infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

Black Hat USA 2026 unleashed new attack classes against NAT tables, HTTP parsers, and Microsoft identity even as the Head Mare crew trojanized TrueConf installers to plant backdoors.


Emerging Trends and Key Updates

Security

1. Flock and ICE Widen Surveillance Reach

Policy and Regulation · [surveillance, privacy, policy]

Latest developments: A leaked Flock presentation showed the company planned to enlist roughly 350,000 Uber, Lyft, and delivery drivers as roaming license-plate collectors for its surveillance network, and Bruce Schneier reported that ICE is buying access to Americans' credit card records through data brokers.

read more

Flock, which already blankets US streets with fixed license-plate cameras, sought to co-opt about 350,000 gig drivers into a mobile dragnet, and ICE is purchasing credit card data through brokers. Both moves push surveillance from public infrastructure into everyday commerce.

Sources: 404 Media · Wired Security · Schneier on Security · ↑ top

2. Head Mare Backdoors TrueConf Video Installers

Software Supply Chain · [supply-chain, backdoor]

Latest developments: BleepingComputer reported that the Head Mare hacktivist group exploited unpatched TrueConf video conferencing servers to swap client installers for trojanized builds that plant backdoors on everyone who downloads them.

read more

TrueConf sells on-premises video conferencing servers widely deployed at Russian enterprises and government bodies, the usual prey of the pro-Ukraine Head Mare crew. Administrators running unpatched servers should patch, verify installer hashes, and hunt for planted backdoors.

Sources: BleepingComputer · ↑ top

3. No-Reply Email Domains Leak Corporate Secrets

Data Breaches · [data-exposure, breach]

Latest developments: Wired reported that two security researchers bought cheap domains including noreply.net and deleteduser.com, stood up email listening services, and found hundreds of companies routing corporate secrets straight into their inboxes.

read more

Automated systems fire messages to no-reply addresses no one owns, and buying those domains turned two researchers into passive recipients of hundreds of companies' internal data. Organizations should own and monitor their sender domains and stop mailing sensitive content to unmonitored addresses.

Sources: Wired Security · ↑ top

4. Black Hat Reveals NatJack and HTTP Terminator Attacks

Vulnerabilities and Exploits · [research, zero-day]

Latest developments: At Black Hat USA 2026, Malcolm Stagg disclosed NatJack, which manipulates network address translation state to hijack live TCP sessions, spoof DNS, expose mapped ports, and exhaust NAT tables across Windows and other implementations, while PortSwigger's James Kettle showed HTTP Terminator, an AI-assisted system that proved new HTTP desynchronization techniques across 30,000 candidate vectors and surfaced a zero-day in Apache Traffic Server.

read more

NatJack and HTTP Terminator both strike core internet machinery—NAT connection tracking and HTTP request parsing—and reproduce across independently built products. Operators should watch for vendor advisories and update Apache Traffic Server, which carries the disclosed zero-day.

Sources: The Hacker News · The Hacker News · ↑ top

5. Attackers Target Microsoft Entra Identity

Vulnerabilities and Exploits · [identity, phishing]

Latest developments: Entra ID researcher Dirk-jan Mollema showed that malware in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID, register a rogue device, grab a Primary Refresh Token, and add authentication methods for lasting cloud access, as researchers separately tracked a widespread adversary-in-the-middle campaign that hijacks Microsoft 365 accounts through residential proxies to harvest payroll and finance email.

read more

Windows Hello for Business abuse gives malware already on a machine durable Entra ID footholds, and the adversary-in-the-middle campaign steals Microsoft 365 sessions from finance staff. Enforce phishing-resistant, device-bound authentication and review Entra device registrations and sign-in logs.

Sources: The Hacker News · The Hacker News · ↑ top

6. AI Coding Agents Expose CI Secrets

AI Security · [ai, vulnerability]

Latest developments: Novee Security, presenting at Black Hat USA on August 5, showed that a GitHub issue opened by an account with no repository privileges executed code on the CI runners behind Anthropic's Claude Code and Google's Gemini CLI and hijacked the next agent run on OpenAI's, each in the vendor's default shipping configuration, while Irregular, the firm behind recent AI hacking incidents involving Anthropic, OpenAI, and Meta models, declined to say whether more occurred.

read more

The default configurations of Claude Code, Gemini CLI, and OpenAI's coding agent let an untrusted GitHub issue reach CI runners and secrets. Teams running these agents should sandbox them, strip secret access from untrusted triggers, and gate agent runs behind human review.

Sources: The Hacker News · The Record · ↑ top

Business and Politics

Iran Sets Hormuz Terms, Strikes UAE Ship

Latest developments: Iran issued formal conditions Saturday for reopening the Strait of Hormuz—a U.S. military pullback from the Gulf and compensation for war damage—as the United Arab Emirates said an Iranian missile struck one of its ships in the waterway.

read more

Tehran demands Washington rectify its behavior and pay reparations before lifting its closure of the Strait of Hormuz, the passage for roughly a fifth of the world's seaborne oil, while a U.S. naval blockade keeps Iranian crude bottled up at Kharg Island and the UAE now reports its shipping under Iranian fire.

Sources: WSJ World News · FT Markets · ↑ top

Senate Advances Graham Russia Sanctions

Latest developments: The Senate voted 86-11 to advance Senator Lindsey Graham's long-stalled package of sanctions and tariffs targeting Russia over its war in Ukraine.

read more

The measure would impose fresh sanctions and steep tariffs aimed at countries buying Russian energy, sharply escalating U.S. economic pressure on President Vladimir Putin as Russian strikes continue to kill civilians in Kyiv.

Sources: WSJ World News · ↑ top

Pittsburgh

Weather

Tonight: Chance Showers And Thunderstorms, low 68F.

Sunday: Mostly Sunny, high 87F.

Sunday Night: Partly Cloudy then Slight Chance Showers And Thunderstorms, low 68F.

Business

Peoples Gas Pipeline Overhaul Starts Monday

Latest developments: Peoples Natural Gas begins its pipeline modernization Monday, August 10, with intermittent street work running through spring 2027, the utility said, firming up the plan first disclosed August 6.

read more

Peoples Natural Gas will replace aging gas mains across parts of Pittsburgh's Lawrenceville and Strip District neighborhoods, intermittently closing streets into 2027.

Sources: WPXI · ↑ top

Chicago Pair Charged in Dick's Gift-Card Scheme

Latest developments: Westmoreland County detectives charged a Chicago man and woman Friday in a nationwide gift-card fraud scheme that targeted Dick's Sporting Goods stores across Pennsylvania.

read more

State investigators say the two ran a gift-card scam hitting Dick's Sporting Goods locations statewide; the retailer is headquartered in Coraopolis outside Pittsburgh.

Sources: TribLive · ↑ top

Around Town

Pittsburgh Paramedic Resigns Over Second Job

Latest developments: A veteran Pittsburgh paramedic suspended last week without pay for allegedly holding a second county job in violation of the city's Home Rule Charter resigned Saturday.

read more

The city medic left rather than fight allegations he violated Pittsburgh's Home Rule Charter ban on dual public employment by also working for Allegheny County.

Sources: WTAE · ↑ top

Kennywood's Jack Rabbit Named Landmark Coaster

Latest developments: American Coaster Enthusiasts recognized Kennywood's Jack Rabbit on Saturday among wooden roller coasters more than 100 years old.

read more

The Jack Rabbit, a wooden coaster at Kennywood Park in West Mifflin, received a designation honoring its century-plus of continuous operation.

Sources: WTAE · ↑ top

Severe Storms Tonight, Heavy Rain Next Week

Latest developments: Pittsburgh forecasters warned of isolated severe storms with strong winds across Western Pennsylvania on Saturday night, with more heavy rain expected Monday and Tuesday.

read more

After a brief dry lull, the region faces a return to heavy rain and storms early in the week, following downpours that downed power lines near an East Huntingdon Township tire shop Friday.

Sources: WTAE · ↑ top

Sports

Around the Teams

Pirates' Skid Turns Season-Defining

Latest developments: The Post-Gazette framed the Pirates' four-game losing streak, which dropped them to last in the National League Central, as potentially season-defining for their fading wild-card hopes.

read more

The paper's 11-point breakdown weighs the fates of ace Paul Skenes and shortstop O'Neil Cruz as Pittsburgh's postseason window narrows.

Sources: Post-Gazette Pirates · ↑ top

Team USA

Johnson Explains Grand Slam Track Payment

Latest developments: Four-time Olympic gold medalist Michael Johnson said a disputed payment tied to the collapse of his Grand Slam Track league was a reimbursement, calling the fallout the most stressful stretch he has faced in years.

read more

Johnson, the American sprint great who founded the now-failed Grand Slam Track circuit, addressed the financial wreckage of its aborted launch and clarified that money he received was to cover expenses.

Sources: ESPN Olympics · ↑ top

Reading

Markets

weekly average, change vs prior week

S&P 500     7,705.63  ▲ +3.9%
Dow        53,907.09  ▲ +3.2%
Nasdaq     26,380.26  ▲ +5.7%
WTI crude      77.36  ▼ -6.7%
EUR/USD       1.1537  ▲ +0.7%
GBP/USD       1.3459  ▲ +0.8%
USD/JPY       157.80  ▼ -2.4%