for suspicious timestamp patterns and large obfuscated files. The Shai-Hulud worm compromised 516 packages and 200+ accounts by exploiting GitHub's trust display.
CISA service disruption planning: Organizations relying on CISA vulnerability scans, risk assessments, and incident response should plan for reduced federal support due to $700 million budget cut and one-third staff reduction. Establish relationships with private sector providers and state-level ISACs. Monitor MS-ISAC funding if you participate in state/local critical infrastructure protection.
Surveillance system access controls: Implement audit logs, query pattern review, and supervisory approval for sensitive queries. Over a dozen cases show police officers abusing Flock ALPR systems for stalking. Limit access to legitimate law enforcement purposes with regular oversight.