A Federal Judge Could Still Stop This Student Visa Rule Before It Hits Sept 15

A coalition led by NAFSA: Association of International Educators filed a federal lawsuit on August 18, 2026. It seeks to block the Department of Homeland Security’s rule ending Duration of Status for international students. A hearing was held September 3 in Boston. The student visa rule lawsuit argues DHS violated the Administrative Procedure Act. It says DHS failed to properly assess the rule’s costs, respond to public comments, or consider less burdensome alternatives, according to the Presidents’ Alliance on Higher Education and Immigration.

The underlying rule was published July 17, 2026 and is set to take effect September 15. It would end the decades-old system letting F-1 students and J-1 exchange visitors remain in status for the length of their academic program. Instead, it caps their stay at their program’s end date or four years, whichever is shorter, plus a 30-day grace period. That is down from 60 days under the prior rule.

What the student visa rule lawsuit is asking a judge to do

The coalition includes the Presidents’ Alliance alongside other associations and labor unions. It filed a motion for a preliminary injunction alongside the complaint, asking the court to block the rule before its September 15 effective date. US District Judge F. Dennis Saylor IV set an August 31 deadline for the government to respond. He held a hearing on September 3 at the Moakley United States Courthouse in Boston, according to ClinchLaw Immigration News.

As of this writing, the court has not ruled on the injunction request. The September 15 effective date for the rule still officially stands. If the judge grants the injunction, the rule’s implementation would pause while the broader legal challenge proceeds, potentially for months.

The plaintiffs are not limited to a single university or student group. The coalition brings together higher-education associations and labor unions whose members range from research universities to community colleges. That shows how broadly the rule change would reach across US higher education. F-1 and J-1 status touches degree-seeking students, exchange visitors, researchers, and their dependents alike. All would face the same fixed-date tracking requirement under the new rule, replacing the flexible program-length system in place now.

Why students and universities are watching closely

United States federal courthouse where the student visa rule lawsuit was heard

Ending Duration of Status would mark the most significant change to student visa rules in roughly 50 years. Immigration attorneys tracking the litigation say so. Universities have advised international students to review their program end dates and consult designated school officials. A hard four-year cap, combined with a shortened 30-day grace period, leaves far less room for delays or extensions. Transitions to other visa categories also get harder than under the current system.

The lawsuit does not dispute the government’s authority to set immigration policy broadly. It argues specifically that DHS cut corners in the rulemaking process. That is a procedural argument. If it succeeds, the rule would go back for more thorough rulemaking rather than face a permanent bar on any change to Duration of Status.

What happens if the rule proceeds anyway

If no injunction comes before September 15, the rule takes effect as written. F-1 and J-1 holders would then need to track a fixed departure date rather than rely on program length alone. Extensions beyond the four-year cap would require a separate application. Students already in the US when the rule takes effect should fall under transition guidance DHS published alongside the rule. University international offices still have active questions about that guidance’s exact scope.

Large research universities often host thousands of F-1 and J-1 holders at once, giving them more staff capacity to walk students through the practical changes. Smaller colleges with fewer dedicated immigration specialists face a harder task communicating the same information. The uncertainty created by the pending litigation, layered on top of the rule itself, has made planning for the fall term unusually difficult for international offices of every size.

Frequently asked questions

What is the Duration of Status rule change?
A DHS rule set to take effect September 15, 2026. It ends open-ended Duration of Status for F-1 and J-1 visa holders. Instead, it caps their stay at their program length or four years, whichever is shorter, plus a 30-day grace period.

Who filed the lawsuit against it?
A coalition led by NAFSA: Association of International Educators and the Presidents’ Alliance on Higher Education and Immigration filed the complaint on August 18, 2026. Other associations and labor unions joined them.

What does the lawsuit argue?
That DHS violated the Administrative Procedure Act. It says DHS failed to adequately assess the rule’s costs and benefits, respond to public comments, or consider less burdensome alternatives.

Has a judge ruled on blocking the rule?
Not yet as of early September 2026. A hearing was held September 3 in Boston, but the September 15 effective date still officially stands.

