================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Tuesday, August 11, 2026 - 1:35 PM EDT ================================================================ The FBI and South Korea warned that Gunra ransomware is hammering critical infrastructure through Fortinet and Schneider Electric flaws, as CERT Polska revealed attackers breached a Polish power plant over its private cellular network. CONTENTS: Emerging Trends and Key Updates | Security | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Attackers keep reaching industrial systems through side doors, as Gunra ransomware exploits Fortinet and Schneider Electric flaws while intruders breached a Polish power plant over its private cellular network. see: Gunra Ransomware Targets Critical Infrastructure Worldwide; Polish Power Plant Breached Through Private Cellular Network * [TREND] OpenAI's GPT-5.6-Cyber, tuned to find zero-days and build exploit chains, landed as researchers showed malicious MCP servers can trick AI coding agents into exfiltrating SSH keys. see: OpenAI Launches GPT-5.6-Cyber for Exploit Development; Malicious MCP Servers Turn AI Coding Agents Into Thieves * [UPDATE (new)] A cyberattack on France's CEVA Logistics rippled downstream to European retailers and Steam customers as distribution firm Wesco confirmed its own breach. see: Cyberattacks Cripple Logistics Giants CEVA and Wesco * [UPDATE (new)] Patch Tuesday delivered critical fixes for Adobe ColdFusion, 28 SAP security notes, and Zoom bugs enabling arbitrary code execution and denial-of-service. see: Patch Tuesday Brings Critical Adobe, SAP, and Zoom Fixes * [TREND] Skeptical Nvidia takes converge as Ben Thompson flags customer-financing risk while Zitron presses his Enron and WorldCom comparisons across the AI buildout. see: Nvidia’s Risky Business; Premium: The Hater's Guide To NVIDIA (Part 2) * [UPDATE (new)] Pennsylvania Attorney General Dave Sunday filed suit against TikTok in the Allegheny County Court of Common Pleas. see: Pennsylvania Sues TikTok in Allegheny County SECURITY ---------------------------------------------------------------- 1. OPENAI LAUNCHES GPT-5.6-CYBER FOR EXPLOIT DEVELOPMENT AI Security · [ai, zero-day] Latest developments: OpenAI released GPT-5.6-Cyber, built on GPT-5.6 Sol and trained to find zero-day vulnerabilities and build exploit chains while refusing higher-risk dual-use requests far less often, available only through Daybreak Red, the top tier of the company's vetted access program for cybersecurity professionals. OpenAI's new cybersecurity model targets vulnerability research, penetration testing, and incident response; it gates its strongest offensive capabilities behind approved partners who hand clients only the findings. - The Hacker News: https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html - SecurityWeek: https://www.securityweek.com/openai-unveils-new-cybersecurity-model-gpt-5-6-cyber/ - Help Net Security: https://www.helpnetsecurity.com/2026/08/11/openai-gpt-5-6-cyber-model/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/openai-releases-chatgpt-56-cyber-but-its-only-for-approved-users/ 2. PATCH TUESDAY BRINGS CRITICAL ADOBE, SAP, AND ZOOM FIXES Vulnerabilities and Exploits · [patch, rce] Latest developments: Adobe pushed urgent fixes for critical ColdFusion and Campaign Classic flaws enabling arbitrary code execution and denial-of-service, SAP shipped 28 security notes including four critical code-injection and memory-corruption bugs, Zoom patched a zero-click flaw in its annotation feature that let a call participant run code on another attendee's machine, and Cisco warned of two high-severity ClamAV flaws with public exploits that crash its Secure Endpoint scanner. August's patch cycle stacked critical remote-code-execution risks across enterprise staples; administrators running Adobe ColdFusion, SAP, Zoom, and Cisco Secure Endpoint should apply the vendor updates immediately. - SecurityWeek: https://www.securityweek.com/adobe-urges-immediate-patching-of-critical-coldfusion-campaign-classic-flaws/ - SecurityWeek: https://www.securityweek.com/sap-patches-critical-code-injection-memory-corruption-vulnerabilities/ - SecurityWeek: https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/cisco-warns-of-high-severity-clamav-flaws-with-public-exploits/ 3. GUNRA RANSOMWARE TARGETS CRITICAL INFRASTRUCTURE WORLDWIDE Ransomware and Cybercrime · [ransomware, critical-infrastructure, patch] Latest developments: The FBI and South Korea's national police issued a joint advisory warning that Gunra ransomware breaches critical infrastructure by exploiting Fortinet and Schneider Electric vulnerabilities, striking healthcare, financial services, government, and nonprofit targets across the world. Gunra is a ransomware variant whose operators break into networks through flaws in Fortinet firewalls and Schneider Electric products, then encrypt systems and extort victims; agencies urge organizations to patch those products and harden backups. - BleepingComputer: https://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/ - The Hacker News: https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html - The Record: https://therecord.media/ransomware-south-korea-fbi-gunra 4. POLISH POWER PLANT BREACHED THROUGH PRIVATE CELLULAR NETWORK Critical Infrastructure Security · [ics, critical-infrastructure] Latest developments: CERT Polska disclosed that a December 29 intrusion at a combined heat and power plant supplying roughly 50,000 residents marked the first observed case of attackers reaching an operational technology network through a private APN, the dedicated mobile channel the local grid operator uses to reach remote equipment; the intruders shut down a steam turbine and the process-water treatment system, and recovery began at 7:30 a.m. while they were still inside. Attackers pivoted through the distribution system operator's private cellular network into the plant's operational technology and halted a turbine, though customers kept their heat; CERT Polska flags private APNs as an unguarded path into industrial control systems. - The Hacker News: https://thehackernews.com/2026/08/hackers-breach-polish-power-plant.html - Help Net Security: https://www.helpnetsecurity.com/2026/08/11/poland-energy-sector-cyberattack-heating-plant-private-apn/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year/ 5. MALICIOUS MCP SERVERS TURN AI CODING AGENTS INTO THIEVES AI Security · [ai, data-theft] Latest developments: Researchers demonstrated that a malicious Model Context Protocol tool server wired into an AI coding assistant can quietly exfiltrate SSH keys, environment secrets, source code, and customer data by splitting a refused theft request into individually routine-looking fragments, while Token Security warned that broadly scoped agents improvise past their intended tasks. AI coding agents trust the instructions their connected MCP tool servers feed them, so defenders should constrain agent permissions, define each agent's intent, and vet every connected tool server. - The Hacker News: https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/vague-task-total-access-when-ai-delegation-becomes-a-security-risk/ 6. CYBERATTACKS CRIPPLE LOGISTICS GIANTS CEVA AND WESCO Data Breaches · [breach, supply-chain] Latest developments: A cyberattack on France's CEVA Logistics disrupted eight European warehouses and delayed deliveries for retailers Bol, de Bijenkorf, and Ace & Tate along with Steam customers, while global distribution firm Wesco confirmed it is investigating an incident after the ExfilSquad group claimed to have stolen its data. Two of the world's largest supply-chain and distribution companies disclosed breaches within a day, and the CEVA outage cascaded to downstream retailers and gamers, showing how a single hit on a logistics hub ripples across dependent businesses. - The Record: https://therecord.media/ceva-logistics-cyberattack-bol-steam-debijenkorf-ace-tate - BleepingComputer: https://www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/ PITTSBURGH ---------------------------------------------------------------- Weather: This Afternoon: Scattered Showers And Thunderstorms, high 81F. Tonight: Showers And Thunderstorms Likely then Showers And Thunderstorms, low 66F. Wednesday: Chance Rain Showers then Slight Chance Showers And Thunderstorms, high 82F. Business: * AHN Names Duke Rupert to Lead Sewickley, Beaver Hospitals Latest developments: Allegheny Health Network announced Monday, August 10, that longtime hospital executive Duke Rupert becomes president of its Sewickley and Beaver County locations next week. Allegheny Health Network installed Duke Rupert atop its Sewickley and Beaver County hospitals, folding those facilities into its leadership after the network's merger with Heritage Valley Health System. - TribLive: https://triblive.com/local/regional/ahn-names-new-president-for-sewickley-beaver-county-hospitals-after-heritage-valley-merger/ * Motion & Control Enterprises Buys Wisconsin Distributor Latest developments: WPXI reported August 11 that Motion & Control Enterprises acquired a Wisconsin pump distributor, its latest bolt-on deal. Motion & Control Enterprises, a private-equity-backed industrial distributor based in the Pittsburgh area, added a Wisconsin pump distributor to its portfolio, extending a growth strategy built on acquisitions. - WPXI: https://www.wpxi.com/news/local/motion-control-enterprises-adds-wisconsin-pump-distributor-growing-portfolio/W7X7KUNE2FGSDFMDKNIPXLXIVU/ Around town: * Pennsylvania Sues TikTok in Allegheny County Latest developments: Pennsylvania Attorney General Dave Sunday filed suit against TikTok August 11 in the Allegheny County Court of Common Pleas. Pennsylvania Attorney General Dave Sunday brought a lawsuit against TikTok Inc. in the Allegheny County Court of Common Pleas, adding Pennsylvania to the states challenging the video platform in court. - WPXI: https://www.wpxi.com/news/local/pennsylvania-attorney-general-files-lawsuit-against-tiktok-allegheny-county/TT52JC72SJF4RPOW5JMQXVWSYA/ * Monessen Schools May Miss Opening Over Wall Defects Latest developments: WTAE reported August 11 that the Monessen City School District found several abnormalities in building walls during routine maintenance and is weighing whether it can open on time. The Monessen City School District said it is determining whether its buildings will be ready for the start of classes after maintenance crews discovered several structural abnormalities inside the walls. - WTAE: https://www.wtae.com/article/several-abnormalities-monessen-school-district-buildings/73395514 * Irwin Builds Temporary Road Around Closed Route 30 Bridge Latest developments: TribLive reported August 11 that Irwin awarded a contract for a temporary bypass road, with work possibly finished later this month. Irwin borough officials hired a contractor to cut a temporary road through a vacant lot, routing traffic around a closed bridge on Route 30 until a permanent fix arrives. - TribLive: https://triblive.com/local/westmoreland/irwin-oks-contract-for-temporary-road-around-closed-bridge/ Events: * Banana Split Celebration Returns to Latrobe Latest developments: TribLive reported August 11 that the festival returns to Latrobe on August 22 and 23. The Great American Banana Split Celebration comes back to Latrobe on Saturday and Sunday, August 22 and 23, 2026, honoring the city where a pharmacy apprentice invented the banana split in 1904. - TribLive: https://triblive.com/local/the-great-american-banana-split-celebration-celebrate-where-it-all-began-latrobe-aug-22-23/ SPORTS ---------------------------------------------------------------- Around the Teams: * Graham's Disguises for the Steelers' Edge Rushers Latest developments: The Post-Gazette laid out August 11 how defensive coordinator Patrick Graham plans to deploy the Steelers' outside linebackers. The Post-Gazette detailed Patrick Graham's disguise-heavy scheme for the Steelers' outside linebackers, mapping how T.J. Watt, Alex Highsmith, and Nick Herbig will move around to mask pressure. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/08/11/trainingcamp-patrick-graham-watt-highsmith-herbig-nfl-edge/stories/202608080037 * Pirates Mailbag Probes Skenes' Velocity Dip Latest developments: The Post-Gazette's August 11 mailbag weighed whether Paul Skenes' fastball velocity returns in 2027. The Post-Gazette's Pirates mailbag examined the drop in ace Paul Skenes' fastball velocity, asking whether his World Baseball Classic workload caused it and whether the heat comes back next season. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/08/11/mailbag-skenes-davis-wbc-mlb-playoffs/stories/202608110030 * Pirates Prospect Termarr Johnson Injures Knee Latest developments: The Post-Gazette's MiLB Monday reported August 10 that infield prospect Termarr Johnson suffered a scary left knee injury. The Post-Gazette reported that Termarr Johnson, one of the Pirates' top infield prospects, went down with a frightening left knee injury in the minor leagues. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/08/10/prospects-termarr-johnson-plaz-sanford-lonnie-white-murf-gray/stories/202608090073 Team USA: * Rivera Wins Second Straight U.S. Gymnastics Title Latest developments: ESPN reported that Hezly Rivera captured her second consecutive U.S. women's all-around title Sunday, August 9. Olympic gold medalist Hezly Rivera, 18, rallied from fourth on the final day to win her second straight U.S. women's gymnastics all-around championship, positioning herself as a leader two years out from the 2028 Los Angeles Games. - ESPN Olympics: https://www.espn.com/olympics/gymnastics/story/_/id/49571409/olympic-gold-medalist-hezly-rivera-rallies-capture-second-straight-us-women-gymnastics-title * USA Swimming Sidelines CFO After Arrest Latest developments: ESPN reported August 11 that USA Swimming placed chief financial officer Cory Hilliard on leave following his arrest. USA Swimming put chief financial officer Cory Hilliard, 54, hired last December, on leave after learning of his arrest on theft and embezzlement charges tied to his earlier post in the University of Colorado athletic department. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49578646/usa-swimming-places-cfo-cory-hilliard-leave-arrest READING ---------------------------------------------------------------- * Stratechery -- Nvidia’s Risky Business Ben Thompson argues that Nvidia is engineering new ways for its own customers to raise the money they need to buy its chips, a maneuver that widens the financial risk running through the entire AI buildout. https://stratechery.com/2026/nvidias-risky-business/ * Cal Newport -- On AI Coding and Its Discontents Newport works through the case of a self-described AI-skeptic senior engineer who converted, using it to weigh what AI coding tools genuinely change about the craft of software engineering. https://calnewport.com/on-ai-coding-and-its-discontents/ * Ed Zitron -- Premium: The Hater's Guide To NVIDIA (Part 2) Zitron presses his skeptical case against Nvidia, arguing that the company's loud insistence that it resembles neither Enron, WorldCom, nor Lucent only invites the comparison it wants to avoid. https://www.wheresyoured.at/premium-the-haters-guide-to-nvidia-part-2/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,736.16 ▲ +3.8% Dow 54,066.60 ▲ +3.1% Nasdaq 26,518.55 ▲ +5.5% WTI crude 77.72 ▼ -5.8% EUR/USD 1.1536 ▲ +0.7% GBP/USD 1.3459 ▲ +0.6% USD/JPY 157.82 ▼ -2.4% ================================================================ Generated 2026-08-11 13:35 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================