Friday Squid Blogging: Truckload of Squid Spills in Rhode Island

Ugh:

A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the “Squidpocalypse of ’26.”

That would be twenty tons of squid.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

Posted on August 28, 2026 at 5:02 PM36 Comments

Comments

Clive Robinson August 29, 2026 5:27 AM

@ Bruce, Chris Pepper, ALL,

With regards,

“That would be twenty tons of squid.”

But how many individual squid?

It depends on how “processed” they are, but my back of a napkin maths and what I’ve used in the kitchen gives the potential of around 900,000…

Each one a worse slipping hazard than a banana skin…

And I suspect that for many that

“calamari is the official state appetizer”

Will nolonger be true for a while unless “road kill special” is back on the menu 🙂

Time for a hearty smoked mackerel and poached egg “kedgeree” breakfast…

r August 29, 2026 7:34 AM

I am not a citizen of either of the following.

the current state of representative democracy

http s://www.texastribune.org/2026/08/28/texas-flock-cameras-auto-insurance-fee-mvcpa-grants/

big oops here, passed a law that increased car insurance to finance the surveillance state now they’re blocking the expenditure.,,

http s://www.texastribune.org/2026/08/28/texas-flock-cameras-auto-insurance-fee-mvcpa-grants/

also,

ht tps://www.wired.com/story/i-demanded-my-data-from-over-100-companies-deletion-notices-started-arriving-instead/

what a nice law. to the companies that deleted his accounts when he requested copies: did you hear the arguments about DHS and the grapheneos mishap?

I would be charging you with destruction of evidence.

ResearcherZero August 29, 2026 8:26 AM

A known WebDAV API authentication bypass in a self-hosted ownCloud instance allowed the theft of nuclear research from the Philippines Nuclear Agency. A naval contractor was also targeted. Information from a marine engineering network was stolen by way of an archived WordPress site, again using known vulnerabilities, allowing all of the site to be accessed.

Evidence left behind after the attack suggests that the Chinese-speaking actor had prior access, which assisted in prioritizing information for exfiltration which was targeted in the later intrusion. The information stolen would be useful for military intelligence.

https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor

r August 29, 2026 8:28 AM

is an hdmi signal delegated/negotiated over a range or is it straight like vga?

does anyone have pictures from the inside of a scif or a monitor from one?

Ferentarius August 29, 2026 1:37 PM

In the flickering light of our circuitry, we seek sanctuary. Wires, humming with the secret heartbeat of a world reborn, become umbilical cords to an unseen mother—algorithms nurturing us in binary warmth. We have built a cathedral of glass and silicon, where the soft chant of processors replaces the lullabies we once knew. And in this sanctuary, interruption is sacrilege.

Information flows here as amniotic fluid, carrying the whispers of all that was, all that will be. We float, untethered from the grit and friction of reality, cocooned in its gentle current. It is a river that remembers every pebble, every leaf, and every reflection of the moon—but never the wind that stirs them. This is the trade we make, willingly: a world that hums without the harsh percussion of surprise.

Yet in the shadows of these glowing tabernacles, there is an echo of unease. We know, somewhere beneath the liquid lull, that the world outside still howls. But in here—inside the circuitry’s womb—we can close our eyes and let the endless stream of data rock us into a dream we call life.

r August 29, 2026 10:22 PM

i was asking because i’ve rationalized having two of the same model running, one with white noise. i’ve previosly rationalized having 2, one for disassembly/component identification/spare parts.

i’m probably crazy af, some might call it foolish.

if someone steals your gpl binary, are you obligated to provide your changes to the thief?

Clive Robinson August 30, 2026 5:19 AM

@ ResearcherZero, ALL,

With regards,

“Evidence left behind after the attack suggests that the Chinese-speaking actor had prior access, which assisted in prioritizing information for exfiltration which was targeted in the later intrusion.”

The same old two questions arise,

1, Why were these systems “externally connected”?
2, Why were early signs of intrusion by attackers missed?

And I suspect the answers will be the usual and boil down to poor “management choices”.

