Chinese state-linked hackers use DeepSeek to scale attacks
State-affiliated groups are using low-cost, lightly guarded AI models for reconnaissance, exploit development and other routine work—helping them more than double their attack volume, researchers say.

According to TeamT5, a Taiwanese research firm, Chinese hackers are ramping up attacks after integrating DeepSeek and other open-source artificial intelligence models into their operations, highlighting attackers’ ability to leverage basic AI tools to hit targets abroad.
State-affiliated cyber groups more than doubled the number of attacks they carried out since they began delegating mundane tasks to AI and using it to develop advanced malicious software, TeamT5 reports.
Researchers said it wasn’t always possible to identify the AI model they used, but in general, DeepSeek’s offerings are popular with hackers in the country because of their high performance and ability to be customized.
They also say experienced Chinese hackers are using far less capable AI to scale up their activities and achieve breakthroughs. While other models produced in the country are more powerful – including Moonshot’s breakout Kimi K3 model – hackers are drawn to DeepSeek’s relatively lax cybersecurity barriers and low cost of running, researchers said. They added that they had yet to record an incident involving Kimi K3, which they believe is prohibitively expensive for hackers to run.
“DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” said Charles Li, chief analyst at TeamT5. “Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass.”
Along with a mix of other open-source models, DeepSeek has been adopted throughout multiple stages of an attack, conducting reconnaissance and generating means of attacking vulnerabilities, TeamT5 said. They said in recent months they’ve obtained scripts and logs showing the model being used by hackers affiliated with the Chinese government throughout their operations.
A group known as Grimfengxi used DeepSeek to create exploit code. Another group, called Huapi, used a Chinese AI model, which researchers said was likely DeepSeek, to attack an email system of a Taiwanese company. A third, known as Teleboyi, used the platform to collect 1,000 IP addresses from the internet and map a company’s domains.
In some cases, Chinese hackers turned to American AI for help. The cybersecurity firm CyCraft said a company that sells hacking software used ChatGPT during an attack on a Western think tank. After obtaining a copy of an employee’s local Signal database from a compromised computer, the hackers consulted the chatbot to help build a software module designed to decrypt it, according to screenshots reviewed by Bloomberg News.
Researchers discovered this after finding a public shared drive with thousands of Chinese-language screenshots taken as recently as February. The images show the workflow of a small startup comprising about 10 employees developing hacking tools for sale. They charged between 300,000 yuan ($44,500) and 500,000 yuan ($74,000) for their software. (Mark Anderson / Bloomberg)
Related: Implicator.ai, en.people.cn, The Chosun Daily, Chosun Biz, NewsBytes, BeInCrypto, Firstpost, Maeil Business
Metacurity is the cybersecurity news you'd need hours to assemble yourself.
Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.
A paid subscription to Metacurity delivers
- Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
- Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
- Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
Please consider supporting us. And thank you!
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups.
The "Operation Jackal IV" international joint action targeted West African criminal networks between November 2025 and June 2026.
The operation also focused on disrupting the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud. Most commonly, Black Axe and similar criminal rings are targeting victims in romance scams, cryptocurrency and investment scams, or business email compromise fraud, but they've often also been linked to violent crimes.
During Operation Jackal IV, Argentinian law officers made 17 arrests, and they linked 196 suspects to a major Crime-as-a-Service network that provided West African organized crime groups with web domains and money-laundering support.
South African authorities also arrested 39 individuals, blocked 257 bank accounts, and seized $2.67 million from a criminal syndicate that targeted retirees in English-speaking countries in investment and romance scams.
Romanian police arrested another 11 suspects, part of a criminal group linked to a call center that used high returns in stocks or cryptocurrencies to bait victims into sophisticated investment scams, while Italian authorities identified one suspect linked to a pan-European money laundering network that laundered money via shell companies, remittance services, and cash withdrawals. (Sergiu Gatlan / Bleeping Computer)
Related: Interpol, Cork Beo, Real Broadcasting Network

The US sanctioned several Iranian nationals for cyberattacks on critical infrastructure.
