================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Saturday, August 8, 2026 - 7:37 PM EDT ================================================================ Black Hat USA 2026 unleashed new attack classes against NAT tables, HTTP parsers, and Microsoft identity even as the Head Mare crew trojanized TrueConf installers to plant backdoors. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Black Hat USA 2026 unleashed new attack classes, from Malcolm Stagg's NatJack targeting NAT tables to Novee's exploit hijacking CI runners behind Claude Code and Gemini CLI. see: Black Hat Reveals NatJack and HTTP Terminator Attacks; AI Coding Agents Expose CI Secrets * [TREND] Identity remains the front door as Dirk-jan Mollema showed malware can abuse Windows Hello keys for persistent Microsoft Entra ID access, echoing Unit 42's ninety-percent finding. see: Attackers Target Microsoft Entra Identity * [TREND] Commercial surveillance spreads beyond the camera pole as Flock pitches 350,000 rideshare drivers as roving plate readers while ICE buys Americans' credit-card records. see: Flock and ICE Widen Surveillance Reach * [UPDATE (new)] Iran set terms to reopen the Strait of Hormuz and struck a UAE ship as the Senate voted 86-11 to advance Graham's Russia sanctions. see: Iran Sets Hormuz Terms, Strikes UAE Ship; Senate Advances Graham Russia Sanctions * [UPDATE (new)] Around town, Peoples Gas starts its pipeline overhaul Monday, severe storms threaten Western Pennsylvania tonight, and Kennywood's Jack Rabbit earned landmark status. see: Peoples Gas Pipeline Overhaul Starts Monday; Severe Storms Tonight, Heavy Rain Next Week; Kennywood's Jack Rabbit Named Landmark Coaster * [UPDATE (updated)] Reading's AI skeptics sharpen, with Zitron pressing his bearish NVIDIA case and Newport probing whether an OpenAI model went rogue at Hugging Face. see: Premium: The Hater's Guide To NVIDIA (Part 2); Did OpenAI’s New Model “Go Rogue”? SECURITY ---------------------------------------------------------------- 1. FLOCK AND ICE WIDEN SURVEILLANCE REACH Policy and Regulation · [surveillance, privacy, policy] Latest developments: A leaked Flock presentation showed the company planned to enlist roughly 350,000 Uber, Lyft, and delivery drivers as roaming license-plate collectors for its surveillance network, and Bruce Schneier reported that ICE is buying access to Americans' credit card records through data brokers. Flock, which already blankets US streets with fixed license-plate cameras, sought to co-opt about 350,000 gig drivers into a mobile dragnet, and ICE is purchasing credit card data through brokers. Both moves push surveillance from public infrastructure into everyday commerce. - 404 Media: https://www.404media.co/flock-pitched-a-plan-to-turn-uber-and-lyft-drivers-into-roaming-surveillance-vehicles/ - Wired Security: https://www.wired.com/story/flocks-plans-for-rideshare-dashcams-and-coaching-police-revealed/ - Schneier on Security: https://www.schneier.com/blog/archives/2026/08/ice-is-buying-access-to-credit-card-records.html 2. HEAD MARE BACKDOORS TRUECONF VIDEO INSTALLERS Software Supply Chain · [supply-chain, backdoor] Latest developments: BleepingComputer reported that the Head Mare hacktivist group exploited unpatched TrueConf video conferencing servers to swap client installers for trojanized builds that plant backdoors on everyone who downloads them. TrueConf sells on-premises video conferencing servers widely deployed at Russian enterprises and government bodies, the usual prey of the pro-Ukraine Head Mare crew. Administrators running unpatched servers should patch, verify installer hashes, and hunt for planted backdoors. - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/ 3. NO-REPLY EMAIL DOMAINS LEAK CORPORATE SECRETS Data Breaches · [data-exposure, breach] Latest developments: Wired reported that two security researchers bought cheap domains including noreply.net and deleteduser.com, stood up email listening services, and found hundreds of companies routing corporate secrets straight into their inboxes. Automated systems fire messages to no-reply addresses no one owns, and buying those domains turned two researchers into passive recipients of hundreds of companies' internal data. Organizations should own and monitor their sender domains and stop mailing sensitive content to unmonitored addresses. - Wired Security: https://www.wired.com/story/sensitive-info-goes-into-no-reply-emails-constantly-this-guy-sees-it-all/ 4. BLACK HAT REVEALS NATJACK AND HTTP TERMINATOR ATTACKS Vulnerabilities and Exploits · [research, zero-day] Latest developments: At Black Hat USA 2026, Malcolm Stagg disclosed NatJack, which manipulates network address translation state to hijack live TCP sessions, spoof DNS, expose mapped ports, and exhaust NAT tables across Windows and other