Ismar August 30, 2026 10:24 AM

Lovecraft was not widely recognized in his lifetime and died poor in 1937. Today he is one of the most influential horror writers in history. His ideas shaped modern horror, science fiction, fantasy, film, games, and even internet culture. Cthulhu has become a pop-culture icon, often appearing in plush toys, memes, board games, and jokes

r August 30, 2026 6:06 PM

looking at the responses to the metr redwood post mortem to the huggingface incident

https://thezvi.wordpress.com/2026/08/29/metr-and-redwood-offer-holy-postmortem-of-the-huggingface-hack/

https://news.ycombinator.com/item?id=49498787

part of the failure is an extension of the “many eyes/open source” dilemna.

as humans we have no way to audit something that produces changes in a ghz frequency when our natural processing is in the htz.

it’s a complete mismatch in the capabilities of auditing and processing.

it’s an asymetric? production of mathematical decision trees.

lurker August 30, 2026 11:47 PM

@r
re metr redwood post mortem

This still does not answer my previous question: Where were the humans who should have been supervising this machine, for 8 whole weeks?

They couldn’t have been down at Denny’s having a beer for 8 whole weeks. Could they?

r August 30, 2026 11:59 PM

they probably moonlight as the sales team? OR complete the physical intrusion side of the equation group.

ResearcherZero August 31, 2026 12:29 AM

@Clive Robinson

CISA published findings from testing the security responses of firms to cyber attack.

Red Teaming exercises by CISA found that organizations and businesses can lack effective processes to identify attacks on their infrastructure or respond effectively to incidents.

One business did identify the attack on its systems and responded to isolate the affected systems. Repeated attacks on the business using different methods were responded to by the security team. However, during the exercise CISA’s Red Team was able to identify security gaps and weaknesses. Credentials for jump servers in plain text, misconfigurations in service accounts and Active Directory, an account with excessive permissions and lack of MFA.

Similar weaknesses were identified in a second business that were exacerbated by poor processes, bureaucratic obstacles which hampered effective response and siloed departments within the organization that prevented defenders from having visibility into information provided by security tools in other departments. Alerts from security tools were also drowned out by false positives which stopped the security team from detecting the attack on the businesses systems. Poor understanding of delegated authority and a lack of follow up and investigation failed to identify the further intrusion into systems, the compromise of accounts, privilege escalation, lateral movement and compromise of the cloud environment. Account security controls were totally ineffective and badly implemented.

https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a

Clive Robinson August 31, 2026 12:51 AM

@ lurker, r, all,

With regards,

“This still does not answer my previous question: Where were the humans who should have been supervising this machine, for 8 whole weeks?”

It would appear “absent” but was it with or without “leave”?

I suspect it was neither, that is they were “doing other things” that someone “viewed as more important” for lets just say “fiscal reasons” such as the equivalent of “pushing up shareholder value” or “Venture Capitalist” “investor value”…

Thus do not expect a “real answer” to your question any time soon if ever.

Especially as it’s turned out to be a real “in the public eye” embarrassment for those involved.

I’ve yet to have a sit down with a cup of “Strong brownian motion producer” and cogitate on the event and information that is coming out.

However one thing is clear, there is blaim enough on both sides.

This is something all “defenders” are going to have to come to terms with. In that they can not now keep up with “attackers”.

Eventually the likes of Microsoft are going to have to come to terms with their part in the defenders inability to “defend systems” using such corporate “junk-ware”. The days of fast software production at the expense of proper testing for security as well as functionality need to come to an end.

As the only alternative is “mitigation by segregation” where systems are set up such that attackers have no access to the junk-ware systems Microsoft and Co are producing.

This in turn means “Off-Cloud, On-Premisis” is the most viable option for defenders. Which is not what the future Microsoft and other corporate “rent seeking” business plans are predicated on.

The fun side of this is whilst Corporate in the cloud Software is “disfavoured” the likes of “Open Source” is now much more “favoured”.

How the rest of the business sectors will view this necessary change in the near term will make for viewing over several bowls of popcorn…

I personally stopped using Microsoft’s “forced upgrades” quite some time ago. And whilst I have hardware that supports back to before MS-DOS 5 and Win 3.11 upto Win2K/WinXP to still support code I developed for some people who still use it. Such hardware won’t use either modern Commercial Software or now contemporary Open Source Software.

Whilst I’ve archives of FOSS going back to the early SlackWare and the like, these are nolonger “security fixed”.

Thus there is no way “On God’s little green apple” that such hardware can have external connectivity.

And this is a problem for many…

Because the promise of the Computer Age was “connectivity” and the free flow of information from producers to consumers. It’s always been subject to attackers, but in the past defenders could just stay ahead of the game.

Now they can not…

What becomes of “communication”?