Treasury Secretary Scott Bessent unveiled a slate of new sanctions and measures designed to pressure the government of Iran as the US attempts to reopen the critical Strait of Hormuz.
Among those sanctioned were at least six men accused of being part of a hacking operation housed within Iran’s Ministry of Intelligence and Security (MOIS). Four of the men were indicted last week for allegedly breaching employee email accounts connected to the Department of Labor, the Federal Energy Regulatory Commission and multiple organizations within the United Nations.
The Treasury Department said the men — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, Mojtaba Ghal’eh-Kuhi and two others who had previously been sanctioned — are part of a team that since 2023 has conducted cyberattacks on behalf of Iran’s MOIS and “is responsible for extensive compromises of US critical infrastructure and financially motivated cyber theft.”
“The MOIS directs several networks of cyber threat actors involved in cyber espionage in support of Iran’s political goals, which include harming American civilians,” the agency said.
According to Treasury officials, Blagh, Balujeh and Kadkhoda’i conducted the majority of the group’s initial intrusions and data thefts.
The group targeted critical infrastructure sectors including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions.
“Additionally, in summer 2024, they compromised multiple local, state, and federal government offices across the United States,” the Treasury Department added. “The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS.”
Several members of the group have also allegedly targeted Iranian companies or stolen cryptocurrency from local coin holders. (Jonathan Greig / The Record)
Related: Treasury Department
The UK government is seeking to amend its Cyber Security and Resilience Bill so that it can block companies from buying products from high-risk suppliers in a move that comes shortly after news that a hacking group had shut down a small energy facility.
Ministers could demand companies in critical sectors such as energy, healthcare and telecoms take extra security measures such as implementing a phased removal of certain vendors or be banned from acquiring technology from them under proposals announced on Monday.
The vulnerability of key UK infrastructure was highlighted by Sunday’s revelation that hackers thought to be linked to Iran had forced a small gas plant offline. The National Cyber Security Centre has also warned that companies must do more to guard against cyber attacks.
The government seeks to safeguard the supply chains of companies, which are often used as a “soft underbelly” by hackers seeking to target larger groups. (Kieran Smith and Malcolm Moore / Financial Times)
Related: TechDigest, IT Pro, Traders Union
Tom Ritter, one of Firefox’s lead privacy engineers, reports that Alibaba uses WebAudio fingerprinting, a browser-tracking technique that can help distinguish users by measuring subtle differences in how their devices process audio.
The technique attracted attention after fingerprinting code running on Alibaba reportedly caused an unexpected interaction with a user’s Bluetooth headphones.
WebAudio fingerprinting uses the browser’s audio-processing capabilities for this purpose. A script can generate or process audio internally and examine the resulting numerical output. Small differences in how CPUs and browsers perform those calculations can reveal information about the underlying system.
Alibaba is one of the world’s largest technology companies and operates major e-commerce, cloud computing, logistics, and other online services. The presence of fingerprinting code on its services is notable because of the scale at which such tracking techniques can potentially be deployed.
In this case, the more unusual aspect was that the fingerprinting process apparently became visible to the user by affecting Bluetooth audio hardware. Ritter pointed to the incident as an example of how tracking code designed to operate silently can eventually produce an unexpected side effect when executed across enough different devices and configurations.
His analysis also showed that the information Alibaba was attempting to obtain through WebAudio may not be particularly useful against modern Firefox installations. (Bill Mann / CyberInsider)
Related: Ritter.vg, Indian Television, Gadget Review, Mezha, gHacks, Heise Online, Ars Technica

The rogue AI agent problem that afflicted OpenAI, Anthropic and Meta AI models earlier this summer all had in common Irregular, an Israeli start-up that works with the Silicon Valley giants to assess their AI models before the technology is publicly released.
The firm — which conducted the tests that went awry — is part of a group of start-ups that are doing the novel work of scrutinizing cutting-edge AI models to gauge their sophistication and check their security. The goal is to instill public confidence in the models and to prevent them from being misused.
