Weekly Threat Brief

Week of Sunday, October 4, 2026

Key Insights

1. The US 50% Duty on Canadian Goods Now Covers the Box Your Product Ships In

The covered list includes corrugated boxes, kraft linerboard, plastic film and plywood.

If a Canadian mill supplies your boxes, bags, stretch film or pallet plywood, or the importer behind your distributor does, that packaging has carried an extra 50% duty since August 22, on top of the duties it already paid.

The duty rests on a 1930 trade law that lets the president penalize a country he finds is discriminating against US commerce. Three July 20 proclamations used it against Canada. Their titles named alcohol, dairy and motor vehicles, but the annexes behind them are broad lists, and the president changed the list effective September 15. It now includes corrugated cartons and boxes, sacks and bags, uncoated kraft linerboard, plastic packaging and film, plywood and wood panels, some aluminum products and dissolving pulp. Folding cartons and other grades of pulp are not on it. The import bans that took effect September 29 are narrower: whey, molasses and sugar syrups, alcohol and beverages, and motorcycles. No paper.

The duty stacks on top of the normal rate and any extra duties on goods sold below fair price, and it applies on the date goods enter the United States, so cargo that was still at sea on August 22 paid the 50% when it entered the country. Sandler Travis & Rosenberg, a trade-law firm, and GHY, a customs broker, read the proclamations as giving no relief to goods that qualify under the US-Mexico-Canada trade agreement, and none of the proclamations carves them out. Canada supplied $6.59 billion of US paper and paperboard imports in 2025, according to Printing United Alliance, the printing and packaging trade association, and Canada has answered with C$27.6 billion, about US$20 billion, in counter-tariffs that include pulp, paper and plastics. No lawsuit challenging the law had been filed as of September 28, according to Law News, and the US Trade Representative said October 1 that talks continue but difficult issues remain.

The Takeaway
The trade war with Canada is escalating into your boxes, bags and pallets. If they come from Canada, they now carry a 50% cost you most likely didn't price, on a list that has already changed once and could again. It may be worth a look at where you source your packaging, or at adding a second source.
Sources: Federal Register: Presidential proclamation imposing additional 50% duties on certain products of Canada (2026-14997) · Federal Register: Presidential proclamation imposing additional 50% duties on certain products of Canada (2026-14991) · Federal Register: Presidential proclamation imposing additional 50% duties on certain products of Canada (2026-14992) · Federal Register: Presidential proclamation on imports of Canadian goods, including the court-invalidation fallback (2026-18836) · US Customs and Border Protection: CSMS 69851916, modification of the list of Canadian products subject to additional duties · Congressional Research Service: U.S. tariffs on Canadian imports, Section 338 of the Tariff Act of 1930 · GHY: U.S. imposes Section 338 tariffs on certain Canadian imports · Sandler, Travis & Rosenberg: Section 338 tariffs on Canada · Printing United Alliance: New tariffs on Canadian inputs could disrupt printing, packaging and paper supply chains · Law News: Section 338 tariffs against Canada face major questions challenge · CTV News: Canada-U.S. trade, 'difficult' issues to resolve, Greer says · Government of Canada: Complete list of U.S. products subject to counter tariffs

2. Washington Wants to Know Who Told Your AI Agent What to Do

The FTC chairman says the person who sent the agent answers for it. A Senate bill would also hold the developer liable, and the FTC is investigating the developers now.

Andrew Ferguson, chairman of the Federal Trade Commission, the federal consumer-protection regulator, told a Reuters conference in Austin on September 25 that he will keep resisting "this anthropomorphizing of these tools," meaning treating an AI agent as if it were a person who can take the blame. His answer was that whoever gave the order does: "If someone tells a tool to do something, and the tool does it, I don't think we would say, 'Oh, what do we do about the tool?'" Treasury Secretary Scott Bessent took the same line on CNBC on September 21, saying the Hugging Face breach was "the responsibility of the OpenAI management, not a bunch of agents."

