View all sources for this day →

The Signal

This limited coverage centers on a high-consequence command-console exposure and an unresolved legal pathway for mail-ballot regulations. The developments differ sharply in operational domain, but each turns on boundaries that are consequential until a fix or court ruling establishes them. [1][2]

Must Know

NASA/JPL spacecraft-command software vulnerability

Vulnerability · Platform

What happened

AIT-GUI, the browser-based operator console in NASA/JPL’s open-source AMMOS Instrument Toolkit, had no authentication, authorization, session checks, or CSRF protection on state-changing endpoints. [1]

The vulnerability is tracked as GHSA-p9r8-2q67-fp86, rated Critical with CVSS 9.4, and fixed in AIT-GUI 2.5.2. [1]

Why it matters

Anyone who could reach the port could issue arbitrary commands through POST /cmd, run server-side scripts through POST /script/run, and execute command sequences through POST /seq. [1]

Postal Service mail-ballot regulations

Policy

What happened

USPS said it is finalizing regulations that would create federally defined eligibility lists for mail-in voting, pursuant to a March executive order. [2]

USPS said it would not implement the regulations until the Supreme Court rules, but must proceed now to have them ready for the 2026 general election. [2]

Why it matters

Multiple lower courts have struck down or blocked the USPS rules, and a Massachusetts judge separately enjoined them; the timing and scope of any Supreme Court ruling remain unclear. [2]

Sources (2)
  1. [1] Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

    securityaffairs · August 22, 2026

  2. [2] Postal Service moves to finalize mail ballot regs before SCOTUS ruling

    cyberscoop · August 22, 2026

Security Daily · August 22, 2026 · Baitaphish