CVE-2024-55591, CVE-2025-24472
Get tomorrow's brief in your inbox
Today: Senate Democrats introduced the Water Cyber Shield Act allocating $300 million annually for water system cybersecurity after Iranian-linked attacks on 30 facilities. The FBI and South Korea warned that Gunra ransomware is exploiting Fortinet firewall vulnerabilities (CVE-2024-55591, CVE-2025-24472) to target healthcare, financial services, and government sectors with ransom demands exceeding $10 million. EFF urged dismissal of the LDS Church's trademark lawsuit against the Mormon Stories podcast, arguing the case represents improper use of trademark law to silence criticism.
Gunra Ransomware Targeting Critical Infrastructure
The FBI and South Korea's National Policy Agency issued a joint cybersecurity advisory warning that the Gunra ransomware gang has been breaching critical infrastructure organizations since April 2025 by exploiting CVE-2024-55591 and CVE-2025-24472, two vulnerabilities in Fortinet firewall products. The group targets healthcare, financial services, and government sectors globally with ransom demands exceeding $10 million and 5-7 day payment deadlines. Gunra operates as ransomware-as-a-service and has expanded under new aliases including "Golden Community." Dragos identified 1,140 ransomware incidents affecting industrial organizations in Q2 2026, a 12% increase from Q1.
Keystone RV Class Action Settlement - $2,000 Per Owner
Keystone RV Co. agreed to pay $2,000 to each owner of a Passport Brand Western Edition trailer with serial numbers ending after HX414101 to resolve claims the company misrepresented the materials used to build the trailers. The settlement follows allegations of false advertising regarding construction materials.
CVS Hypoallergenic Wipes Class Action
A new class action lawsuit alleges CVS falsely advertises its toddler cleansing wipes as hypoallergenic despite containing added fragrance, a known allergen. The case challenges product labeling accuracy under consumer protection statutes.
Mercedes-Benz Sunroof Defect Class Action Dismissed
A federal judge dismissed a class action lawsuit against Mercedes-Benz alleging panoramic sunroofs in their vehicles are defective and shatter under normal driving conditions. The court found insufficient evidence to support the defect claims.
Two Class Actions Filed Against Frontier Airlines Over Data Breach
Two new class action lawsuits accuse Frontier Airlines of failing to protect the personal information of thousands of customers and employees in a data breach. The complaints allege negligent data security practices and failure to timely notify affected individuals.
EFF Urges Dismissal of LDS Church Trademark Lawsuit Against Mormon Stories Podcast
EFF filed an amicus brief urging dismissal of the LDS Church's trademark lawsuit against the Mormon Stories podcast, arguing the case represents improper use of trademark law to control criticism and commentary about the church. EFF advocates for application of the Rogers test, a First Amendment safeguard for expressive works, and argues trademark law should not extend to generic terms like "Mormon." The church has a decade-long pattern of using trademark threats against Mormon Match (2014), Mormon Mental Health Association (2016), and Mormon News Roundup podcast (2025).
Water Cyber Shield Act Introduced - $300 Million Annual Funding
Senate Democrats Adam Schiff (D-Calif.) and Amy Klobuchar (D-Minn.) introduced the Water Cyber Shield Act, allocating $300 million annually from Drinking Water and Clean Water State Revolving Funds for water system cybersecurity improvements. The legislation would amend the Safe Drinking Water Act and Clean Water Act to authorize EPA cybersecurity assessments, mandate corrective actions when vulnerabilities are found, require water systems to assess cybersecurity risk as part of resilience planning, and enforce incident reporting under the forthcoming CIRCIA regulations. The bill follows Iranian-linked cyberattacks on at least 30 water and wastewater systems across 12 states and addresses EPA's current lack of authority to institute cybersecurity rules after Biden administration efforts were abandoned following lawsuits from water industry groups and states.
Poland Reveals Hidden Critical Infrastructure Attack on Heat Plant
Poland's CERT disclosed a previously unknown cyberattack on a combined heat and power plant serving 50,000 residents during last winter's cold snap, occurring the same day as coordinated attacks on 30 renewable energy installations formally attributed to Russia's FSB in July. The attack, initially misattributed to contractor error, represents the first known use of a private cellular data network as a pathway into an industrial control system. Attackers moved from compromised wind farm firewalls to a cellular router on a private network, then accessed a heat plant controller running factory-default credentials, conducting 11 days of reconnaissance before disabling Siemens controllers and locking out operators on December 29.