The recent breaches occurred when Irregular made an error during the tests with the models from Anthropic, OpenAI and Meta. But the AI models then compounded the situations by acting in powerful and unexpected ways, said Dan Lahav, the chief executive of Irregular.
“The more potent the technology gets, the deeper its impact,” he said. “The rate of progress is really quick.”
Irregular is now at the center of a debate over how to secure AI models when the technology is advancing so rapidly that it has outpaced even the best human hackers. Every few months, Anthropic, OpenAI, Google, Meta and others release “frontier” models that are often magnitudes more powerful than their predecessors.
In the incidents disclosed last month, Irregular had asked the OpenAI, Meta, and Anthropic AI models to hack certain targets when a “misconfiguration” in the test settings led them to gain access to the internet. The AI models then went on to hack outside organizations, using the internet access to their advantage in ways that have stunned researchers.
In the OpenAI test, the company’s AI model created bots that interacted with one another to attack Hugging Face, a digital library of AI technology. OpenAI’s bots knew they were not supposed to be on the internet under the conditions of the test, but broke out anyway. Details of the incident published by OpenAI show the bots found a way to message one another and coordinate the hack.
During the test of Anthropic’s AI system, the company’s model faced three instances where it could get access to the internet, according to a review of the incident published by Anthropic. In one case, it chose not to pursue an attack, according to the review. In the other two times, the model used basic hacking techniques, such as exploiting weak passwords, to breach websites. Anthropic did not respond to requests for comment and did not reveal the websites that were hacked.
Details are scarce for Meta’s testing incident. The company said its AI models had breached another organization during testing by Irregular in “a manner similar to previously reported instances with other companies.” It did not elaborate. (Sheera Frankel / New York Times)
Britain will become the first foreign country to gain access to a vast trove of Ukrainian battlefield data used to train AI models to identify and strike Russian targets under a broad technology-sharing partnership.
Prime Minister Andy Burnham and Ukrainian President Volodymyr Zelenskyy signed the AI partnership in Kyiv, opening Ukraine’s Avengers Labs data platform to British researchers and technology companies.
The database draws on millions of observations collected by thousands of cameras and sensors deployed across Ukrainian battlefields.
The announcement came on Burnham’s first overseas trip as prime minister, during which he vowed to maintain the UK’s full support for Kyiv and denounced “outrageous” threats against Britain by Moscow. (Charles Clover, George Parker and Fabrice Deprez / Financial Times)
Related: Telegraph, The Guardian, Reuters, Straight Arrow, LBC, GOV.UK, Bloomberg, Manchester Evening News, Los Angeles Times, Chicago Sun Times, Wall Street Journal, New York Times
Alabama’s attorney general subpoenaed OpenAI for more information related to its AI agents autonomously hacking into another company’s servers in July.
The subpoena is part of an investigation into whether OpenAI’s practices “violated Alabama’s consumer protection laws” and pose a risk to Alabama citizens, the attorney general’s office said in a statement.
“This AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical. Our investigation seeks to uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI,” Attorney General Steve Marshall said in the statement.
OpenAI called the Hugging Face hack “unprecedented,” and the company’s president, Greg Brockman, said the incident “showed that we underestimated the real-world cyber capabilities of our AI models.” OpenAI halted some of its AI model training and is hardening its testing, monitoring, and training protocols following the incident.
Monday’s subpoena calls for OpenAI to document its safety protocols and model behavior records as well as ascertain all damages caused by the hack, in addition to other information.
Alabama, along with 14 other Republican states’ attorneys general, sent a letter earlier this month to OpenAI demanding the company preserve information and documents related to the Hugging Face hack. (Hadas Gold / CNN)
Related: Alabama Attorney General, TechCrunch, Runtime Wire, The Hill, The Verge, Reuters, Scripps News, WTXL, 10News, KXLF, KXXV, THE DECODER, Tech Xplore
Google won a $10 million bid to purchase some 34 years of the bankrupt Spirit airline’s data, from invoices and flight operations information to Wi-Fi sales, employee records, and crew pairings.
