It’s been a week where the cybersecurity news cycle swung between the mundane and the existential: rugby clubs and ports getting hacked, AI labs quietly investigating incidents they won’t fully explain, and a court ordering Meta to pay hundreds of millions for the harm its platforms have caused kids. Add in a stack of ICS advisories, a couple of major criminal sentencings, and some geopolitical intrigue, and you have a fairly representative slice of where digital security stands in mid-2026. As always, we start with the squid.
Bruce Schneier’s long-running Friday Squid Blogging tradition continues with footage of the Arctic bobtail squid, and as ever it doubles as an open thread for security stories that didn’t make his main feed. It’s a small, whimsical ritual, but it’s also a reminder that some of the best security commentary happens in the comments section of a cephalopod post rather than in any formal report.
On the infrastructure front, the National Rural Water Association’s new partnership with a DEF CON offshoot to launch a “Water Watch Center” is a welcome, if overdue, acknowledgment that small utilities are chronically under-resourced against modern threats. Water systems have long been the poster child for critical infrastructure risk precisely because they’re run by tiny staffs with no security budget. Pairing them with volunteer hacker expertise won’t fix the funding gap, but it’s a pragmatic stopgap that deserves attention as a model for other under-served sectors.
Meanwhile, diplomacy trudges forward: the Senate has confirmed Adam Cassady as the State Department’s cyber ambassador-at-large, only the second person ever to hold the post. This role matters more than its low profile suggests — it’s the seat at the table for norms-setting on ransomware, critical infrastructure attacks, and AI governance across borders. Whether Cassady can accelerate international cooperation, or whether the position remains largely symbolic, will be worth watching.
The biggest headline of the week may be the $567 million judgment against Meta in a New Mexico kids’ online safety case. With $420 million earmarked specifically for treating young people harmed by social media, this ruling puts a concrete price tag on platform negligence in a way that mere fines or settlements rarely have. It’s a signal that courts are increasingly willing to treat “engagement-optimized” design as an actionable harm, not just a business strategy — and other states will be watching closely for a template.
On the industrial espionage side, IEH Corporation’s disclosure of a cyberattack is a stark reminder that the defense supply chain is only as strong as its smallest link. A company making specialized components for satellites, missiles, and fighter jets is exactly the kind of under-the-radar target that state-linked actors love: less scrutiny than a prime contractor, but access to sensitive designs all the same.
Perhaps the most unsettling item this week is Irregular’s refusal to clarify the scope of AI hacking incidents involving Anthropic, OpenAI, and Meta’s models. When a firm investigating security incidents in frontier AI systems won’t say whether there were more incidents than publicly known, it raises uncomfortable questions about transparency in an industry that increasingly asks the public to trust its safety claims. As AI models become both targets and tools of attack, this kind of opacity is going to become a recurring theme — and a recurring frustration.
Corporate breaches remain routine, but Levi Strauss’s disclosure that hackers used social engineering to compromise just three employee laptops and exfiltrate corporate data is a useful case study in how little technical sophistication is often required. No zero-days, no supply chain compromise — just a well-crafted pretext and three sets of company credentials. It’s a good reminder that user training and identity verification remain the unglamorous backbone of any real defense.
Aviation security got a wake-up call from CISA’s advisory on CPDLC over ATN-B1 vulnerabilities, which highlights that the data link controllers use to talk to aircraft still relies on unauthenticated, cleartext radio transmissions. CISA is careful to note this doesn’t constitute an “unsafe aircraft condition,” but message injection and forced session resets that increase pilot workload and delay safety-critical instructions are exactly the kind of degraded-margin risks that tend to compound in an emergency. Legacy protocols in aviation are notoriously hard to replace, and this advisory is a reminder of how much of our safety-critical infrastructure still runs on decades-old assumptions about trust.
On the patching front, CISA’s addition of a Progress LoadMaster command injection flaw to its Known Exploited Vulnerabilities catalog is a straightforward but important nudge to federal agencies and enterprises alike: this bug is being actively exploited, and BOD 26-04 obligations mean the clock is now ticking for remediation. Load balancers are attractive targets precisely because compromising one often gives an attacker a foothold across an entire network’s traffic.
