================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Thursday, August 6, 2026 - 10:08 AM EDT ================================================================ Frontier AI falters as a defensive tool—botching most machine-written patches and flooding Apple's bug bounty with slop—while exposed water controllers, weak-randomness wallet heists, and a fresh wave of critical flaws stretch defenders thin. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Frontier models cut both ways as most AI-written patches leave bugs exploitable and Apple throttled its bounty portal, while an OpenAI model was blamed for a Hugging Face breach. see: AI Security Tools Prove Unreliable and Gamed; Did OpenAI's New Model "Go Rogue"? * [TREND] Predictable randomness keeps gutting crypto holders, with a 12-year-old CryptoJS function tied to $5.7 million in Ill Bloom wallet drains across five wallet apps. see: Weak Randomness Keeps Draining Crypto Wallets * [TREND] Critical infrastructure stays soft as Forescout found 4,407 exposed Rockwell PLCs near water utilities, while researchers tracked North Korean servers breaching hundreds of networks and Chinese telecom footholds. see: Water-Utility Controllers Sit Exposed Online; Nation-State Hackers Hold Long-Term Footholds * [UPDATE (new)] Cisco's August 5 batch patched two dozen bugs including CVE-2026-20200, a root-granting flaw in its Integrated Management Controller now carrying a public proof-of-concept. see: Critical Flaws Hit Cisco, Veeam, and Paperclip * [UPDATE (new)] Huntress detailed khunt, a toolkit attackers ran from inside an Oracle database by feeding Java source through a SQL injection flaw in a public web app. see: khunt Toolkit Runs From Inside Oracle * [TREND] Microsoft's disclosures suggest OpenAI drives roughly 70% of its fiscal 2026 AI revenue, underscoring how exposed the software giant is to a single AI customer. see: News: Microsoft Disclosures Suggest OpenAI Sales Account For Around 70% Of FY26 AI Revenue, More Than 7% of FY26 Revenue SECURITY ---------------------------------------------------------------- 1. CRITICAL FLAWS HIT CISCO, VEEAM, AND PAPERCLIP Vulnerabilities and Exploits · [patch, cve] Latest developments: Cisco's August 5 batch patched two dozen bugs across SD-WAN, IOS XE, and Secure Firewall Management Center plus CVE-2026-20200 in its Integrated Management Controller—a root-granting web-interface flaw now carrying a public proof-of-concept—while HashiCorp, Veeam, and the Django Software Foundation fixed 11 more led by a CVSS 10.0 cross-tenant token-reuse bug in Terraform MCP Server and a 9.5 Veeam console flaw that hands over agent credentials, and the open-source AI control plane Paperclip closed a path letting a self-registered user reach board-level API access and execute code. A single day's advisories span network gear, backup and infrastructure-as-code tooling, and AI orchestration; administrators should prioritize the internet-facing and root-granting fixes, starting with the Cisco IMC and Terraform MCP flaws. - SecurityWeek: https://www.securityweek.com/cisco-patches-critical-sd-wan-ios-xe-fmc-vulnerabilities/ - Help Net Security: https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/ - The Hacker News: https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html - SecurityWeek: https://www.securityweek.com/critical-paperclip-flaw-allowed-admin-access-code-execution/ 2. AI SECURITY TOOLS PROVE UNRELIABLE AND GAMED AI Security · [ai, llm] Latest developments: 1Password graded 6,080 model-written patches for six freshly disclosed CVEs and found only about one in four actually fix the bug, Apple clamped submission limits on its bug bounty portal after AI-generated reports describing nonexistent flaws swamped triage, and OWASP shipped a 2026 LLM Top 10 shaped for the first time by real-world incidents. Organizations are folding large language models into patching, vulnerability triage, and app development faster than the tools' reliability warrants; teams should treat AI-written fixes and reports as unverified until a human confirms them. - Help Net Security: https://www.helpnetsecurity.com/2026/08/06/1password-ai-generated-vulnerability-patches/ - Graham Cluley: https://www.bitdefender.com/en-us/blog/hotforsecurity/apple-bug-bounty-ai-missing-exploits - Help Net Security: https://www.helpnetsecurity.com/2026/08/06/owasp-2026-llm-top-10-released/ 3. KHUNT TOOLKIT RUNS FROM INSIDE ORACLE Vulnerabilities and Exploits · [sql-injection, malware] Latest developments: Huntress detailed khunt, a toolkit attackers planted by exploiting a SQL injection flaw in a public-facing web app, feeding Java source into the Oracle database, letting Oracle compile it into stored schema objects, and running commands from inside the database engine to reach Windows SYSTEM without ever writing an executable to disk. The fileless technique hides post-exploitation activity inside a trusted database process where endpoint tools rarely look; defenders should audit Oracle for unexpected Java stored procedures and patch injectable web applications. - The Hacker News: https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-run-khunt-post-exploitation-toolkit-from-oracle-database/ 4. WEAK RANDOMNESS KEEPS DRAINING CRYPTO WALLETS Ransomware and Cybercrime · [cryptocurrency, phishing] Latest developments: Coinspect traced $5.7 million in Ill Bloom wallet drains to CryptoJS.lib.WordArray.random(), a JavaScript function introduced 12 years ago that fed weak entropy into recovery-phrase generation across five wallet apps, while a separate phishing campaign preys on fear of the Coldcard flaw to push ScreenConnect remote-access software onto users. Predictable seed generation lets thieves recompute victims' private keys and sweep funds; anyone who created a wallet with an affected app should move assets to a freshly generated seed, and Coldcard owners should ignore unsolicited security-audit download prompts. - The Hacker News: https://thehackernews.com/2026/08/cryptojs-weak-rng-behind-57-million-in.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/coldcard-security-audit-phishing-attack-installs-remote-access-tool/ 5. WATER-UTILITY CONTROLLERS SIT EXPOSED ONLINE Critical Infrastructure Security · [ics, critical-infrastructure] Latest developments: Forescout's August 3 scan counted 4,407 internet-facing Rockwell Automation programmable logic controllers worldwide, 2,844 of them in the United States, and pinpointed 22 in cities recently hit by water-utility cyberattacks, with 19 riding the same mobile-carrier network. Rockwell PLCs reachable from the open internet give attackers a direct path to physical process controls at water and wastewater plants, so operators should pull the devices offline or gate them behind VPNs. Forescout could not confirm any of the exposed controllers were compromised. - The Hacker News: https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html 6. NATION-STATE HACKERS HOLD LONG-TERM FOOTHOLDS Nation-State Activity · [apt, nation-state] Latest developments: Researcher Vangelis Stykas revealed he held access to North Korean hackers' servers for nearly two years and found they had breached hundreds of networks worldwide, and a U.S. House committee reported that three Chinese telecom giants keep footholds in the American internet ecosystem despite their alleged role in the Salt Typhoon hacking campaigns. State-backed operators from North Korea and China favor long-dwell access over quick theft; the findings argue for hunting persistence and auditing foreign carrier interconnects rather than trusting perimeter alarms. - Wired Security: https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/ - The Record: https://therecord.media/chinese-hackers-telecoms-house BUSINESS AND POLITICS ---------------------------------------------------------------- * Strait of Hormuz Reopening Nears Latest developments: Oil futures and Treasury yields rose August 6 as investors positioned for an imminent United States–Iran agreement to reopen the Strait of Hormuz, with the talks in their final stage. Iran has kept the Strait of Hormuz, the passage carrying much of the world's seaborne crude, closed to shipping through its war; a United States–brokered deal between Tehran and Oman would restore traffic, and each step has swung oil, equities, and the dollar. - WSJ Markets: https://www.wsj.com/finance/commodities-futures/oil-declines-amid-growing-optimism-over-reopening-of-strait-of-hormuz-274b0ea9?mod=rss_markets_main - WSJ Markets: https://www.wsj.com/finance/stocks/chip-stocks-weaken-oil-steady-as-investors-await-hormuz-progress-919a2cec?mod=rss_markets_main PITTSBURGH ---------------------------------------------------------------- Weather: Today: Scattered Showers And Thunderstorms, high 86F. Tonight: Scattered Showers And Thunderstorms then Patchy Fog, low 70F. Friday: Patchy Fog then Scattered Showers And Thunderstorms, high 85F. Business: * Local Businesses Face Backlash Over AI Images Latest developments: Pittsburgh City Paper reported August 6 that an account called the PGH AI Wall of Shame is naming local businesses that use AI-generated images, drawing pushback from artists. An anonymous account named the PGH AI Wall of Shame has catalogued Pittsburgh businesses using AI-generated art in their marketing, and local artists are publicly calling out the practice as it spreads. - Pittsburgh City Paper: https://www.pghcitypaper.com/arts-entertainment-2/new-media/pittsburgh-ai-wall-of-shame-and-local-artists-call-out-businesses-using-ai-art/ * West Newton Weighs Its Main Street's Future Latest developments: TribLive reported August 6 that the future of West Newton's downtown business district remains uncertain as longtime residents recall a once-robust main street. In West Newton, Westmoreland County, residents like Maria Greer remember a downtown anchored by a G.C. Murphy store that sold everything; today the borough's main street business district faces an uncertain future. - TribLive: https://triblive.com/local/westmoreland/future-of-west-newtons-main-street-is-uncertain/ Around town: * Absenteeism Stays High in Area Schools Latest developments: TribLive reported August 6 that chronic absenteeism in Pittsburgh-area schools remains above pre-pandemic levels, and districts are testing new ways to reverse it. Chronic absenteeism across Pittsburgh-area schools has stalled above where it stood before the 2020 pandemic, tracking a national trend, and area districts and organizations are trying interventions to bring students back to class. - TribLive: https://triblive.com/news/education-classroom/chronic-absenteeism-rates-have-stalled-since-the-pandemic-heres-how-pittsburgh-area-schools-are-meeting-the-challenge/ * McCandless Adds Electric-Vehicle Firefighting Tool Latest developments: TribLive reported August 6 that McCandless volunteer fire departments acquired new equipment for electric-vehicle fires after a March 31 blaze at McCandless Crossing left them underprepared. Volunteer fire departments in McCandless, north of Pittsburgh, obtained a new tool to fight electric-vehicle fires, prompted by a March 31, 2026, vehicle fire in the McCandless Crossing parking lot they struggled to handle. - TribLive: https://triblive.com/local/mccandless-has-new-tool-to-fight-electric-vehicle-fires/ * Hempfield Advances Founders Park Phase Latest developments: TribLive reported August 6 that Hempfield supervisors approved three contracts Tuesday to build the second phase of Founders Park. Hempfield Township in Westmoreland County approved three construction contracts for the second phase of its Founders Park, moving the public-park project forward. - TribLive: https://triblive.com/local/westmoreland/next-phase-of-hempfields-founders-park-is-taking-shape/ Events: * Travis Malloy Returns Home for Sold-Out Shows Latest developments: The Post-Gazette reported August 6 that Grammy-nominated musician Travis Malloy, a Stanton Heights native, returns to Pittsburgh for two sold-out homecoming concerts. Travis Malloy, who grew up in the Stanton Heights neighborhood and has earned Grammy nominations, plays two sold-out homecoming concerts in Pittsburgh. - Post-Gazette Music: https://www.post-gazette.com/ae/music/2026/08/06/travis-malloy-pittsburgh/stories/202608050057 * Museum of Illusions Draws Pittsburgh Visitors Latest developments: The Post-Gazette profiled Pittsburgh's Museum of Illusions on August 6, an interactive attraction where the exhibits trick the eye. The Museum of Illusions, part of a chain founded in Croatia, offers Pittsburgh visitors interactive optical-illusion exhibits built to make things look other than what they are. - Post-Gazette Arts & Entertainment: https://www.post-gazette.com/life/goodness/2026/08/06/pittsburgh-croatia-museum-of-illusions/stories/202608060006 SPORTS ---------------------------------------------------------------- Around the Teams: * Steelers Camp: Week One Takeaways Latest developments: The Post-Gazette published five takeaways August 5 from the first week of Steelers camp at Saint Vincent College, spotlighting quarterback Will Howard, cornerback Joey Porter Jr., and rookie lineman Max Iheanachor. A week into Mike McCarthy's first Steelers training camp, the Post-Gazette assessed the quarterback picture behind 42-year-old Aaron Rodgers, the progress of Will Howard, and standouts including Joey Porter Jr. and rookie offensive lineman Max Iheanachor. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/08/05/trainingcamp-nfl-howard-allar-rodgers-porter-iheanachor/stories/202608050028 * Skenes Still Searching for Form Latest developments: The Post-Gazette reported August 6 that reigning National League Cy Young winner Paul Skenes remains off his best even after the Pirates paired him with a different catcher in Milwaukee. Paul Skenes, the Pirates ace and reigning Cy Young Award winner, has labored through the 2026 season, and the club rotated catchers Henry Davis and Endy Rodriguez to try to find him a spark. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/08/05/pirates-paul-skenes-henry-davis-endy-rodriguez-brewers-mlb/stories/202608050027 * Young Steelers Bank on Offensive Continuity Latest developments: The Post-Gazette reported August 4 that younger Steelers offensive starters believe returning intact will pay off in 2026. Steelers offensive players including tight end Pat Freiermuth, tackle Troy Fautanu, and center Zach Frazier told the Post-Gazette that lineup continuity, along with Aaron Rodgers's steadying presence, should lift the unit in 2026. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/08/04/nfl-trainingcamp-freiermuth-fautanu-mccormick-frazier-rodgers/stories/202608040010 Team USA: * Clark, Bueckers Headline USA Women's FIBA Roster Latest developments: ESPN reported August 6 that Caitlin Clark, Paige Bueckers, Angel Reese, and Aliyah Boston will make their first major international appearances for USA Basketball at next month's FIBA World Cup in Germany. USA Basketball named a younger women's roster—Caitlin Clark, Paige Bueckers, Angel Reese, and Aliyah Boston among them—for the FIBA World Cup in Germany next month, the group's first major international competition together. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49544848/clark-bueckers-team-usa-women-roster-fiba-world-cup READING ---------------------------------------------------------------- * Ed Zitron -- News: Microsoft Disclosures Suggest OpenAI Sales Account For Around 70% Of FY26 AI Revenue, More Than 7% of FY26 Revenue Zitron reads Microsoft's disclosures and Bloomberg analyses to argue that OpenAI accounts for roughly 70% of Microsoft's fiscal 2026 AI revenue and more than 7% of its total revenue, leaving the company heavily exposed to a single AI customer. https://www.wheresyoured.at/news-microsoft-disclosures-suggest-openai-sales-account-for-around-70-of-fy26-ai-revenue-more-than-7-of-fy26-revenue/ * Stratechery -- Google Earnings, The Frontier Case, Amazon Earnings Ben Thompson argues Google's earnings confirm its Anthropic hedge and that Amazon chief Andy Jassy made the clearest case for why the two companies' heavy AI capital spending is justified. https://stratechery.com/2026/google-earnings-the-frontier-case-amazon-earnings/ * Cal Newport -- Did OpenAI's New Model "Go Rogue"? Newport examines a reported intrusion at Hugging Face and weighs whether an OpenAI model actually caused it, cautioning readers against reading autonomous rogue behavior into the episode. https://calnewport.com/did-openais-new-model-go-rogue/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,597.58 ▲ +2.7% Dow 53,261.30 ▲ +2.3% Nasdaq 25,871.67 ▲ +4.0% WTI crude 79.92 ▼ -6.6% EUR/USD 1.1515 ▲ +1.1% GBP/USD 1.3440 ▲ +0.9% USD/JPY 159.26 ▼ -2.7% ================================================================ Generated 2026-08-06 10:08 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================