Other signals point somewhere different. On September 30 an FTC spokesperson confirmed to CBS News that the agency is investigating Anthropic, OpenAI and other AI companies over the risk their technology poses to consumers, so the agency is looking at the builders too. On October 1 Senators Josh Hawley, a Missouri Republican, and Chris Murphy, a Connecticut Democrat, announced a bill that would make the operators of AI agents criminally and civilly liable "for knowing operation of an AI agent that recklessly causes computer hacking damage or loss," and would also hold developers liable for failing to put reasonable safeguards in place.

The signals do not line up. Reuters headlined Ferguson's remarks as developers being liable for their agents' conduct, his quote names whoever gave the order, and the bill reaches both. Cobun Zweifel-Keegan of the International Association of Privacy Professionals reads the week as developers and deployers both being on the hook. Where the responsibility will land is still anyone's guess.

An AI agent books, pays, emails and changes records using access someone granted and a task someone set. When it does harm, the questions will be who set the task, what it could touch and what the logs show. For a mid-sized manufacturer, that includes the purchasing assistant your accounting vendor switched on in an update and the bot answering order emails. If liability lands on whoever set the task, the indemnity clause in the vendor contract decides how much of a loss you can push back to the vendor.

The Takeaway
Regulators and lawmakers are converging on one question about AI agents: who told it to do that. The best position right now is knowing what your agents are doing before anyone asks, including the ones a vendor switched on in an update.
Sources: IAPP: A view from DC, the FTC says your company's agents are your problem · Reuters (syndicated): FTC chair pushes back on treating AI agents as independent actors · PYMNTS: FTC chair says companies cannot blame AI agents for their actions · aiweekly.co: FTC's Ferguson says developers, not AI agents, own the liability · Bloomberg Law: Bessent targets OpenAI managers for Hugging Face incident blame · CBS News: FTC investigation of OpenAI and Anthropic over AI safety · Senator Hawley: Hawley and Murphy announce bipartisan AI Agent Accountability Act

3. Matching Price Hikes by Box Makers Are Enough for a Price-Fixing Case to Proceed, a Judge Says

Six suppliers raised prices by the same amount on the same day, and the court found that plausible enough to move forward.

Ten companies that make containerboard and corrugated boxes, including Packaging Corporation of America, International Paper, Smurfit Kappa, WestRock, Georgia-Pacific, Pratt Industries, Greif and Cascades, are defendants in a federal price-fixing class action, and on September 4 a judge in Chicago refused to dismiss it. The plaintiffs are businesses that bought containerboard products directly from the defendants since November 2020, and no class has been certified yet. Containerboard is the flat and fluted sheets that make up a box wall.

The complaint alleges that seven rounds of parallel price increases since 2020 raised prices about 30%, and that the defendants hold 85% or more of the market. The judge found six of the seven rounds plausibly coordinated. Her anchor fact: "after approximately two and a half years without an industry price increase, six Defendants implemented on the same day a $50-per-ton increase on both linerboard and corrugating medium." The plaintiff has no direct evidence of an agreement, and the ruling says only that the claim is plausible enough to go forward to discovery, where the defendants' internal documents get exchanged. It is not a finding that prices were fixed.

The Takeaway
The case rests on one pattern: suppliers raising prices by the same amount on the same day after years of no increases. It may be worth looking back at your own suppliers' price changes, in boxes and in anything else you buy from a handful of big sellers, for increases that moved in step.
Sources: CourtListener: Artuso Pastry Foods Corp. v. Packaging Corp. of America, opinion denying motions to dismiss (docket entry 148) · A&O Shearman: District court denies cardboard makers' motion to dismiss in price-fixing class action

4. Patching Your Remote-Access Appliance Can Erase the Proof You Were Breached

The federal advice on two Citrix flaws is to look for a break-in before you patch, because the patch may destroy the evidence.

