Squid, Spies, and Silicon: This Week’s Security Roundup

It’s been a week that ping-ponged between the absurd and the alarming — a truckload of squid overturning in Rhode Island shares headline space with nation-state espionage, ransomware hitting a federal firearms agency, and a cottage industry of ICS vulnerabilities that never seems to run dry. Below is our roundup of what mattered, what’s worth watching, and what’s just delightfully weird.

Let’s start with the weird: a tractor-trailer full of squid rolled over in Rhode Island, dubbed by locals the “Squidpocalypse of ’26.” Twenty tons of cephalopods baking on hot asphalt for hours is the kind of story that reminds us infrastructure failure comes in many flavors, not all of them cyber. It’s also, as always on Schneier’s blog, an open thread for whatever security news didn’t make the cut elsewhere — a nice reminder that even serious security researchers need a release valve.

On the enterprise side, PaperCut is warning customers of active exploitation of flaws in its NG and MF print management software. Printer software has long been an underrated attack surface — it sits deep in corporate networks, often with elevated privileges, and is rarely patched with the urgency reserved for more “glamorous” systems. Given PaperCut’s history as a ransomware entry point in 2023, this emergency advisory should trigger fast patching rather than a shrug.

Meanwhile, Bruce Schneier and Kasra Rafi offer a refreshingly grounded take on whether AI is about to make mathematicians obsolete. Their argument, following a reportedly gloomy closed-door meeting of top mathematicians at OpenAI, is that current models are nowhere near expert-level mathematical reasoning despite the hype. It’s a useful corrective in a news cycle that oscillates between AI doomerism and utopianism — the actual frontier of capability is messier and slower than either extreme suggests, and that gap matters for how institutions plan their workforce and curricula.

On the policy front, the White House has moved to ban foreign-made components in power generation equipment, citing backdoor risks from unnamed “foreign actors.” This is a significant escalation in supply-chain hardening for critical infrastructure, following years of warnings about grid vulnerabilities. The challenge, as always, will be implementation: domestic manufacturing capacity for many of these components is limited, and blanket bans can create cost and availability headaches even as they close a real security gap.

Speaking of infrastructure and international intrigue, a Finnish appeals court has revived the case against Eagle S officers accused of damaging undersea cables — even though the men have since left the country. This saga, tied to the shadowy fleet suspected of servicing sanctioned Russian oil exports, has become a bellwether for how European nations will handle accountability for suspected hybrid-warfare sabotage when the accused are foreign nationals who can simply leave. Sending it back to the district court keeps the legal question alive, but enforcement remains an open problem.

German companies, meanwhile, are sounding the alarm: a new survey finds Chinese and Russian state-linked actors are increasingly behind cyberattacks on the private sector. This tracks with broader European trends of espionage bleeding into industrial and economic targeting, not just government systems. For businesses, it’s a signal that geopolitical tension is translating directly into operational risk, regardless of whether a company sees itself as a plausible espionage target.

Closer to consumers, a breach at Manchester Airports Group exposed data belonging to 8.7 million customers, though the company says most of what was accessed was limited to email addresses. Even “just email addresses” breaches matter at this scale — they feed phishing campaigns and credential-stuffing attempts for months afterward, and the sheer number here (nearly a tenth of the UK population) underscores how deeply intertwined our travel data has become with everyday digital exposure.

In enforcement news, Australian authorities have charged two men allegedly behind TeamPCP, a group blamed for one of the most damaging supply-chain hacking campaigns in recent memory. Krebs on Security has additional detail on the arrests, noting the suspects — aged just 21 and 23 — are accused of running what may be the longest-running open-source supply-chain attack spree on record. The youth of the alleged perpetrators is a familiar and uncomfortable pattern in cybercrime: technical skill increasingly outpaces both legal deterrence and the maturity to weigh consequences, and open-source ecosystems remain a soft target for this kind of long-game infiltration.

