infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

A self-propagating npm worm poisoned more than 1,300 packages carrying two billion monthly downloads, as fresh evidence showed criminals turning AI coding tools into everyday offensive weapons.


Emerging Trends and Key Updates

Security

1. Adversaries Weaponize AI Coding Tools

AI Security · [ai, malware, infostealer]

Latest developments: Cisco Talos published prompt logs it pulled directly from threat-actor endpoints running Claude Code, CodeX, Cursor, and Gemini, and Netskope Threat Labs found criminals cloning popular AI-tool GitHub repositories to spread a Windows infostealer through the ClickFix trick.

read more

Frontier models increasingly serve as a tireless junior hacker for any adversary, from criminals coaxing chatbots into writing exploits to trojanized GitHub clones that lure AI developers into running infostealers. Security teams should treat AI coding assistants as a new class of actor and monitor for ClickFix social-engineering lures.

Sources: Cisco Talos · Help Net Security · The Hacker News · ↑ top

2. AI Agents and Chats Spill Secrets

AI Security · [ai, data-leak, agent]

Latest developments: Schneier reported that some Claude conversations turned up searchable on Google, exposing cryptocurrency wallet keys, home addresses, and medical billing data through a user data-sharing setting Anthropic calls the customer's responsibility, while SecurityWeek detailed a Gemini agent-to-agent attack that passed a malicious hand-off comment from a low-privilege Google ADK agent to a privileged one, exposing secrets and tampering with pull requests.

read more

Autonomous AI assistants keep leaking data their users assumed stayed private, from indexed chat logs to prompt-injected agent workflows. Google deleted three workflows from its Agent Development Kit after Pillar Security showed a public GitHub issue could trigger the privileged code-fixing agent; organizations should restrict agent permissions and audit data-sharing defaults.

Sources: Schneier on Security · The Hacker News · SecurityWeek · ↑ top

3. ChainDrop npm Worm Poisons Hundreds of Packages

Software Supply Chain · [supply-chain, npm, worm]

Latest developments: A credential-stealing worm that surfaced in keyv@6.0.0 self-propagated across the npm registry on August 4, 2026, spreading beyond the Keyv and Cacheable namespaces into hundreds of packages and planting Claude Code and VS Code hooks to persist.

read more

The worm, which BleepingComputer tracks as ChainDrop, has compromised more than 1,300 npm packages carrying a combined two billion monthly downloads; SafeDep verified 353 poisoned versions across 79 package names, and Aikido counted at least 868 affected packages. Developers should pin dependencies, audit lockfiles for the poisoned versions, and rotate any credentials exposed on build machines.

Sources: BleepingComputer · The Hacker News · ↑ top

4. Midnight Blizzard CaptiveCrunch Targets Hotel Wi-Fi

Nation-State Activity · [apt, nation-state, credential-theft]

Latest developments: Microsoft named the two malware strains behind the CaptiveCrunch campaign, CornFlake and ChocoShell, and confirmed Russia's Midnight Blizzard, the SVR-linked group also tracked as APT29, has spent months abusing public Wi-Fi at hotels and conference centers to steal Microsoft 365 credentials.

read more

Midnight Blizzard compromises hospitality Wi-Fi captive portals to push malware and harvest credentials from traveling executives and officials worldwide. Travelers should avoid signing into work accounts over untrusted public networks and rely on hardware-backed authentication.

Sources: Help Net Security · BleepingComputer · ↑ top

5. Passkey Hijacking and BMC Hash Leaks

Vulnerabilities and Exploits · [vulnerability, passkey, patch]

Latest developments: Researchers unveiled Pass-ta-key, three attacks that let malware on an already-compromised Windows machine hijack Google Password Manager's synced passkeys, bypass user verification, and extract passkey private keys, and SecurityWeek reported a decades-old baseboard management controller flaw exposing more than 24,000 internet-accessible server-management interfaces that disclose authentication hashes before login.

read more

Two disclosures undercut authentication assumptions: passkeys once presumed phishing-proof and the out-of-band controllers that administer data-center hardware. Operators should pull BMC interfaces off the public internet and harden endpoints against local malware that can reach synced passkeys.

Sources: BleepingComputer · SecurityWeek · ↑ top

6. Greatness PhaaS and SMOKE#SCREEN Campaigns

Ransomware and Cybercrime · [phishing, social-engineering, rmm]

Latest developments: The commercial phishing-as-a-service kit Greatness added device code phishing that abuses the OAuth 2.0 device authorization grant to bypass multifactor authentication and seize tokens, and Securonix detailed SMOKE#SCREEN, a multi-wave campaign using fake Adobe and Zoom update lures to install ConnectWise ScreenConnect for persistent remote access.

read more

Attackers keep automating MFA bypass and remote-access footholds through off-the-shelf crimeware and software-update lures, a shift Dark Reading measured as a 1,500% jump in device code phishing this year. Defenders should block device-code grants where unused and treat unsolicited update prompts as suspect.

Sources: The Hacker News · The Hacker News · ↑ top

Pittsburgh

Weather

This Afternoon: Sunny, high 87F.

Tonight: Mostly Clear, low 69F.

Wednesday: Mostly Sunny then Chance Showers And Thunderstorms, high 88F.

