CVE-2026-81578, CVE-2026-82078
Get tomorrow's brief in your inbox
Today: The Trump administration asks the Supreme Court to reinstate its ban on transgender military service members after the D.C. Circuit blocked enforcement. A Northern District of California court permanently enjoins Pete Hegseth's Defense Department from blacklisting Anthropic as a national security risk, finding the designation violated the First Amendment and was retaliatory for Anthropic's refusal to remove AI safety guardrails. American Consumer Credit Counseling and New York City settle major data breach and detention class actions totaling over $21.5 million.
American Consumer Credit Counseling Data Breach Settlement
American Consumer Credit Counseling reached a class action settlement over claims it failed to prevent a 2025 data breach that exposed customer financial and personal information. The settlement resolves allegations that inadequate security controls allowed unauthorized access to sensitive credit counseling records.
Microsoft K-12 Student Data Harvesting Allegations
A Washington state class action alleges Microsoft harvests personal and behavioral data from over one million K-12 students using its educational products, collecting information far beyond what schools need to provide educational services. The lawsuit claims Microsoft's data practices violate student privacy protections under state and federal law.
PaperCut Print Management Software Under Active Exploitation (CVE-2026-82078, CVE-2026-81578)
PaperCut issued emergency patches for vulnerabilities in PaperCut NG and MF print management software currently exploited by cybercriminals. Both vulnerabilities carry severity scores over 8.8. The company confirmed customer incidents and warned that PaperCut servers are targets for ransomware gangs seeking initial access and sensitive document exfiltration. CISA previously warned that K-12 schools face particular exposure to PaperCut vulnerabilities. Iranian state-backed groups exploited similar bugs in 2023.
FCC Expands Political Ad Discount Eligibility, Drawing Commissioner Rebuke
The FCC Media Bureau quietly expanded lowest unit charge (LUC) broadcast advertising discounts to joint fundraising committees and party committees in March 2026, extending benefits historically limited to individual candidates. The change followed the Supreme Court's June 2025 ruling eliminating federal caps on coordinated party expenditures. Democratic Commissioner Anna Gomez condemned the decision as made "behind closed doors" without public comment and in "direct conflict" with the administration's prior Supreme Court position. Senators and House members filed suit in June to block the rule change.
$21.5 Million New York City Central Booking Settlement
New York City reached a $21.5 million class action settlement benefiting individuals detained in Central Booking facilities. The settlement resolves claims regarding conditions and treatment in the detention facilities.
Anthropic Wins Permanent Injunction Against DOD Blacklisting
The Northern District of California issued a permanent injunction and vacated Defense Secretary Pete Hegseth's designation of Anthropic as a supply chain national security risk. The court found the designation violated Anthropic's First Amendment rights by retaliating against the company for publicly refusing to sell the government an AI model without safety guardrails. The court ruled Hegseth's social media posts expressly tied the punishment to Anthropic's "arrogance," "corporate virtue-signaling," and "Silicon Valley ideology," demonstrating the action was designed to punish protected speech on matters of public concern rather than serve legitimate national security purposes. The court also found violations of Fifth Amendment due process and the Administrative Procedure Act, calling the blacklisting "arbitrary and capricious."
Judge Refuses to Dismiss Steve Bannon Contempt Conviction
U.S. District Judge Carl Nichols rejected the Justice Department's request to erase Steve Bannon's criminal conviction for refusing to testify before the January 6 congressional committee. Nichols ruled prosecutors failed to properly explain their motivations for seeking dismissal of Bannon's indictment. The decision came months after the Supreme Court threw out an appellate ruling upholding Bannon's conviction at prosecutors' request. Nichols said the government may renew its dismissal request "in a manner that follows the law."
Driscoll's PFAS Class Action
A new class action alleges Driscoll's failed to disclose that its strawberries marketed as "safe" contain per- and polyfluoroalkyl substances (PFAS), known as "forever chemicals." The lawsuit challenges product labeling and marketing claims in light of PFAS contamination.