On the domestic front, the DOJ’s Bureau of Alcohol, Tobacco, Firearms and Explosives has confirmed a breach of a system containing investigation-related information, with the Qilin ransomware gang claiming responsibility. A ransomware hit on a federal law enforcement agency handling firearms investigations raises obvious concerns beyond typical data breach fallout — compromised investigation details could endanger ongoing cases or informants. It’s also another data point in ransomware gangs’ growing appetite for high-profile government targets, regardless of the reputational and legal risk that comes with attacking federal agencies directly.

For defenders keeping score, CISA has added three vulnerabilities to its Known Exploited Vulnerabilities catalog: an ownCloud authentication flaw, a Linux kernel bug, and a JFrog Artifactory path traversal issue. As always, inclusion in the KEV catalog is CISA’s way of saying “patch this now” — federal agencies are required to remediate on a deadline, and everyone else should treat the list as a practical, evidence-based patching priority rather than just another advisory to skim.

The ICS advisory pipeline was also busy this week, and it’s worth taking these collectively rather than one by one, since they paint a picture of an industrial control landscape still riddled with basic security failures. CISA flagged an update to a denial-of-service flaw in the Mitsubishi Electric CNC Series, alongside a separate update covering communication-delay and timeout vulnerabilities in Mitsubishi Electric’s Multiple FA Products line, both affecting remote I/O modules used in manufacturing environments.

More concerning are the vulnerabilities that allow outright device takeover. The Xiiaozet LK100W carries a maximum-severity 9.8 CVSS score thanks to OS command injection and authentication bypass flaws, and the Ebyte NA111-M racked up a staggering thirteen separate CVEs, also topping out at 9.8, enough to “fully compromise the device.” These are the kinds of low-cost, widely-deployed IoT-adjacent industrial devices that rarely get security scrutiny until something breaks catastrophically downstream.

Rounding out the ICS list: Rockwell Automation’s OTTO Fleet Manager was found using an insufficiently hardened password hashing scheme, making offline brute-force attacks cheaper for an attacker who obtains the hash database. The All-Line Equipment Company Fuel-Boss system is still running on an ancient, long-unsupported PHP 7.1.5 stack with known remote code execution bugs dating back to 2018 — a stark illustration of how fuel-handling infrastructure can quietly run on forgotten software for years. And the Applied Systems Engineering ASE2000 V2 Communications Test Set, used for testing protective relay communications in the power sector, has flaws that could let an attacker intercept and tamper with supposedly protected TLS connections. Individually these are niche advisories; collectively they’re a reminder that critical infrastructure security debt accumulates in unglamorous corners that rarely make headlines until exploited.

On the offensive-AI front, Schneier flags OpenAI’s disruption of a Cambodia-based scam network that used ChatGPT to run overlapping romance, investment, and impersonation scams at scale. The blending of “pig-butchering” romance scams with crypto fraud and fake authority figures — all scripted and iterated with LLM assistance — shows how generative AI lowers the labor cost of running sophisticated, multi-pronged social engineering operations. This is likely to be a recurring story for years: platform operators disrupting misuse after the fact, while the underlying economics of AI-assisted fraud keep improving for the scammers.

Finally, a curious institutional story: The Record reports that the NSA is planning a reunion for former members of its elite Tailored Access Operations unit, timed to a recent rebranding effort. Bringing back potentially hundreds of former TAO hackers is a striking move for an agency built on secrecy, and it hints at real institutional anxiety about brain drain and talent retention in an era when private-sector and criminal opportunities for offensive cyber talent have never been more lucrative. Whether nostalgia and esprit de corps can compete with market forces is an open question — but it’s a telling sign of how seriously the agency takes the erosion of its elite bench.

That’s the roundup for this cycle — equal parts spilled squid, spilled data, and spilled patience with unpatched industrial gear. As always, we’ll keep tracking these threads as they develop.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *