The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.” The post SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules appeared first on CyberScoop.

The Supreme Court has dismissed one of two injunctions that had blocked the Trump administration's changes to U.S. Postal Service (USPS) regulations concerning mail-in ballots. The 6-3 decision, issued on August 24, 2026, found that the plaintiff states lacked standing to sue because they could not demonstrate concrete harm from the executive order.
The lawsuit was brought by California and 23 other states in response to a White House executive order. This order directed the USPS to create "State Citizenship Lists" for each state, identifying voters eligible for mail-in ballots based on federal data. The order specified that these lists would be updated and sent to states 60 days before an election. It also clarified that an individual's presence on the list did not confirm voter registration or override state laws that might preclude registration.
Two federal courts had previously deemed these provisions unconstitutional, viewing them as an intrusion on states' constitutional authority to manage elections. However, the Supreme Court's conservative majority disagreed, stating that the order was an "internal directive" from the President to executive branch subordinates, and "neither requires nor forbids anything of anyone outside the executive branch." The majority emphasized that the order's provision for transmitting lists was prefaced with "to the extent feasible and consistent with applicable law," making claims of harm by states "entirely speculative" at this stage.
The Court further noted that any actual injury to states would stem from "downstream action that the Secretary might take in the future to implement the USPS sections," highlighting the conditional nature of such actions.
Another section of the executive order directed the Department of Justice (DOJ) to prioritize investigations and prosecutions of state and local election officials who knowingly permit non-citizen voting. The majority characterized this as internal guidance that neither regulated state voter registration nor limited states' authority over election rules. Since it only prioritized enforcement of existing laws, the Court concluded it had no direct impact on states, thus denying them standing to challenge it.
Despite this ruling, the USPS regulations remain blocked under a separate, nationwide injunction issued by a federal court in Massachusetts. The USPS moved to finalize the new regulations on Friday, even with this injunction still in place.
The three liberal justices—Elena Kagan, Sonia Sotomayor, and Ketanji Brown Jackson—issued two dissenting opinions. Justices Sotomayor and Kagan argued that the majority's decision merely "postpones adjudication" and failed to address substantive constitutional questions. They contended that a "commonsense reading" of the executive order, supported by the government's own statements, indicated a "sufficiently concrete and imminent injury" to the states.
Justice Sotomayor expressed skepticism at the majority's view that the sections on USPS state citizenship lists and DOJ prosecutions were unrelated or non-threatening. She wrote that "to pretend that the lists assembled [in one section] bear no relation to the prosecutions directed by [the second section] is to ignore the structure of the Executive Order and the Government’s words alike." She further cited the long-recognized principle that "people do not lightly disregard public officers’ thinly veiled threats to institute criminal proceedings against them if they do not come around."
Justice Jackson, in her separate dissent, was more direct, stating that the District Court had found the President's order unlawful, and the government did not defend its lawfulness before the Supreme Court. She noted that "no judge or Justice has held (or holds today) that the Order comports with the Constitution." Despite this, she observed, the Court granted "equitable relief to proceed with implementing the challenged Order" on the grounds that the plaintiff states lacked a concrete injury for Article III purposes, as a final rule had not been issued when the complaint was filed.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early