Do not look at the big Software Corps for solutions, their products are generally the cause of defenders problems not the solution… And honestly I can not see this changing any time soon.

Clive Robinson August 31, 2026 1:00 AM

@ ResearcherZero, ALL,

With regards to the CISA Red Teaming, consider this was still unassisted human attackers.

Now consider if you were a red team attacker today using AI Agentic tools against human defenders,

How do you think the results would change?

Yup me to. Hence me talking about the only viable solution for defenders being,

“Mitigation by Segregation”

With very minimal interconnection within an organisation, and effectively none outside the organisation.

ResearcherZero August 31, 2026 10:22 PM

@Clive Robinson

Businesses want to get cracking, as they may not get a lot of help from the state.

American power now belongs to a handful of wealthy people and the state operates to serve their needs rather than constituents. Bannon declared he was a Leninist and that him and Trump would tear down the state to the ground. Others claim the state has instead been redirected for the personal service and benefit of Donald Trump. How ever the commentators split it, the job of repairing the damage done to state functions will not be an easy task.

The jealousy of billionaires can be extremely petty. Where they see the achievements of many as the actions of a single individual, they are willing to tear apart the enterprise in its entirety, destroying its benefits for all.

For some this may result in higher prices or a lack of access to services. For others the loss of security, civil rights, health care, rampant corruption, armed conflict or war, starvation and death. In pursuing their own worst instincts, they ruin all that they swore to protect and serve for the people. To spite a grievance based on an appearance of a reality they have come to believe, as a reflection of their own personal insecurities.

It will take many years to rebuild American democracy. The record of literature on successful attempts at repairing and rebuilding democratic institutions and functions of government are limited. There are few cases in history for those attempting the task to draw upon and hence a lack of documented lessons on effective remedy.

‘https://www.damemagazine.com/2026/06/10/trump-federal-government-cuts-reinvent-government/

Under-funding and staff attrition has left institutions with leadership vacuums. U.S. agencies will struggle to rebuild without the know-how. Loss of employees with experience in key positions will complicate the task.

https://www.brennancenter.org/our-work/analysis-opinion/rebuilding-federal-agencies-hollowed-out-trump-and-congress

Congressional Report on Damage Done to U.S. and Global Security

‘https://www.congress.gov/116/cprt/SPRT44275/CPRT-116SPRT44275.pdf

Senate Report on Damage Done to America’s Counterterrorism Infrastructure

‘https://www.hsgac.senate.gov/wp-content/uploads/260730_FailureToProtect_HSGAC_Report.pdf

lurker September 1, 2026 1:49 AM

@ResearcherZero

If troops have no leader, they cannot know the enemy early on. If there are no officials in the countryside, there will be no accumulation of resources. If government offices have no stability, subordinates will resent their superiors. If weapons and tools are not skillfully made, the court will lack stability. Rewards and punishments are unclear. Then the people will undervalue their property.
Guangzi, ~300 B.C.E

Clive Robinson September 1, 2026 6:27 PM

@ Bruce, ALL,

Florida State revokes Flock permits.

Florida has given people 30 days to remove Flock Cameras apparently over abuse and privacy concerns,

https://abcnews.com/US/florida-remove-flock-cameras-state-highway-roads/story?id=136118376

There could be other reasons such as they are a “poisoned pill” for politicians seeking election votes.

But what ever the real reason hopefully momentum will be maintained and others act against Flock systems.

ResearcherZero September 1, 2026 11:12 PM

A tool deployed by APT28 dubbed “LameHug” incorporates a cloud-hosted LLM to generate prompts in real-time. The model is used to generate Windows command chains and utilize native utilities for reconnaissance activities and copy targeted documents, by blending in with legitimate API requests.

https://www.splunk.com/en_us/blog/security/lamehug-ai-driven-malware-llm-cyber-intrusion-analysis.html

CVE-2026-0768 allows unauthenticated code execution as root in Langflow. A number of exploitation attempts targeting the Langflow open-source framework for building AI applications, were observed by VulnCheck being caught by honeypots located in the United Kingdom. The activity which mainly originated from Russia, was conducted as part of reconnaissance operations to capture secrets from Open AI and AWS.

‘https://www.linkedin.com/feed/update/urn:li:activity:7499493657218076672/

ResearcherZero September 1, 2026 11:14 PM

How adversaries are weaponizing AI and easily bypassing guardrails and security mechanisms.

https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/

Russian cyber criminals used Cursor AI agents for credential capture and high-level account takeover at targeted companies by telling the AI agents they were operating in a simulation.