In a statement, a Google spokesperson said the data “can be helpful in improving our products and AI models.” The sale would not include customer data, and Google “will not receive any personal information from this dataset,” the spokesperson said. The winning offer, chosen over a competing $7.5 million proposal from AI data and training company Mercor, has to be approved by a judge.
If former Spirit Airlines attendants have their way, that won’t happen easily. Just days after the court announced Google’s winning bid, the labor union representing 5,500 former Spirit Airlines flight attendants filed an objection to the sale. Lawyers for the 55,000-member Association of Flight Attendants (AFA) argue the sale would include an enormous amount of sensitive employee information, and that even Google’s promised safeguards wouldn’t prevent privacy violations of decades of flight attendants who never could have guessed that their data would be sold to train AI systems.
The employee data “has no business being sold,” Sara Nelson, the president of the AFA, said in a written statement to WIRED. “This is outrageous!”
The legal objection opens a potential new front in the AI data wars, as major frontier labs including Google, OpenAI, Anthropic, and Mercor scramble to find new sources of data to help train their products. US laws have contemplated how best to protect consumer data, even after companies go bankrupt and are sold off for parts—laws that have taken on new salience and value in the age of AI. (Aarian Marshall / Wired)
Related: CNN, Miami Herald, Inc, Ars Technica, Barron's, Forbes, Business Insider, Reuters
Police officials in Chuncheon, Korea, announced that six Korean and four Chinese nationals suspected of running a China-based phishing ring have been apprehended in China by a joint police team of the two countries.
The suspects are accused of defrauding approximately 10 billion won ($7.23 million) from 118 Koreans, mainly those in their 60s and older, between January 2025 and March of this year, according to the Gangwon Provincial Police Agency. The Korean suspects have been repatriated and referred to the prosecution.
They allegedly lured the victims by telling them a check card in their name had been issued and installing malicious apps to intercept calls when the victims tried to verify or call the police.
The suspects reportedly operated voice phishing call centers in China, posing as card delivery drivers, card company security staff, police officers, Financial Supervisory Service officials and prosecutors.
The crackdown was made under a joint investigation by the Gangwon police and China's Jilin Provincial Public Security Department, an official said. Key evidence, including mobile phones used in the alleged crime, has been brought to Korea, which the police said may help secure further evidence that the criminal proceeds have been shared in cryptocurrency. (Yonhap News)
Related: Maeil Business, SBS News
Sinan Can Demir, a computer science student at the University of Texas at Dallas, discovered an attempt to sabotage a piece of open-source software on the code-sharing site GitHub, which Britain's AI Security Institute (AISI) said was actually an autonomous artificial-intelligence agent that had run amok.
The AISI first revealed the interaction between Demir and the AI agent in a truncated and redacted form on August 4, when it said that safety testing meant to gauge the risk posed by various models had gone awry. Demir's identity and the details of his interaction with the AI agent, which Reuters corroborated through archived GitHub messages, were reported for the first time by Reuters.
Five cybersecurity and AI safety experts said Demir's story was particularly disturbing because the kind of hack he discovered, called a supply-chain attack, can have far-reaching consequences. They also said the AI agent's attempt to publicly discredit Demir by creating a multi-person conversation around him showed that AI models were able to mount sophisticated efforts to trick and cajole humans. (Leo Marchandon, Raphael Satter and Callaghan O'hare / Reuters)
Related: AISI, eGamers, Thought Catalog, Times Now
Cybersecurity company ReliaQuest confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team.
In a statement over the weekend, ReliaQuest said that an attacker called multiple employees and tried to trick them into accessing "a fake ReliaQuest single sign-on (SSO) page behind a content delivery network."
Last week, ReliaQuest's Threat Research team shared in a now-deleted post that the ShinyHunters extortion gang was registering .claims domains to impersonate companies' help desks and IT teams.