Business

Promise Confections Cuts Pearson's St. Paul Plant

Latest developments: WPXI reported August 4 that Pittsburgh-based Promise Confections will cut its Pearson's Candy plant in St. Paul, Minnesota.

read more

Pearson's, the maker of the Salted Nut Roll and Bun candy bars, operates under Pittsburgh's Promise Confections, which is reducing the brand's St. Paul, Minnesota, factory.

Sources: WPXI · ↑ top

Federal Grant Cancellations Mount at Pitt

Latest developments: The Post-Gazette reported August 4 that canceled federal research grants keep piling up at the University of Pittsburgh.

read more

The University of Pittsburgh continues to lose federal research funding as grant cancellations accumulate, squeezing one of the region's largest research and healthcare-science institutions.

Sources: Pittsburgh Post-Gazette · ↑ top

Saatva Opens Shadyside Showroom

Latest developments: TribLive reported August 4 that luxury sleep brand Saatva will open a brick-and-mortar showroom in Shadyside.

read more

Saatva, a luxury mattress and sleep brand, plans a showroom in the former Rite Aid space in Pittsburgh's Shadyside neighborhood.

Sources: TribLive · ↑ top

Around Town

Brentwood Elementary Opening Slips to 2027

Latest developments: The Brentwood Borough School District told parents its new elementary school will not open this fall and now targets 2027.

read more

Construction on Brentwood Borough's new elementary school, begun in October 2024 for a fall 2026 opening, fell behind, so the district pushed the building's debut to 2027.

Sources: KDKA · ↑ top

Pittsburgh Council Tightens Sidewalk Parking Rules

Latest developments: Pittsburgh City Council moved August 4 to strip code language that let drivers dodge citations for parking on sidewalks and in bike lanes.

read more

Pittsburgh City Council advanced a change to city code, removing wording that has allowed some drivers to avoid tickets for blocking sidewalks and bike lanes, strengthening enforcement.

Sources: WPXI · ↑ top

Montour Trail Posts E-Bike Rules in Peters

Latest developments: New signs on the Peters Township stretch of the Montour Trail now spell out e-bike and e-scooter regulations, KDKA reported August 4.

read more

The Montour Trail Council installed signage in Peters Township, one of the trail's busiest sections at 400,000 annual uses, warning that e-bikes and e-scooters capable of 50 to 60 mph must follow new safety limits.

Sources: KDKA · ↑ top

Events

Penguins Single-Game Tickets On Sale Wednesday

Latest developments: Pittsburgh Penguins single-game tickets go on sale Wednesday, August 5, WPXI reported.

read more

The Pittsburgh Penguins put individual-game tickets for the coming NHL season on sale Wednesday, August 5.

Sources: WPXI · ↑ top

Heinz History Center Adds Third Thursdays

Latest developments: The Heinz History Center will launch a monthly Third Thursdays program that extends its hours, WPXI reported August 4.

read more

The Senator John Heinz History Center in the Strip District is starting Third Thursdays, keeping the museum open the entire day one Thursday each month, with access included in regular admission.

Sources: WPXI · ↑ top

Sports

Around the Teams

Kaleb Johnson Eyes a Year 2 Rebound

Latest developments: The Post-Gazette reported August 3 that Steelers running back Kaleb Johnson is chasing a bigger role after a quiet rookie season.

read more

Kaleb Johnson never found his footing as a Steelers rookie, and now he is trying to work into the 2026 backfield behind Jaylen Warren and Rico Dowdle under quarterback Aaron Rodgers and coach Mike McCarthy.

Sources: Post-Gazette Steelers · ↑ top

Roman Wilson Has the Most to Gain

Latest developments: Post-Gazette columnist Noah Hiles wrote August 3 that receiver Roman Wilson has the most to gain of any Steeler this camp.

read more

Noah Hiles argued Steelers receiver Roman Wilson enters training camp with the most on the line, fighting for snaps against Germie Bernard, Michael Pittman Jr., and DK Metcalf.

Sources: Post-Gazette Steelers · ↑ top

Pirates Draft a Scout's Brother

Latest developments: The Post-Gazette's Off The Bat reported August 3 that the Pirates drafted Auburn's Chris Rembert, whose brother scouts for the club.

read more

The Pittsburgh Pirates used a draft pick on Auburn infielder Chris Rembert, whose brother Brandon works as a Pirates scout.

Sources: Post-Gazette Pirates · ↑ top

Team USA

USMNT Sets First Post-World Cup Fixtures

Latest developments: ESPN reported August 4 that the U.S. men host Peru, Chile, Canada, and Mexico in friendlies during the September and October FIFA window.

read more

The United States men's national team, back in action for the first time since its 2026 World Cup exit, will play friendlies against Peru, Chile, Canada, and Mexico across the country under Mauricio Pochettino.

Sources: ESPN Soccer · ↑ top

Reading

Markets

weekly average, change vs prior week

S&P 500     7,454.56  ▲ +0.1%
Dow        52,442.59  ▲ +0.7%
Nasdaq     25,145.96  ▼ -0.7%
WTI crude      82.46  ▼ -5.4%
EUR/USD       1.1458  ▲ +0.5%
GBP/USD       1.3379  ▲ +0.1%
USD/JPY       161.74  ▼ -0.9%