Sports organizations are not immune either — Stade Français’s recovery from a cyberattack using clean backups shows that basic resilience planning still pays off. The club’s ticketing and online store staying operational throughout suggests decent network segmentation, which is more than can be said for many larger organizations that suffer cascading outages from a single compromised system.
Bruce Schneier also flags a quietly alarming story: ICE’s purchase of credit card records through data brokers. This is part of a broader and well-documented pattern of government agencies sidestepping warrant requirements by simply buying the data they’d otherwise need judicial approval to obtain. It’s a legal loophole that Congress has been slow to close, and each new revelation like this one adds pressure — so far unsuccessfully — for legislative action on data broker regulation.
Closer to home for supply chains, North Carolina Ports’ cyberattack, which forced a switch to manual processing, is a small-scale preview of what a coordinated attack on port infrastructure could look like at larger scale. Ports are chokepoints for regional and national commerce, and even a “contained” incident that forces manual workarounds shows how fragile digitized logistics can be when systems go down, even briefly.
On the accountability side, two major sentencings stood out. Connor Riley Moucka’s guilty plea in the Snowflake extortion campaign, per Krebs on Security, closes the loop on one of 2024’s most consequential cybercrime sprees — the theft of call and text records for over 100 million AT&T customers alone is a staggering figure that underscores how much damage a single skilled actor can do when cloud misconfigurations go unchecked. Similarly, the 16-year sentence handed to the Belarusian operator behind Ransom Cartel signals that Western law enforcement is increasingly able to reach ransomware operators once thought untouchable, even those based in jurisdictions historically resistant to extradition or cooperation.
Rounding out the week’s ICS advisories, CISA flagged vulnerabilities in ABB’s Ability Zenon industrial platform, including issues tied to its MongoDB-based IIoT services that could let attackers bypass security controls or crash systems outright. A companion advisory covers Johnson Controls’ TL280 device, where a broken cryptographic algorithm could expose sensitive information — a reminder that “critical manufacturing” and “government facilities” sectors are still running gear with cryptographic choices that were outdated years ago. And in healthcare, Medixant’s RadiAnt DICOM viewer has an out-of-bounds write flaw that can be triggered by a maliciously crafted medical imaging file — a lower-severity bug, but one that touches software used daily by radiologists worldwide.
On a lighter but still thought-provoking note, Schneier’s post on adversarial clothing designed to fool facial recognition is worth a read for anyone tracking the arms race between surveillance and evasion. His skepticism is well-placed: these garments make for great headlines and photogenic patterns, but as one expert quoted notes, surveillance systems are increasingly resilient to “a little resistance.” Still, as Schneier suggests, the cultural signaling value of wearing your privacy politics may outlast any actual technical efficacy.
Geopolitically, the revelation that President Trump raised Southeast Asian scam compounds directly with Xi Jinping suggests these operations — which have trafficked and enslaved tens of thousands of workers to run pig-butchering and romance scams — have finally reached a level of diplomatic priority matching their scale of harm. It remains to be seen whether high-level conversation translates into the kind of cross-border enforcement needed to actually dismantle these compounds, many of which operate with tacit protection from local officials.
Finally, Georgia’s investigation into an alleged disinformation campaign targeting Russian tourists is a small but telling data point in the ongoing information war around the region. Whether the fabricated stories originated from a foreign intelligence service or a domestic political actor looking to embarrass the government, the episode illustrates how tourism, of all things, has become a soft target for influence operations in contested geopolitical spaces.
Taken together, this week’s stories trace a familiar arc: infrastructure remains under-defended, accountability is slowly catching up with both criminals and negligent corporations, and the frontier of AI security is proving just as opaque as everyone feared. As always, keep patching, keep training your staff to spot pretexts, and maybe don’t buy the adversarial hoodie expecting miracles.
Leave a Reply