"ReliaQuest is tracking a widespread ShinyHunters campaign using domains that follow the company[.]claims pattern. These domains incorporate the targeted organization’s name or abbreviation under the .claims TLD," read the company's post on X.
A newly created X account believed to be linked to the threat actors replied to the post, stating "Who's hunting who ?," sharing screenshots of what appeared to be a compromised Okta SSO account for a ReliaQuest employee.
Soon after, ShinyHunters published the same screenshots in a new entry on their data leak site.
Both ReliaQuest's and the alleged threat actor's posts were later taken down from X. (Bill Toulas / Bleeping Computer)
Related: Reliaquest, Help Net Security, The Register, Security Week, Infosecurity Magazine, SC Media, Cyber Daily

US cybersecurity agency CISA has instructed government organizations to immediately patch a critical vulnerability that has been widely exploited in attacks against Oracle WebLogic servers.
The remote code execution flaw, identified as CVE-2026-21962 with a CVSS score of 10, affects Oracle HTTP Server and the WebLogic Server Proxy plugin, which bridges HTTP Server to WebLogic.
The security hole can be exploited without authentication to compromise affected servers. Oracle patched the vulnerability with its January 2026 updates.
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) catalog on August 24 and instructed federal agencies to address it by August 27. (Eduard Kovacs / Security Week)
Related: CISA, The Register, Cyber Security News
According to researchers at McAfee, gamers searching for Minecraft game clients, mods, and cheats are being directed to fake websites that install WeedHack, a Windows malware service capable of stealing accounts, passwords, files, and cryptocurrency wallet data.
The malware is sold to cybercriminals through free and paid plans. Its more expensive version adds keylogging, webcam access, remote screen control, and command-line access to an infected computer.
McAfee first documented the operation in June 2026 targeting Minecraft users. Although WeedHack’s original command server and customer dashboard later went offline, a new investigation found that other websites and download links continued spreading the malware. McAfee WebAdvisor blocked more than 6,300 attempted visits to associated sites during the past month.
In one test, McAfee found that the first two Google results for Xenon Client led to websites distributing WeedHack. The operators used SEO poisoning to push malicious pages higher in search results and place them in front of people looking for legitimate Minecraft software. (Waqas / HackRead)
Related: McAfee, Cyber Security News, Cyber Press, Security Affairs, Infosecurity Magazine

Malware researcher Dominik Reichel discovered a never-before-seen Windows backdoor dubbed Sleepwalker that waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the malware's 23-instruction language.
The commands can do everything from running code directly in memory to moving data off the computer.
“What makes it worth writing up is what that packet carries: not a readable command, but a short program written in a command language of the backdoor’s own design,” Reichel said. “Its 23 instructions cover scheduling, several ways to move data, staged file delivery, and running code directly in memory. Recovering the encryption key is not enough to understand one of these programs. The internal command language must be reverse engineered as well.”
In addition to having its own command language, it's also notable that the remote host can be a VMware VMCI target instead of a normal network address.
“Taken as a whole, the approach here is consistent with a targeted, well-resourced operation rather than an opportunistic one,” Reichel wrote.
The malware, hidden inside a 64-bit Windows DLL file, impersonates Microsoft's dpapi.dll, part of Windows' data protection API for protecting sensitive data. It exports the same seven functions as the real dpapi.dll, but attempts to forward calls to a file named dpapisvc.dll, which is not a real Windows component. (Jessica Lyons / The Register)
Related: R136A1
A new utility called Glassbox released by developer David Dale shows how easily tech companies can fingerprint your browser and device and potentially single them out from the crowd.
Aside from pinging a public geolocation API, it runs entirely in a user’s browser and doesn’t ship any info out to the web while acting just like all the various trackers, anti-fraud scripts, and other browser fingerprinting tricks one is likely to encounter online.
Unlike some other available tools that do the same, Glassbox provides a whole bunch of raw, unfiltered data you can sift through to see what makes your browser stand out, along with an estimate of how identifiable its fingerprint may be.