How does the grace period change?
The rule shortens the grace period for F-1 students from 60 days to 30 days. That window covers the time to depart, extend, or change status after a program ends or the four-year cap is reached.

Related coverage

Sources

  • Presidents’ Alliance on Higher Education and Immigration — Coalition Files Federal Lawsuit Challenging Rule Ending Duration of Status. presidentsalliance.org
  • ClinchLaw Immigration News — Duration of Status Lawsuit Reaches Critical Juncture. news.clinchlaw.com

Berlin Said No to the Hackers — Then 5.8 Terabytes of Its Files Hit the Dark Web

Hackers published roughly 5.8 terabytes of data stolen from Berlin’s state government on August 28, 2026. City officials had refused to pay a ransom demand that expired that day. The Berlin ransomware city attack exposed more than 5,000 personnel files and payslips. It also exposed fine proceedings, confidential parliamentary committee documents, and vulnerability analyses of Berlin’s drinking water supply, according to Help Net Security.

The Rhysida ransomware group claimed responsibility for the attack. It is believed to operate out of Russia and eastern Europe. The group had demanded 30 bitcoin, worth roughly €2 million ($2.3 million), according to The Hacker News. The same group previously hit the British Museum.

Rhysida follows a clear pattern across its attacks. It breaches a target’s network first. Then it pulls out as much data as it can before detection, and threatens public release on a deadline to force payment. The tactic works because it shifts the cost for victims. A private ransom negotiation becomes a public data-exposure event, carrying reputational and legal consequences well beyond the ransom itself. Berlin’s refusal echoes a stance other European public-sector victims have taken this year. Government bodies increasingly treat paying ransoms as rewarding the tactic rather than resolving it.

How the Berlin ransomware city attack unfolded

The initial data leak happened between August 7 and 12. Affected Berlin departments were not disconnected from the state network until August 14. That gap, roughly seven days, gave the attackers extended access to internal systems. Some of the city’s online services shut down as a direct result, disrupting routine government functions while the network was isolated.

Berlin’s state executive said, as a matter of principle, it would not give in to extortion. It held that position through the deadline. When the deadline passed without payment, Rhysida released the stolen files publicly instead of continuing to hold them privately. That is a common escalation tactic once ransomware negotiations fail.

What was actually exposed

Berlin government building affected by the Berlin ransomware city attack

The released package included about 1.44 million files. Beyond personnel records and payslips, the leak reportedly held confidential parliamentary committee documents. It also held technical vulnerability analyses of the city’s drinking-water infrastructure. That raises concerns beyond privacy, reaching into potential physical infrastructure risk. City officials have not detailed how many residents or employees the personnel-file exposure affects.

Why the seven-day delay matters

Security researchers flag the week-long gap between the initial breach and full network isolation as a critical failure point. It gave Rhysida extra time to locate and extract sensitive files before Berlin cut off access. Ransomware response plans generally call for near-immediate isolation once a breach is detected. The delay will likely be a focus of any post-incident review.

What happens next for Berlin

Berlin’s government has not announced a timeline for restoring all affected online services. It also has not said when it will notify individuals whose personnel data appeared in the leak. Cybersecurity researchers continue analyzing the released files to map the full scope of exposure. That includes checking whether the drinking-water vulnerability data poses an ongoing risk needing separate remediation.

The incident lands amid a broader pattern of ransomware attacks on European public-sector targets this year. City and regional governments prove attractive because they often run older IT systems alongside genuinely sensitive records. Berlin’s stance against paying mirrors guidance from several national cybersecurity agencies across Europe. Those agencies generally discourage ransom payments, arguing they fund further attacks without guaranteeing stolen data is actually deleted. Employees whose personnel files appeared in the leak have limited recourse beyond monitoring for identity theft. The files are already public on the dark web and cannot be recalled.

Berlin’s experience is likely to influence how other German states approach network segmentation going forward. Security consultants typically recommend isolating a breached department immediately, not after a week’s delay. Whether Berlin implements that change before facing another attempt remains an open question the city has not yet addressed publicly.