U.S. Government Opposes 9/11 Defendants' Plea Agreement Restoration
U.S. Solicitor General D. John Sauer urged the Supreme Court to reject Khalid Sheikh Mohammed's bid to restore plea agreements that would spare him and co-defendants the death penalty. The filings respond to petitions challenging a D.C. Circuit ruling that allowed the Pentagon to withdraw from agreements approved by a Biden administration official in July 2024. Defense Secretary Lloyd Austin canceled the agreements two days after approval, claiming such decisions required his authority. A military judge ruled Austin acted too late because defendants had begun fulfilling obligations, but the D.C. Circuit reversed in July 2025, blocking guilty pleas and allowing the Pentagon's withdrawal.
Meta $17 Billion Child Safety Settlement Creates New Compliance Standard
Meta paid nearly $17 billion to settle child safety claims, effectively establishing compliance standards for social media platforms. The settlement addresses allegations regarding harm to minors from platform features and content recommendation algorithms. The UK expects Meta to match U.S. child safety measures following the settlement.
Brazil Elections: EFF Recommends Privacy Protections as Electoral Integrity Tool
EFF, Access Now, and Data Privacy Brasil issued recommendations to strengthen privacy and data protection safeguards for Brazil's elections. The recommendations emphasize the link between personal data protection violations and electoral integrity challenges, noting how privacy guarantees curb targeted spread of false or manipulative content amplified by AI systems. The organizations stress that political microtargeting uses personal data to create profiles for targeted advertising that can persuade voters, discourage turnout, or raise funds using deliberately misleading information. The recommendations call for greater coordination among oversight institutions, civil society, and digital platforms.
Trump Administration Petitions Supreme Court on Transgender Military Ban
The Trump administration asked the Supreme Court to review whether its ban on transgender military service members violates the Constitution. U.S. Solicitor General D. John Sauer challenged a D.C. Circuit decision that barred enforcement of the ban against service members already in the military, calling it "gravely erroneous" and an "unprecedented intervention into military affairs." The February 2026 Department of Defense policy disqualifies individuals with gender dysphoria or who have undergone medical interventions to treat gender dysphoria. U.S. District Judge Ana Reyes found the ban "soaked in animus" and issued a preliminary injunction in March 2025. Judge Robert Wilkins' D.C. Circuit opinion found "direct evidence" of animus, citing the policy's premise that persons with a "false gender identity" lack "honesty, humility, and integrity." The Solicitor General argues lower courts applied overly stringent "heightened scrutiny" instead of a deferential standard appropriate for military judgments.
Right to Repair State Laws Surge, But Enforcement Remains Nonexistent
Over 50 right-to-repair bills were introduced across 22 states in 2026, including measures addressing wheelchairs (Florida), motorcycles (Missouri), and broad protections for devices, aircraft, and construction equipment (Ohio). Iowa passed agricultural equipment legislation in April. Despite Massachusetts, New York, Texas, Minnesota, Colorado, California, Oregon, and Washington passing laws, enforcement remains absent across all states, some approaching four to five years since enactment.
Patch PaperCut immediately: Organizations using PaperCut NG or MF must apply CVE-2026-82078 and CVE-2026-81578 patches, remove servers from public internet, and restrict web access to trusted IPs. K-12 schools face heightened risk per CISA advisory.
Audit educational technology data practices: Schools using Microsoft 365 Education or similar platforms should review Data Processing Agreements, conduct Privacy Impact Assessments, and verify FERPA, COPPA, and state student privacy law compliance in light of the Washington K-12 lawsuit.
Review PFAS testing and labeling: Food manufacturers should test products for PFAS contamination and verify that "safe," "natural," or "clean" marketing claims are accurate given emerging class action litigation patterns.
Prepare for enhanced child safety standards: Social media platforms should review content recommendation algorithms for minors and implement age-appropriate design standards, as Meta's $17 billion settlement establishes new industry baseline requirements likely to be enforced by U.S. and UK regulators.
Enforce right-to-repair compliance: Manufacturers in the eight states with right-to-repair laws should proactively comply with parts availability, repair manual access, and diagnostic tool requirements despite lack of enforcement, as regulatory action or private litigation may eventually materialize.