LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host
security

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.

zeroday.news ·

The U.S. Postal Service (USPS) announced late Friday night that it is finalizing new regulations concerning mail-in ballots for federal elections, despite multiple lower court rulings that have blocked the underlying executive order. The move comes as the White House appeals these decisions to the Supreme Court.

The proposed regulations stem from an executive order signed by President Donald Trump in March, which directed the USPS to establish federal standards for mail-in voter eligibility. The USPS stated that while it is finalizing the rules now, it will not implement them until the Supreme Court issues a ruling. However, the agency emphasized the need to proceed with finalization to ensure the changes could be in place for the November 3, 2026, general election.

The U.S. Constitution grants states and Congress the authority to regulate elections, a point highlighted by courts that have struck down the administration's order. The U.S. District Court of Massachusetts, for instance, recently issued a second injunction against the USPS rules in a lawsuit brought by states and voter groups, with Judge Indira Talwani stating that "the executive branch has no authority to regulate elections."

The USPS notice, posted to the Federal Register, indicated that the agency received approximately 200,000 public comments on the proposed rule. While not providing a breakdown of support versus opposition, the notice acknowledged that many supportive comments argued the rules would enhance public confidence and reduce uncertainty regarding voter fraud. The administration and its allies have frequently asserted, without credible evidence, that voter fraud by noncitizens, deceased individuals, and Democrats is widespread. These claims have been repeatedly debunked by courts, post-election audits, and independent experts.

Comments in opposition to the rule frequently cited the unconstitutionality findings by two courts that had already blocked the White House's order. Concerns were also raised that the USPS might reject ballots from states that do not comply with the new data-entry requirements. The USPS dismissed comments influenced by "partisan political speculation," including those about the order's intent, impact on voter turnout, or potential for voter suppression, labeling them as "speculative" and outside the scope of the proceeding. The agency asserted that the rule is not intended to facilitate voter suppression, affect election outcomes, or target specific demographics or states.

Voting rights organizations swiftly condemned the Friday night announcement, expressing concerns that it could confuse voters about election processes that remain under state jurisdiction. They stressed that for the 2026 election, voters should continue to rely on their state's established voting rules unless and until a court mandates otherwise. The groups urged continued vigilance to maintain trust in the election system amid ongoing efforts to centralize control over elections.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions […]

ai

If you're not using AI to attack your own systems, your adversaries will

Agents are also the new attack surface - cue defenders' existential angst

malware

Hackers infect Android car head units with proxy botnet malware

A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]

security

Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. [...]

security

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

Plus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.

malwarehigh

Malware Hijacks Android Car Head Units

Researchers have identified new Android malware that hijacks car head units by exploiting their official update mechanisms. The malware installs proxy software, turning vehicles into nodes for the BADBOX botnet, primarily for ad fraud and to provide anonymized internet connections. This marks the first documented instance of malware specifically targeting car head units through their native update channels.