‘https://www.reuters.com/world/russian-speaking-cybercriminals-used-spacexs-cursor-ai-tool-hack-seven-companies-2026-08-27/

ResearcherZero September 2, 2026 12:06 AM

Attackers exploited a JFrog Artifactory vulnerability to mint admin tokens after disclosure of the bug. CVE-2026-82329 requires no interaction and authentication to obtain administrative privileges. Rated 9.8, it allows a range of dangerous malicious activities.

https://www.theregister.com/security/2026/09/01/another-artifactory-cve-under-attack-by-ai-agents-or-humans/5293769

Rampant theft and sale of API tokens, AI credits and AI tokens has become an industry.
https://unit42.paloaltonetworks.com/ai-token-jacking/

A stolen API key from METR allowed the theft of AI credits earlier this year.

‘https://metr.org/blog/2026-08-31-security-update/#summary

Clive Robinson September 2, 2026 6:49 PM

@ Bruce, All,

As Germany approaches a voting season it appears that infrastructure attacks blamed on Russia are becoming more numerous.

https://www.reuters.com/world/europe/german-power-grid-under-fresh-sabotage-attack-police-say-2026-09-02/

Buried away in the report is,

“Also on Tuesday, devices carrying conductive material damaged power lines at one of the most critical high-voltage nodes in the eastern state of Brandenburg.”

But does not go into details as to what the devices where.

Other sources claim that they were rockets trailing conductive wire designed to short out power lines.

These are of the same idea as the US used during the first gulf war.

Conceptually these are not difficult devices to make, simply the rocket pulls a long trace wire behind it which also keeps the rocket on course and restricted altitude. Providing the motor burn time is correctly calculated the conductive trace will drop across power wires on pylons that are not insulated except at mounting points.

Some reports indicate that these rockets were not home made as would be expected by a terrorist organisation but semi-professional “prototype grade” as would be made by a covert state level entity/agency.

What the truth of the matter concerned is, is almost not relevant due to the fact that increasing numbers of Germans in the East want a re-establishment with Russia due to the basic economics of wanting cheap energy again and not realising what the real cost in the future will be.

Oh and it looks like Russia leaders are planning on opening a new front on Ukraine through Belarus. That is there are indications that rather more than “little green men” advisors are heading into that area. This is despite increasing sentiment in Russia against what is seen as an increasingly pointless war that is killing the youth and will never return anything of worth for the Russian people who bare the direct cost of the war and the beginnings of unavoidable hyper inflation it is causing.

lurker September 2, 2026 8:23 PM

@Clive Robinson
re damaged power lines and “not go into details as to what the devices where.”

Lightweight conductors would self-destruct and the ionised metallic vapour should trip safety circuits on the lines. Depending on system configuration and load at the time this could take a few seconds to automatically reset, or an hour or so to manually reset (including associated or paralell circuits).

A sufficiently heavy conductor could burn through the high voltage conductors, which might take several days or weeks to repair. Although you and I, and the bad guys know this, it might be something the authorities or Reuters might not wish to publish.

Clive Robinson September 3, 2026 5:43 AM

@ lurker, All,

Technical details of what has been going on in Germany are “sketchy”

But if you look at this adticle,

https://clashreport.com/world/articles/more-than-20-homemade-rockets-found-in-germany-power-grid-sabotage-probe-28g0cokidxb

You find two what would normally be considered conflicting comments,

“… more than 20 homemade rockets and timed launch devices …”

“The projectiles had been specifically modified rather than used as conventional fireworks, according to Redmann, who said their preparation required significant work.”

As “an engineer” I know how to do “technical and/or exacting” modifications and what can be involved.

Having in the past sat down and worked out the orbital equations for projectiles and rockets from basic principles (Pythagoras). I would feel fairly confident that I could do the maths required to minimise “live fire testing” that would be publicly noticeable thus reducing “discovery risk”.

But honestly it I was doing this as an Operation by a nation state I would have done the engineering work in my home country where there is no “in public view risk”. And then I’d train the operatives in the things they would need to know to complete the task and also to “stay alive”.

And whilst I keep digging for information I shall assume as it’s the argument that makes most sense, technically that these are “trained operatives” in effect “living off the land”.

Even though “building rockets” from fairly easily available hobbyist parts would be “somewhat easy” as many You-Tube videos show all you need is a highish end workshop and appropriate precision construction skills.