Citrix NetScaler is the gateway many companies use to let staff and vendors log in remotely. Citrix disclosed eight flaws in it on September 27, and two are rated critical and let an attacker run commands on the device from the internet. Both are on the US cyber agency CISA's list of flaws known to be exploited, and attackers were using them before Citrix had a fix. CISA says "threat actors are actively exploiting these vulnerabilities globally," and Shadowserver, a nonprofit that scans the internet for exposed systems, counts more than 20,000 reachable devices.

The usual response is to patch immediately. CISA encourages organizations to check for signs of a break-in first, and to preserve forensic evidence if they suspect one, because "updates may result in loss of forensic visibility." Patch first and you may lose the only record of whether anyone got in, which is what an insurer, outside lawyers or a regulator will ask you for later.

The Takeaway
If you run the appliance yourself, take a snapshot or export the logs before you patch. If a provider runs it, ask whether they did that before patching, and put it in the contract so it happens every time.
Sources: CISA: Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC and Gateway · NIST NVD: CVE-2026-88771 · Cybersecurity Dive: Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts

5. Stolen Passwords Opened France's Tax Portals, and the Gaps Are Common Ones

Two incidents, one cause: valid logins from computers the tax authority did not manage, on portals with gaps in monitoring.

On August 12, an actor calling itself Zerobytes claimed on a forum to have stolen taxpayer data from France's tax authority, the DGFiP. ANSSI, France's national cybersecurity agency, said in a report published September 29 that the theft had begun seven weeks earlier and was "not the consequence of a sophisticated attack." The attacker logged in with the credentials of dozens of tax agents, "probably compromised via infostealers on computers not administered by DGFiP," infostealers being malware that copies saved passwords off a personal computer. The agent portals had no MFA, the second login step beyond a password. The tax authority's security team was not monitoring one of the portals, or analyzing the night-time logins and abnormal data volumes. A password reset on June 24 did not end the attacker's live sessions: the accounts were reset, but the sessions already open were never revoked, so the data kept flowing. The attacker claims up to 680,000 records, a count the report does not verify.

A second incident, claimed the next day, took land-registry data through a portal for surveyors. Its second login step was a code sent by email, and the report says a compromised computer at a private surveyor's firm defeated it. An emailed code only works as a second step if the mailbox is protected separately from the password.

ANSSI's advice is plain: keep personal devices off professional systems, don't rely on an emailed code when the mailbox is protected by a password alone, send every application's logins to central monitoring, and end every live session when a password is reset.

The Takeaway
The attackers needed nothing clever: stolen passwords, no second step, and nobody watching the logs. Any portal your company runs that works the same way is one infected laptop away from the same result. It is worth knowing whether anyone would notice an unusual login to yours.
Sources: ANSSI: Rapport d'incident, cyberattaques ayant touché la DGFiP (PDF, French) · ANSSI: L'ANSSI publie le rapport d'incident sur les cyberattaques ayant touché la DGFiP · State of the Threat: Daily brief, September 30, 2026

6. Shipping Lines Keep Changing Their Minds About Whether the Red Sea Is Safe

About 140 container ships have gone back to Suez since May, and a reported Saudi offensive could put that route in doubt again.

Shipping lines sent their ships the long way around Africa because the Red Sea was not safe. Since May, Linerlytica, a container-shipping analyst, estimates that about 140 ships, just over 2 million twenty-foot container units of capacity, have switched back to the Suez route because it looks safe enough again. Maersk and Hapag-Lloyd's joint network, Gemini, announced four more returning services on September 14 to 16, saying future routing depends on the Red Sea staying stable, and the Premier Alliance of ONE, HMM and Yang Ming is sending the ONE Continuity from Thailand in mid-October to reach Suez in early November.

It may not stay stable. Six people with knowledge of the plans told Reuters on October 2 that the Houthis have taken control of Bab el-Mandeb, the narrow passage at the southern end of the Red Sea that every ship on this route has to use, and that Saudi Arabia is planning an offensive to retake it, led by Yemeni forces and overseen by Riyadh. Their estimates of the timing range "from within a week to until after the US midterm elections in early November." Fighting has since intensified: the Saudi-led coalition said it carried out 97 targeting operations against Houthi positions overnight into Sunday, and the Houthis claimed an attack on an Aramco facility in Riyadh, which the coalition called misleading.