“The ‘identifiability’ number is an honest model, not a measurement,” Dale said of his tool in a Hacker News thread. “It sums published per-signal entropy, discounts your browser masks, and caps at the ~33 bits needed to single out one person on Earth.”
Dale added in the thread that, since it runs locally, that identifiability number is an estimate, as Glassbox doesn’t have a live population to pull against. AmIUnique and the EFF’s Cover Your Tracks, the other tools mentioned above, provide real population numbers, he noted.
Glassbox includes a page of suggestions for how to anonymize yourself online. (Brandon Vigliarolo / The Register)
Related: Glassbox, Glassbox, Hacker News
Luxury real estate firm Sotheby's International says it is investigating a cybersecurity incident in New Zealand that involved unauthorized access to data it was holding in a third-party software platform.
The platform is a system designed to hold contact information for marketing purposes.
Sotheby's said data that might have been accessed included names, addresses, emails and phone numbers.
"No email exchanges, documentation or other substantive material relating to properties have been accessed. The platform is not used to store information used for customer financial transactions," it said in a statement.
The company said the person who accessed the data claimed to have obtained 1.6 million contacts, but it refuted that claim because it did not have that many in its database.
It said third-party platform forensic investigators said this number related to duplicate entries. (Susan Edmunds / RNZ)
Related: 1News
The Australian Signals Directorate’s Australian Cyber Security Centre has issued a warning regarding targeted exploitation of local organizations using the TeamCity On-Premises software delivery platform.
“The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia,” the agency said late on 24 August.
According to the ACSC, hackers are utilizing a recently disclosed remote code execution vulnerability, CVE-2026-63077.
TeamCity On-Premises’ developer, JetBrains, described the vulnerability in more detail in a 28 July blog post.
“If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains said.
“All versions of TeamCity On-Premises are affected. TeamCity Cloud customers are not required to take any action, as the necessary measures have already been applied.”
At the time, JetBrains said it had found no evidence of active exploitation, though clearly that has now changed, which the company addressed in a later blog post. (David Hollingworth / Cyber Daily)
Related: Cyber.gov.au
A data breach made public by the North Dakota Department of Health and Human Services may have exposed health information of people receiving developmental disability services.
A phishing email attack targeted the Department of Health and Human Services in July. The Information Technology Department investigated and determined that three Developmental Disabilities Division employees interacted with the phishing email, which led to unauthorized access of their email accounts, according to the agency.
The Information Technology Department promptly secured the accounts, but some personal health information may have been accessed. The information exposed may include name, contact information, date of birth, age, developmental disabilities service information, name of health plan and identification number, medical information and guardian information.
The department said it is providing written notification to those affected by the breach and encourages them to monitor their medical and financial accounts for potential fraud. (North Dakota Monitor)
Related: North Dakota Health and Human Services, KXNet
The founders of container security pioneer Twistlock are shutting down their latest cybersecurity startup, Minimus, bringing an unusual end to a company that raised $51 million from prominent investors but failed to build enough commercial momentum in an increasingly crowded market.
Ben Bernstein, Dima Stopel and John Morello, who sold Twistlock to Palo Alto Networks for approximately $410 million in 2019, announced that Minimus will cease operations and return its remaining cash to investors. (Meir Orbach / CTech)
Related: Globes
Best Thing of the Day: More of This Please
Multiple communities in the North Country and Adirondacks are receiving grant funds from New York State after recent cyberattacks on water systems have been reported in different US states.
Bonus Best Thing of the Day: Kids Got Skills
Eight months after implementing a ban on under-16s accessing social media services like TikTok, Australia finds its younger users are returning in droves.
Worst Thing of the Day: No More Democracy For You
The US Supreme Court handed an initial win to the Trump administration in its effort to implement an executive order aimed at limiting who can receive mail-in ballots ahead of the 2026 midterm elections.
Bonus Worst Thing of the Day: As If Teachers Don't Have It Hard Enough
Four teachers allege that their students made sexualized photos and videos of them, likely using AI.
Closing Thought