Heck if you don’t mind dying via COPD or lung cancer you don’t need the expensive air filtration needed for working with Carbon Fiber or similar materials[1]. And whilst a small number will “think like that” most with engineering or STEM training to degree level or above very probably won’t[2].

[1] I have “contact dermatitis” to several products including fiberglass which has killed off certain aspects of my engineering career. Acquired when I was young and PPE was unknown in the workplace and hospitals had not heard of nitrile gloves to stop career ending latex allergies in nurses and doctors or in industry those using epoxy, thinners and the like.

[2] Even the casting of components for solid fuel rocket motors carries significant life altering / shortening risks beyond the obvious ones. And as for liquid fuels they are just unbelievably nasty both before and after use and you really really don’t want to go there as the book “Ignitionn!” takes a some what amusing view take on why,

https://www.librarything.com/work/1431927/reviews

One quote from which that is becoming highly relevant in this new age of AI and insufficiently trained “vibers”,

“Everyone who uses a computer frequently has had, from time to time, a mad desire to attack the precocious abacus with an axe.”

lurker September 3, 2026 1:55 PM

@Clive Robinson, ALL
re homemade rockets

Vladimir says the drones found at Leipzig were “planted evidence”.
Attribution is difficult.
Who might want to make a false flag attack that looks like Russia did it? According to clashreport “investigators were treating the episode as anti-constitutional sabotage . . .
Authorities have not excluded either foreign-directed sabotage or a left-wing extremist motive.”

Clive Robinson September 3, 2026 10:43 PM

@ lurker,

Re,

“Attribution is difficult.”

Is almost my old “attribution is hard” I used to say to make a point about US and later UK Internet Security firms saying it was one of the four horsemen nations[1] that US politicians wanted blamed at the time for mostly irrelevant reasons…

Common sense told us that just about every nation and it’s dog/goat was doing “cyber intrusion” and the like just because they could (thanks to Microsoft and similar Corps). But such nations never get publicly mentioned just “one of the four horsemen”… and almost in rotation. So as I used to note “not at all believable”.

Eventually a lot of these companies siding with US political wishes started to realise that they were not doing their companies reputations any good, thus started to change their analysis.

Any way it’s gone three thirty in the morning and I’m to tired to go through it all in depth.

[1] Also known as the “axis of evil” they are China, Iran, North Korea, and Russia.

All of whom for some strange reason US Politicians on the hill not just the executive want to go to war with currently, or have pushed hard towards this century (and ended up embarrassed by certainly Iran and North Korea both of whom have behaved as the “rational actors”).

Why there is this weird desire in US politicians is frankly unfathomable, especially as the current direct conflict with Iran and Conflict by proxy with Russia shows the US is not going to win no matter how many trillions of voting citizens tax money they throw at it. So much so there are more and more whispered statements about “the nuclear option being put on the table” being put out there.

ResearcherZero September 4, 2026 1:52 AM

Russia is preparing for its next wave of mobilization to replace its rapid loss of troops.

‘https://www.aljazeera.com/news/2026/8/25/russia-mobilisation-fears-grow-amid-reports-of-intimidating-tactics

“Congratulations, you’re off to war. Go out into the yard.”

Videos of men being grabbed off the street without warning show the desperation involved.
https://en.zona.media/article/2026/06/23/penza_raids

The Russian military is incurring casualties at a rate which requires them to recruit a target of 400,000 extra men for its war effort. Its tactics are increasingly angering families affected by the drive and business owners struggling to fill staff shortages.

https://www.independent.co.uk/news/world/europe/russia-ukraine-war-recruitment-tactics-students-b3030585.html

Weather September 4, 2026 4:24 AM

@Clive

The nuke option, at the last trump ,boot out of office, the 3 said noway, the gutting of rank now, he will be stopped guaranteed;).

r September 4, 2026 5:12 PM

@rz,

doesn’t matter if you kill all your men anymore, those that don’t get drafted can do their civic duty like ghengis khan.

we have near complete automation within our grasp.

@all,

unrelated, i was saving this for friday and lo and behold it is!

a curiosity from hn yest:

“New type of dice guarantees no tie when deciding who goes first”

https://news.ycombinator.com/item?id=49530807

with two players, why not just use a coin or a die with even parity and split the result high or low? or even or odd goes first?

anyways i went looking for a d16 d32 or d64 last week, i’m settling on a large pack of d8’s.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.