implementations, while PortSwigger's James Kettle showed HTTP Terminator, an AI-assisted system that proved new HTTP desynchronization techniques across 30,000 candidate vectors and surfaced a zero-day in Apache Traffic Server. NatJack and HTTP Terminator both strike core internet machinery—NAT connection tracking and HTTP request parsing—and reproduce across independently built products. Operators should watch for vendor advisories and update Apache Traffic Server, which carries the disclosed zero-day. - The Hacker News: https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html - The Hacker News: https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html 5. ATTACKERS TARGET MICROSOFT ENTRA IDENTITY Vulnerabilities and Exploits · [identity, phishing] Latest developments: Entra ID researcher Dirk-jan Mollema showed that malware in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID, register a rogue device, grab a Primary Refresh Token, and add authentication methods for lasting cloud access, as researchers separately tracked a widespread adversary-in-the-middle campaign that hijacks Microsoft 365 accounts through residential proxies to harvest payroll and finance email. Windows Hello for Business abuse gives malware already on a machine durable Entra ID footholds, and the adversary-in-the-middle campaign steals Microsoft 365 sessions from finance staff. Enforce phishing-resistant, device-bound authentication and review Entra device registrations and sign-in logs. - The Hacker News: https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html - The Hacker News: https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html 6. AI CODING AGENTS EXPOSE CI SECRETS AI Security · [ai, vulnerability] Latest developments: Novee Security, presenting at Black Hat USA on August 5, showed that a GitHub issue opened by an account with no repository privileges executed code on the CI runners behind Anthropic's Claude Code and Google's Gemini CLI and hijacked the next agent run on OpenAI's, each in the vendor's default shipping configuration, while Irregular, the firm behind recent AI hacking incidents involving Anthropic, OpenAI, and Meta models, declined to say whether more occurred. The default configurations of Claude Code, Gemini CLI, and OpenAI's coding agent let an untrusted GitHub issue reach CI runners and secrets. Teams running these agents should sandbox them, strip secret access from untrusted triggers, and gate agent runs behind human review. - The Hacker News: https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html - The Record: https://therecord.media/irregular-ai-security-company-incidents BUSINESS AND POLITICS ---------------------------------------------------------------- * Iran Sets Hormuz Terms, Strikes UAE Ship Latest developments: Iran issued formal conditions Saturday for reopening the Strait of Hormuz—a U.S. military pullback from the Gulf and compensation for war damage—as the United Arab Emirates said an Iranian missile struck one of its ships in the waterway. Tehran demands Washington rectify its behavior and pay reparations before lifting its closure of the Strait of Hormuz, the passage for roughly a fifth of the world's seaborne oil, while a U.S. naval blockade keeps Iranian crude bottled up at Kharg Island and the UAE now reports its shipping under Iranian fire. - WSJ World News: https://www.wsj.com/world/middle-east/u-a-e-says-iran-attacked-one-of-its-ships-in-hormuz-bfbec3b2?mod=rss_worldnews - FT Markets: https://www.ft.com/content/9a1ab09b-82d7-43c2-b44a-ebb41d352dab?syn-25a6b1a6=1 * Senate Advances Graham Russia Sanctions Latest developments: The Senate voted 86-11 to advance Senator Lindsey Graham's long-stalled package of sanctions and tariffs targeting Russia over its war in Ukraine. The measure would impose fresh sanctions and steep tariffs aimed at countries buying Russian energy, sharply escalating U.S. economic pressure on President Vladimir Putin as Russian strikes continue to kill civilians in Kyiv. - WSJ World News: https://www.wsj.com/opinion/russia-hears-from-lindsey-graham-sanctions-putin-2be9b55c?mod=rss_worldnews PITTSBURGH ---------------------------------------------------------------- Weather: Tonight: Chance Showers And Thunderstorms, low 68F. Sunday: Mostly Sunny, high 87F. Sunday Night: Partly Cloudy then Slight Chance Showers And Thunderstorms, low 68F. Business: * Peoples Gas Pipeline Overhaul Starts Monday Latest developments: Peoples Natural Gas begins its pipeline modernization Monday, August 10, with intermittent street work running through spring 2027, the utility said, firming up the plan first disclosed August 6. Peoples Natural Gas will replace aging gas mains across parts of Pittsburgh's Lawrenceville and Strip District neighborhoods, intermittently closing streets into 2027. - WPXI: https://www.wpxi.com/news/local/peoples-natural-gas-replace-pipelines-2-pittsburgh-neighborhoods-through-spring-2027/HNPKGHUGXZGSLBO5P7MLATDN5I/ * Chicago Pair Charged in Dick's Gift-Card Scheme Latest developments: Westmoreland County detectives charged a Chicago man and woman Friday in a nationwide gift-card fraud scheme that targeted Dick's Sporting Goods stores across Pennsylvania. State investigators say the two ran a gift-card scam hitting Dick's Sporting Goods locations statewide; the retailer is headquartered in Coraopolis outside Pittsburgh. - TribLive: https://triblive.com/local/westmoreland/2-people-from-chicago-charged-in-nationwide-gift-card-scheme-targeting-dicks-sporting-goods/ Around town: * Pittsburgh Paramedic Resigns Over Second Job Latest developments: A veteran Pittsburgh paramedic suspended last week without pay for allegedly holding a second county job in violation of the city's Home Rule Charter resigned Saturday. The city medic left rather than fight allegations he violated Pittsburgh's Home Rule Charter ban on dual public employment by also working for Allegheny County. - WTAE: https://www.wtae.com/article/pittsburgh-paramedic-resigns-alleged-dual-employment-violation/73382712 * Kennywood's Jack Rabbit Named Landmark Coaster Latest developments: American Coaster Enthusiasts recognized Kennywood's Jack Rabbit on Saturday among wooden roller coasters more than 100 years old. The Jack Rabbit, a wooden coaster at Kennywood Park in West Mifflin, received a designation honoring its century-plus of continuous operation. - WTAE: https://www.wtae.com/article/kennywoods-jack-rabbit-centennial-coaster-designation-american-coaster-enthusiasts/73382841 * Severe Storms Tonight, Heavy Rain Next Week Latest developments: Pittsburgh forecasters warned of isolated severe storms with strong winds across Western Pennsylvania on Saturday night, with more heavy rain expected Monday and Tuesday. After a brief dry lull, the region faces a return to heavy rain and storms early in the week, following downpours that downed power lines near an East Huntingdon Township tire shop Friday. - WTAE: https://www.wtae.com/article/western-pa-trending-drier-this-weekend/73381519 SPORTS ---------------------------------------------------------------- Around the Teams: * Pirates' Skid Turns Season-Defining Latest developments: The Post-Gazette framed the Pirates' four-game losing streak, which dropped them to last in the National League Central, as potentially season-defining for their fading wild-card hopes. The paper's 11-point breakdown weighs the fates of ace Paul Skenes and shortstop O'Neil Cruz as Pittsburgh's postseason window narrows. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/08/08/pirates-mlb-wild-card-race-paul-skenes-oneil-cruz/stories/202608080027 Team USA: * Johnson Explains Grand Slam Track Payment Latest developments: Four-time Olympic gold medalist Michael Johnson said a disputed payment tied to the collapse of his Grand Slam Track league was a reimbursement, calling the fallout the most stressful stretch he has faced in years. Johnson, the American sprint great who founded the now-failed Grand Slam Track circuit, addressed the financial wreckage of its aborted launch and clarified that money he received was to cover expenses. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49559759/michael-johnson-says-questioned-payment-was-reimbursement READING ---------------------------------------------------------------- * Ed Zitron -- Premium: The Hater's Guide To NVIDIA (Part 2) Zitron presses his bearish case against NVIDIA, arguing the chipmaker's insistent denials that it resembles Enron or WorldCom only invite the scrutiny it fears, and that its AI-fueled boom rests on shakier ground than its valuation implies. https://www.wheresyoured.at/premium-the-haters-guide-to-nvidia-part-2/ * Stratechery -- Google Earnings, The Frontier Case, Amazon Earnings Ben Thompson reads Google's earnings as confirming its Anthropic hedge and credits Amazon chief Andy Jassy with the clearest justification yet for the two companies' massive AI capital spending. https://stratechery.com/2026/google-earnings-the-frontier-case-amazon-earnings/ * Cal Newport -- Did OpenAI’s New Model “Go Rogue”? Newport examines reports tying an OpenAI model to an intrusion at Hugging Face's production infrastructure and asks whether the episode signals an AI genuinely going rogue or something far more mundane. https://calnewport.com/did-openais-new-model-go-rogue/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,705.63 ▲ +3.9% Dow 53,907.09 ▲ +3.2% Nasdaq 26,380.26 ▲ +5.7% WTI crude 77.36 ▼ -6.7% EUR/USD 1.1537 ▲ +0.7% GBP/USD 1.3459 ▲ +0.8% USD/JPY 157.80 ▼ -2.4% ================================================================ Generated 2026-08-08 19:37 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================