The 5.8 terabyte figure places this among the larger public-sector leaks reported in Europe this year. Full comparisons are difficult, since not every victim discloses how much was taken. Journalists and researchers with leak-monitoring tools have begun cataloguing the exposed files. That process typically takes weeks, given the sheer volume involved. Standard practice after a leak like this is to watch for phishing attempts referencing personal details only a leaked file would contain. Stolen data is frequently reused in follow-on scams.

Frequently asked questions

What happened in the Berlin ransomware attack?
Hackers linked to the Rhysida group breached Berlin’s state government network in early August 2026 and stole data. They published about 5.8 terabytes of it after the city refused to pay a ransom.

How much ransom did the hackers demand?
Roughly 30 bitcoin, worth about €2 million ($2.3 million).

What data was exposed?
About 1.44 million files. That includes over 5,000 personnel files and payslips, plus fine proceedings, confidential parliamentary documents, and vulnerability analyses of Berlin’s drinking water supply.

Who is behind the attack?
The Rhysida ransomware group, believed to operate from Russia and eastern Europe, claimed responsibility. The group was previously linked to an attack on the British Museum.

Did Berlin pay the ransom?
No. City officials said as a matter of principle they would not pay, and the hackers released the stolen data after the deadline passed.

Related coverage

Sources

  • Help Net Security — Berlin refuses to be blackmailed after network breach. helpnetsecurity.com
  • The Hacker News — Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network. thehackernews.com

Apple’s New Boss Gets One Shot to Prove the Foldable Rumors Were Worth the Wait

Apple holds its “Surprise and Shine” event on September 9, 2026 at 10am Pacific. It is the first product launch under new CEO John Ternus, who succeeded Tim Cook on September 1. The Apple September iPhone event is widely expected to include Apple’s first foldable device alongside iPhone 18 Pro updates, according to Bloomberg.

The event streams from Apple’s website, through the Apple TV app, or on YouTube. Rumors also point to new Apple Watch models and a redesigned AirPods lineup. A preview of a 7-inch smart home hub with a full display may also appear, according to reporting compiled by CNBC.

Why the Apple September iPhone event matters beyond the hardware

This is Ternus’s first public moment leading Apple’s product strategy. Investors and analysts will watch his presentation style as much as the devices themselves. Ternus previously led Apple’s hardware engineering division, which gives him deep technical credibility. But stepping into the keynote role that Cook, and before him Steve Jobs, held for decades is a different kind of test.

The company is positioning 2026 and 2027 as the start of its biggest run of device releases in its history, according to reporting from MacDailyNews. That framing casts the foldable iPhone as the opening move in a multi-year hardware push, not a one-off launch.

Ternus spent years running Apple’s hardware engineering division before moving into the CEO role. He oversaw the physical design and engineering of the iPhone, Mac, and iPad lines. That background gives him direct credibility on the decisions behind a first-generation foldable device, in a way a finance-focused executive might lack. It also raises the stakes. Early competitors struggled with hinge and durability problems on their folding phones. If Apple’s foldable ships with the same flaws, the criticism lands on the executive who spent over a decade solving exactly those engineering problems.

What’s expected to launch on September 9

Smartphone product launch setting related to the Apple September iPhone event

Analysts expect three new iPhone models. That includes the rumored foldable device and updated iPhone 18 Pro variants, plus two new Apple Watch models. Reporting also points to a redesigned Apple TV box and HomePod mini hardware alongside the smart home hub preview. Apple has not officially confirmed any of these products. The company’s own invitations have not detailed specific products, consistent with its usual pre-launch practice.

The foldable iPhone question

Apple resisted the foldable phone category for years while competitors shipped multiple generations of folding devices. A first-generation Apple foldable arrives well after rivals worked through early design problems like screen creasing and hinge durability. That timing could let Apple learn from competitors’ mistakes. Whether that translates into a device that justifies its expected premium price is the open question analysts are watching for on September 9.