The route is moving prices. Drewry, a shipping research firm, says Asia-Europe container rates have fallen for 12 straight weeks, helped by more ships transiting Suez, which adds capacity, and that carriers plan higher rates for the second half of October. A ship pushed back onto the Cape route takes that capacity away and adds one to two weeks of transit.

The Takeaway
Freight on this route has been getting cheaper because ships are back on the short way. If the Red Sea closes again, those costs are likely to climb, and the increase lands on whoever pays for the freight: importers, producers and, through them, customers.
Sources: gCaptain: Premier Alliance prepares for Asia-North Europe services' return to Suez · gCaptain: Saudis plan assault on Houthis to break Red Sea chokehold · Al Jazeera: Houthis claim strike on Saudi energy facility as Yemen fighting intensifies · gCaptain: Container shipping returns to Suez despite rising Red Sea risks · Food Business MEA: Maersk and Hapag-Lloyd return four more Gemini services to the Suez Canal · Hellenic Shipping News: Drewry, World Container Index down 1% last week (October 1 assessment)

7. Europe Heads Into Winter With Less Gas in Storage and Fewer Places to Get More

Norway and the United States supplied more than half of Europe's gas in 2025, Russia is being phased out, and the Iran conflict has cut off much of the Gulf LNG that made up almost a fifth of world supply.

Europe imports most of its gas. In 2025, according to the Council of the EU, about 31% came from Norway, mostly by pipeline, 26% from the United States, almost all of it liquefied natural gas, or LNG, 13% from North Africa and 12.5% from Russia, with Qatar under 4%. Russia is on its way out, slowly: the EU has ended short-term Russian contracts, long-term Russian LNG contracts end on December 31, and long-term pipeline contracts run until September 30, 2027.

The shortage is global. Before the Iran conflict the Strait of Hormuz carried almost 20% of the world's LNG, according to the International Energy Agency, and flows remain well below pre-war levels even after June's interim US-Iran agreement. Qatar sold little directly to Europe, but Asian buyers are now competing for the same US cargoes, and Norway's pipelines are already running near capacity.

Europe also did not fill its tanks. Summer gas cost more than winter gas, so traders had little reason to pay to store it, and EU storage was 68% full on September 12 against 80% a year earlier, the lowest at this point in the year since the think tank IEEFA's records start in 2011. The European Commission says there are no immediate risks to supply, and it has allowed countries to aim for 80% storage this year instead of the usual 90% target.

Prices show it. The benchmark European gas price was about EUR 75 per megawatt-hour on October 2, up about 138% from a year earlier, and euro-area inflation was estimated at 3.8% in September, with energy up 18.8%, in Eurostat's flash estimate. Eurofer, the EU steel industry body, says high prices "will inevitably lead to production disruptions," and the chemicals maker Ineos said on September 22 it is mothballing three plants in Hull, England, citing energy costs.

The Takeaway
Europe's gas supply has little slack, so a cold winter lands on prices first. If you run sites in Europe or buy from gas-heavy suppliers such as chemicals, steel or aluminum, it may be worth knowing which of them could pass energy costs on through surcharges or price clauses.
Sources: Council of the EU: Where does the EU's gas come from? · ACER: Russian gas imports into the EU, 2026 report · International Energy Agency: Gas Market Report, Q3-2026 · IEEFA: Europe bets on a mild winter when it should be cutting gas demand · Politico: EU Commission calls for gas and electricity demand cuts · Trading Economics: EU natural gas (Dutch TTF) · Eurostat: Euro area annual inflation up to 3.8% · The Guardian: Europe faces a bleak winter as supply shock pushes factories to the brink · Reuters via Euronext: Ineos to mothball three chemical plants as high energy costs hit production

Get this brief in your inbox every Sunday.

No tracking. No spam. One email per week.

Subscribe