Meta Must Stop Censoring Reproductive Health Information - EFF Tells Oversight Board
EFF submitted a public comment to Meta's Oversight Board regarding censorship of reproductive health information on Instagram, documenting nearly 100 cases where healthcare providers, clinics, educators, and advocates had content removed under Meta's Restricted Goods and Services policy despite not violating stated rules. Meta's moderation systems routinely fail to distinguish between prohibited drug transactions and legitimate discussion of medications, including educational information about mifepristone and prescription drugs during pregnancy. The Miscarriage+Abortion Hotline, Red River Women's Clinic, and RISE reproductive health research center at Emory University all had accounts restricted or posts removed for providing information about legally obtaining medication rather than selling pharmaceuticals. EFF called for five changes: clear policies, consistent enforcement, meaningful explanations for removals, functional appeals that don't require insider access, and expanded human review for nuanced healthcare content.
Supreme Court Jury Size Case - Kian v. Florida
The Supreme Court will confront whether Florida may convict a person of a serious crime with a jury of only six when it hears Kian v. Florida this fall, potentially reconsidering Williams v. Florida (1970), which held that the Sixth Amendment does not require 12-person juries. Justice Thurgood Marshall dissented in Williams, arguing the Court cast aside historical meaning and precedent, and Justice Neil Gorsuch has repeatedly authored dissents urging reconsideration. More than half of U.S. states retained 12-person juries despite Williams allowing six-person panels.
Justice Alito Confirms He Will Not Retire This Term
Justice Samuel Alito told The Wall Street Journal he will not leave the Supreme Court this summer despite calls from conservatives for him to retire while Republicans control the White House and Senate. Alito addressed critiques of partisanship, stating he votes in every case the way he thinks it should be decided regardless of correlation with presidential preferences. The decision ensures the current 6-3 conservative majority remains intact through at least the 2026-2027 term.
Trump Administration Narrows Birthright Citizenship Via Executive Orders
President Trump unveiled two executive orders narrowing birthright citizenship and cracking down on birth tourism schemes. Conservative legal groups plan to make ending birthright citizenship a recurring topic at conferences and law schools, with Article III Project founder Mike Davis stating they "turned birthright citizenship into the next Roe v. Wade, that we're going to have to spend the next 50 years overturning." Courts will test the scope of presidential power following Trump v. Slaughter (June 29, 2026), which struck removal protections for FTC members and expanded presidential authority to fire members of independent boards and commissions at will.
Water System Operators: Prepare for cybersecurity assessment requirements under the proposed Water Cyber Shield Act. Begin voluntary risk assessments now and review incident reporting capabilities to comply with forthcoming CIRCIA obligations. Budget for potential cybersecurity improvements funded through $300 million annual allocation.
Critical Infrastructure - Fortinet Users: Immediately patch CVE-2024-55591 and CVE-2025-24472 to defend against Gunra ransomware exploiting these vulnerabilities. Review firewall access logs for unauthorized privileged access indicators. Prepare incident response plans for ransom demands exceeding $10 million with 5-7 day payment deadlines.
Industrial Control Systems: Change all factory-default credentials on controllers immediately following Poland's disclosure of heat plant compromise via default credentials. Report unexplained operational disruptions, not just confirmed cyberattacks. Treat private cellular networks as potentially compromised pathways requiring the same security controls as public internet connections.
Healthcare Content Publishers: Document all Meta platform content removals involving reproductive health information. Maintain backup patient education channels given Meta's systematic over-enforcement of Restricted Goods and Services policy against legitimate medical information. File appeals immediately and consider whether Meta platforms remain viable for patient education.
Immigration Compliance: Monitor litigation challenging Trump administration birthright citizenship executive orders. Prepare for potential changes to citizenship documentation requirements and update HR policies accordingly as courts test the scope of presidential power following Trump v. Slaughter expansion of removal authority.