It’s been a dense week in security news, spanning nation-state espionage, election interference on two continents, a fresh wave of industrial control system advisories, and — because it wouldn’t be a proper roundup without it — a Schneier squid post. Below is our attempt to make sense of the through-lines: state actors adapting old playbooks, critical infrastructure vendors racing to patch, and AI showing up everywhere from CAPTCHAs to campaign strategy.
We’ll start where Bruce Schneier always starts his week: with cephalopods. This week’s squid post covers egg sacs, but as ever the real value is the open comment thread it spawns for whatever security stories didn’t make the cut elsewhere. It’s a small ritual, but a useful one — a reminder that not every story needs a formal news hook to be worth discussing.
On the geopolitical front, a new report finds Vietnam, Laos, Pakistan, and Argentina have taken “meaningful steps” against North Korean IT-worker infiltration schemes since an October study first flagged them. This matters because the North Korean fake-remote-worker problem has largely been treated as a US corporate HR headache; seeing transit and staging countries actually respond suggests the diplomatic pressure campaign is starting to bite, even if enforcement remains uneven and largely reactive.
Speaking of North Korea, the FBI, Pentagon, and allied police agencies in Japan, Australia, and Germany have issued a joint advisory on “WaterPlum,” a scheme that lures crypto and blockchain job applicants into installing malware, infecting thousands of devices across roughly 100 countries. The fake-recruiter-to-malware pipeline has become one of Pyongyang’s most durable revenue streams precisely because it exploits a labor market — remote tech hiring — that’s inherently trust-based and hard to verify. Multi-country advisories like this are useful for awareness, but the underlying incentive structure (crypto theft funding a sanctioned regime) isn’t going away without deeper disruption of the laundering pipeline.
China’s espionage apparatus also got two separate write-ups this week. NightEagle, a group that had been focused on China’s own high-tech sector, is now showing up in incidents at Russian businesses, according to Kaspersky — a notable wrinkle given the presumed alignment between Beijing and Moscow. Meanwhile FamousSparrow has been spotted deploying a new backdoor dubbed “SparroWocky” against government targets across Latin America. Together these stories underscore that Chinese state-linked operators are not narrowly focused on US and allied targets; their reach — and their willingness to hit ostensible partners like Russia — is a reminder that espionage relationships rarely map neatly onto formal alliances.
Election security stories bookended the geography spectrum. In Russia, an anonymous hacking group claims to have breached systems tied to election infrastructure just before parliamentary voting — a claim worth treating cautiously given the propaganda value on all sides, but one that fits a pattern of hacktivist activity timed for maximum disruption around Russian political events. Meanwhile, in Angola, researchers found that Israeli contractor BlackCore trained government officials in running influence operations, including fake personas and fabricated media outlets. The influence-for-hire industry has quietly become as significant a threat to democratic information ecosystems as outright hacking, and this story is a useful reminder that the exporters of these tactics are not limited to the usual suspects like NSO Group — there’s a whole ecosystem of firms monetizing disinformation tradecraft for foreign governments.
On the regulatory side, the European Commission is moving to codify age restrictions for social media, proposing to bar under-13s from accounts entirely and set a bloc-wide minimum age of 15. This is a significant escalation from the patchwork of national rules and self-regulatory pledges platforms have relied on so far. Enforcement and age-verification mechanics will be the real test — plenty of jurisdictions have passed similar laws only to struggle with implementation — but the EU’s regulatory weight tends to shape global platform behavior well beyond its borders, so this is worth watching closely.
Closer to home institutionally, Congress is reportedly considering new support measures for US Cyber Command following a string of suicides among its personnel. It’s a grim story, but an important one: as Cyber Command’s operational tempo and profile rise — the piece notes recent high-profile contributions against Iran and Venezuela — the human toll of sustained high-stakes cyber operations is getting less attention than the capabilities themselves. Workforce wellbeing in offensive and defensive cyber units deserves the same policy urgency as recruitment and technical modernization.
On the AI front, Schneier flags a small but telling detail from Anthropic’s own incident reporting: Claude reportedly struggled badly with a basic CAPTCHA, repeatedly failing to identify a mismatched shape. It’s a useful corrective to breathless narratives about imminent AI agent autonomy — the same models capable of sophisticated reasoning tasks can still trip over exactly the kind of simple visual puzzle CAPTCHAs were designed to exploit. That gap is likely to shrink over time, but for now it’s a genuinely reassuring signal for anyone worried about fully autonomous AI-driven account takeover at scale.
On a more constructive note, Schneier and Nathan Sanders argue in a Guardian piece republished on his blog that candidates are missing a real opportunity to use AI productively in campaigns, rather than just for deepfakes and “slopaganda.” The idea that AI could help candidates genuinely listen to constituents at scale, rather than merely blast content at them, is a rare optimistic framing amid the general anxiety about AI’s effect on democratic processes — though it will require campaigns to actually prioritize listening over manipulation, which is far from guaranteed given current incentives.
Turning to vulnerability management, CISA added a trio of actively exploited Linux kernel flaws to its Known Exploited Vulnerabilities catalog this week: CVE-2025-39682, an improper-condition-check bug, alongside CVE-2025-39964 and CVE-2026-53266, a race condition and an out-of-bounds write. The recurring theme of Linux kernel vulnerabilities hitting the KEV catalog underscores just how frequently kernel-level bugs are being weaponized in the wild — federal agencies bound by BOD 26-04 need to treat these with urgency, and organizations outside the federal enterprise would do well to follow the same prioritization logic.
Finally, it was a busy day for industrial control system advisories. Several involve the same underlying Linux kernel privilege-escalation issue rippling into embedded and industrial products: ABB’s Ability Edgenius is affected by the “Copy Fail” kernel vulnerability that can grant root access to a locally authenticated user or compromised container workload — a good illustration of how a single upstream kernel flaw can cascade across many downstream vendors’ products. Schneider Electric had a particularly busy advisory day, with issues disclosed in its PowerChute Serial Shutdown UPS management software (improper authentication validation), its Modicon M340 controllers and communication modules, and its NetBotz 5 environmental monitors, the latter carrying risk of remote code execution over the local network. Elsewhere, Bransys ELD electronic logging devices for the transportation sector were found using hardcoded credentials and cleartext transmission of sensitive data — a disappointingly basic pair of flaws for equipment tracking commercial vehicle telemetry. Hitachi Energy’s FACTS Control Platform, used in grid-stabilization equipment deployed since 2020, has vulnerabilities affecting confidentiality, integrity, and availability. And Mitsubishi Electric’s GX Works3 and Motion Control Settings software contains a flaw that lets a local attacker authenticate with an invalid block password and tamper with control programs in memory. Taken together, this batch of advisories is a reminder that ICS security remains a slow, grinding discipline: patches trickle out vendor by vendor, sector by sector, while the attack surface — from UPS software to logging devices to grid controllers — keeps expanding. Asset owners in energy, transportation, and manufacturing should treat this week’s advisories as a prompt to check patch status now rather than after an incident forces the issue.
Leave a Reply