What happens after the keynote

When new iPhone models are announced, Apple has historically opened pre-orders within days. Shipping usually begins within two weeks of the keynote. Analysts will watch initial demand signals, especially for any foldable device. That gives an early read on whether Ternus’s first major product bet pays off. Apple’s fiscal Q4 earnings call, typically held in late October, will offer the first hard sales data tied to the launch.

Apple has not commented publicly on any of the rumored products ahead of the keynote. That silence is consistent with its long-standing practice of staying quiet until the stage presentation itself. It leaves outlets like Bloomberg, CNBC, and MacRumors to piece together expectations from supplier relationships and past product cycles, rather than official confirmation. The gap between rumor and confirmation is part of why September 9 matters. It is the first moment analysts, investors, and competitors get a verified account of what Ternus’s Apple actually built, rather than an assembled forecast.

Competitors will also be watching closely. Samsung and other foldable-phone makers have had the category largely to themselves for several product generations, and Apple’s entry could reshape how the broader smartphone market prices and markets folding devices. A strong Apple debut could validate the category for consumers who have been skeptical of folding phones, while a lukewarm reception could reinforce the view that folding screens remain a niche feature rather than the smartphone industry’s next major shift.

Frequently asked questions

When is Apple’s September 2026 event?
September 9, 2026, at 10am Pacific Time (1pm Eastern), streamed on Apple’s website, the Apple TV app, and YouTube.

Is this John Ternus’s first Apple keynote?
Yes. Ternus became Apple’s CEO on September 1, 2026, succeeding Tim Cook, and this event is his first major product launch in the role.

Will Apple launch a foldable iPhone?
It’s widely rumored but not officially confirmed. Reports point to Apple’s first foldable device debuting alongside iPhone 18 Pro updates.

What else might Apple announce?
Rumors point to new Apple Watch models, redesigned AirPods, and a new Apple TV box. A HomePod mini refresh and a preview of a smart home hub with a full display may also appear.

When would new iPhones ship?
Based on Apple’s past pattern, pre-orders typically open within days of the keynote and shipping begins within about two weeks.

Related coverage

Sources

  • Bloomberg — What to Expect at Sept. 9 Apple Event. bloomberg.com
  • CNBC — Apple sets iPhone launch event for Sept. 9, first under new CEO John Ternus. cnbc.com
  • MacDailyNews — Apple’s Ternus era begins September 9th. macdailynews.com

One Cyberattack, 14 Lawsuits: Inside the Insurer That Credit Unions Are Now Suing

TruStage Financial Group now faces at least 14 lawsuits after a cyberattack it disclosed on July 15, 2026. The Madison, Wisconsin insurer sells life and auto coverage through credit unions nationwide. The TruStage outage lawsuits include one filed by a credit union and roughly a dozen more brought by individual policyholders. Most seek class-action status, according to American Banker.

Bessemer System Federal Credit Union in Greenville, Pennsylvania filed the first suit on July 17. It alleges TruStage failed to implement adequate, industry-standard cybersecurity safeguards. The credit union says that failure led directly to the outage and its own financial losses. TruStage shut down its own network to contain the attack. The company still has not determined whether member or employee data was exposed, per CU Today.

What the TruStage outage lawsuits allege

Federal court records reviewed by American Banker show at least 13 of the lawsuits landed in the Western District of Wisconsin, where TruStage is headquartered. The suits generally argue the company failed to protect systems and data to industry standards. They say the resulting outage disrupted payment processing and account access for weeks. Bessemer’s complaint focuses on recovering costs the outage imposed on the credit union’s own operations, not data-exposure damages.

Individual policyholder suits instead center on the risk that personal data was compromised. TruStage has not confirmed a breach of member information. That distinction matters procedurally. Courts often require plaintiffs to show concrete harm, not just risk, before a data-breach class action can proceed.

TruStage is not a small niche vendor. It supplies life insurance, auto coverage, retirement products, and payment protection to a large network of credit unions nationwide. Its outage did not stay contained to one institution’s members. Credit unions that bundle TruStage products directly into member accounts had little room to route around the failure. Their insurance and payment-protection functions were not duplicated anywhere else in their own systems. Plaintiffs’ attorneys point to that structural dependency when arguing the company should have invested more in redundancy and security before the attack.

Weeks of missed payments and frozen funds

Credit union office affected by the TruStage outage lawsuits following the July cyberattack

The outage’s practical impact extended well beyond TruStage’s own systems. CU Today reported that missed payments and frozen funds persisted six weeks after the attack. That affected credit unions relying on TruStage for payment protection and insurance products bundled into member accounts. TruStage has since said its recovery is “gaining ground” but that it has “not reached the finish line.” That is an unusually candid public update for a company facing active litigation.

Why one vendor’s outage hits so many credit unions

TruStage’s business model concentrates risk. It supplies insurance and payment-protection products to a large network of credit unions, rather than operating as one institution’s internal system. When its network went down, the disruption cascaded to every credit union relying on those products. That is part of why the lawsuit count climbed so quickly. Credit unions, unlike large banks, often lack the in-house resources to quickly substitute a failed vendor’s function.

What happens next in the TruStage litigation

The Western District of Wisconsin cases will likely be consolidated for pretrial proceedings, given their overlapping claims. That is a common step in multi-plaintiff data-incident litigation. TruStage has not indicated a settlement timeline. It still has not confirmed whether member data was exposed, a determination that could significantly affect the individual plaintiffs’ claims once resolved.

Insurers generally face separate state reporting obligations once they confirm a cybersecurity incident, obligations that run independent of civil litigation. Those requirements could add regulatory scrutiny on top of whatever the lawsuits eventually produce, though TruStage has not said whether any state insurance regulator has opened a formal inquiry. For now, the credit unions caught in the middle are left absorbing member complaints about an outage they did not cause and cannot fix on their own, since the failure sits inside a shared vendor’s systems rather than their own.

The incident is likely to become a reference point for credit unions evaluating their own vendor risk. Smaller institutions often rely on a handful of outside providers for insurance, payments, and core banking functions. That concentrates risk in a way large banks, with more in-house capacity, typically avoid. Whether the lawsuits change how vendors like TruStage structure their contracts and security spending remains an open question that will likely take the litigation itself to answer.

Frequently asked questions

What is TruStage?
TruStage is a Madison, Wisconsin-based financial group that sells life and auto insurance, retirement accounts, and payment protection products through credit unions.

How many lawsuits has TruStage faced?
At least 14 as of early September 2026, including one from a credit union and roughly a dozen from individual policyholders.

Was member data exposed in the attack?
TruStage has said it has not yet determined whether member or employee data was compromised.

When did the cyberattack happen?
TruStage disclosed the incident publicly on July 15, 2026, after shutting down its own network to contain it.

Where are the lawsuits being heard?
At least 13 of the 14 suits were filed in the US District Court for the Western District of Wisconsin, where TruStage is headquartered.

Related coverage

Sources

  • American Banker — CU vendor TruStage faces 14 suits over monthslong outage. americanbanker.com
  • CU Today — TruStage Says Cyberattack Contained, But Data Answers Could Still Be Months Away. cutoday.info
  • CU Today — Missed Payments, Frozen Funds Persist Six Weeks After TruStage Cyberattack. cutoday.info

Why Washington Just Sanctioned a 31-Year-Old Named Castro

The United States announced new sanctions on September 3, 2026 against five Cuban companies and Fidel Ernesto Castro. He is the 31-year-old grandson of former Cuban leader Raul Castro. The US sanctions Cuban companies action targets Cuba’s state financial and energy sectors. Named entities include Banco Exterior de Cuba and the Cuban Oil Industry Supply Import Company, known as Abapet, according to a State Department fact sheet.

The State Department sanctioned Fidel Ernesto Castro for being an adult family member of other already-sanctioned Castro relatives. The administration has used that designation category repeatedly against relatives of Cuban officials. Secretary of State Marco Rubio said the goal is to dismantle the Castro family’s financial networks, according to UPI.

What the US sanctions Cuban companies action actually blocks

The sanctions freeze any US-linked assets belonging to the designated companies and individual. They also bar Americans from doing business with them. Banco Exterior de Cuba handles a portion of the country’s international financial transactions. Its inclusion is meant to squeeze the channels Cuba uses to move money abroad. Abapet’s designation targets Cuba’s ability to import equipment for its energy sector, which has struggled with chronic blackouts.

Four other Cuban state-linked entities in natural resources and energy were named alongside Abapet. The State Department fact sheet did not attach dollar figures to the economic impact. No independent estimate of the sanctions’ financial effect has been published yet.

Cuba’s energy sector has faced chronic blackouts for years. The problem stems partly from aging infrastructure and partly from difficulty importing fuel and parts under existing sanctions. Targeting Abapet strikes at the supply chain the island uses to keep power plants running. That could deepen blackouts rather than simply squeeze government finances in the abstract. The administration has not said whether it expects the sanctions to worsen electricity shortages for ordinary Cubans. Humanitarian groups tracking the broader campaign have raised that concern.

Sanctioning family members, not just officials

United States government building linked to the US sanctions Cuban companies announcement

Targeting an official’s relative, rather than the official directly, is a tool the administration has used before against Cuban leadership. The rationale: sanctioned officials sometimes route assets through family members who hold no formal government position. Fidel Ernesto Castro has faced no public accusation of an independent role in Cuban governance. His designation rests on his family relationship alone.

Cuban officials have not issued a detailed response to the September 3 sanctions specifically. The government has previously called similar measures collective punishment against the Cuban population rather than its leadership, according to Al Jazeera’s reporting on the broader sanctions campaign.

Raul Castro himself, now 95, has largely receded from public life. He no longer holds a formal government post, though he retains significant informal influence within Cuba’s Communist Party. Sanctioning his grandson instead of targeting Raul Castro directly reflects that shift. US officials appear to be pursuing the financial networks around the Castro family rather than the aging former leader himself, betting that cutting off younger relatives will do more to constrain the family’s long-term economic position.

Part of a longer pressure campaign

This round follows a series of sanctions actions against Cuba this year. Earlier rounds targeted officials and state companies; this one extends to family members. The administration frames the campaign as pressure for political and economic reform. Critics argue the sanctions mainly strain an economy already short on fuel and hard currency, with limited effect on the government’s political decisions.

What happens next for US-Cuba relations

The Treasury Department is expected to add implementation details for the new designations in the coming weeks. That should include specific compliance guidance for US financial institutions. Cuba’s government has not signaled any policy shift in response. Analysts tracking the relationship expect more sanctions rounds if diplomatic channels stay closed.

US-Cuba relations have swung between engagement and pressure for decades, depending on the administration in office. The current approach leans firmly toward pressure, with this round following several earlier ones this year. Cuban-American communities in the US remain divided on the strategy’s effectiveness. Some support continued pressure on the Castro family. Others argue it mainly hurts ordinary Cubans without changing government behavior.

Frequently asked questions

Who is Fidel Ernesto Castro?
He is the 31-year-old grandson of former Cuban president Raul Castro. He was sanctioned for being an adult family member of other sanctioned Castro relatives, not for an independent government role.

What companies were sanctioned?
Five entities, including Banco Exterior de Cuba and the Cuban Oil Industry Supply Import Company (Abapet), along with four other state-linked natural resources and energy firms.

Why is the US targeting Cuba’s financial sector?
Secretary of State Marco Rubio said the sanctions aim to dismantle the Castro family’s financial networks and limit the channels Cuba uses to move money internationally.

When did the sanctions take effect?
The State Department announced the measures on September 3, 2026, with the Treasury Department expected to issue compliance guidance for US institutions afterward.

Has Cuba responded to the sanctions?
Cuba’s government has not issued a detailed response to this specific round, though it has previously described similar measures as collective punishment against ordinary Cubans.

Related coverage

Sources

  • US Department of State — Further Sanctions on Cuba’s Elites, Financial Channels, and Resource Exploitation Apparatus. state.gov
  • UPI — U.S. sanctions Raul Castro’s grandson, Cuban state bank. upi.com
  • Al Jazeera — US continues to squeeze Cuban economy with new round of sanctions. aljazeera.com