================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Wednesday, August 12, 2026 - 7:36 PM EDT ================================================================ A stealthy 17-month campaign quietly siphoning Salesforce and ServiceNow data worldwide anchors a day dominated by attackers exploiting fresh enterprise flaws faster than defenders can patch. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Attackers weaponized freshly disclosed VMware vCenter and Cisco flaws within days of patches, shrinking the gap between disclosure and active enterprise exploitation. see: Enterprise Flaws Under Active Exploitation * [TREND] A reasoning-API flaw lets hidden chain-of-thought replay across sessions, spilling OpenAI, Anthropic, and Google internals along with the API keys and passwords they carry. see: AI Reasoning API Leak Exposes Secrets * [TREND] Slow, as-designed abuse paid off as City-Forum spent 17 months harvesting Salesforce and ServiceNow guest portals while 737 fake VPN extensions quietly proxied 75,486 users. see: City-Forum Data Theft Campaign; Fake Chrome VPN Extensions Route Traffic * [TREND] Physical-access attacks surfaced too, from WindRelay Android malware relaying live payment cards to a coin-sized device that hijacks a Boeing 737 autopilot through an exterior hatch. see: WindRelay Android NFC Relay Malware; Aircraft and In-Flight Network Attacks * [TREND] Commentators sharpened AI skepticism, with Ben Thompson panning Anthropic's watermarking, Ed Zitron warning the boom's economics are unsustainable, and Cal Newport weighing AI coding's real limits. see: Anthropic's Watermarking, How It (Probably) Works, Worse Than It Seems; Don't Look Up; On AI Coding and Its Discontents * [UPDATE (new)] Locally, July inflation cooled to 3.4%, an audit faulted Pittsburgh's URA for undocumented Rescue Plan spending, and the airport confirmed it is pulling two people movers. see: US Inflation Slows to 3.4%; Audit Faults Pittsburgh COVID Relief Records; Pittsburgh Airport Pulling Two People Movers SECURITY ---------------------------------------------------------------- 1. CITY-FORUM DATA THEFT CAMPAIGN Data Breaches · [breach, data-theft] Latest developments: Reco disclosed today that a campaign it calls City-Forum has quietly pulled records from Salesforce Experience Cloud and ServiceNow customer portals worldwide since at least March 2025, abusing unauthenticated guest access with custom tooling and continuing still. The operators run from a rented German server tied to city-forum.com, a domain registered in 2002 and abandoned, enumerating then exfiltrating any record an anonymous guest user can reach across many industries; Reco urges administrators to audit and restrict guest permissions on both platforms. - BleepingComputer: https://www.bleepingcomputer.com/news/security/city-forum-data-theft-attacks-target-salesforce-servicenow-portals/ - Help Net Security: https://www.helpnetsecurity.com/2026/08/12/salesforce-servicenow-guest-user-exposure/ - SecurityWeek: https://www.securityweek.com/stealthy-city-forum-attacks-target-salesforce-and-servicenow-with-custom-toolset/ - Dark Reading: https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow 2. ENTERPRISE FLAWS UNDER ACTIVE EXPLOITATION Vulnerabilities and Exploits · [exploit, patch, vulnerability] Latest developments: Attackers began exploiting four freshly disclosed enterprise bugs today: Broadcom VMware vCenter directory-traversal CVE-2026-59310 at CVSS 9.8 for persistent remote code execution, Cisco ASA and FTD HTTP flaw CVE-2026-20349 at CVSS 8.6 for remote denial of service, a critical Microsoft SharePoint bug driven by Rapid7's just-published proof of concept, and Adobe Commerce and Magento flaw CVE-2026-71362 for customer-account hijacking. The four span Broadcom, Cisco, Microsoft, and Adobe and hand attackers code execution, denial of service, and account takeover; every vendor has shipped a fix, and administrators should apply each one at once. - The Hacker News: https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html - The Hacker News: https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html - BleepingComputer: https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-adobe-commerce-flaw-to-hijack-customer-accounts/ 3. AIRCRAFT AND IN-FLIGHT NETWORK ATTACKS Vulnerabilities and Exploits · [aviation, research] Latest developments: Wired reported that security researchers built a coin-sized device which, plugged into an exterior hatch of a Boeing 737 in under 60 seconds, redirects the aircraft's autopilot or rewrites its flight plan, and FBI Atlanta confirmed it is investigating a fake Wi-Fi hotspot attack, which observers suspect traces to the DEF CON crowd, against a Delta flight. The Boeing technique needs brief physical access to an external maintenance hatch, and the Delta incident spoofed an in-cabin Wi-Fi hotspot to lure passengers; the FBI has made no arrests as it probes the hotspot case. - Wired Security: https://www.wired.com/story/this-coin-sized-device-can-hack-a-boeing-737/ - Ars Technica Security: https://arstechnica.com/information-technology/2026/08/def-con-crowd-suspected-in-fake-hotspot-attack-on-delta-flight/ 4. FAKE CHROME VPN EXTENSIONS ROUTE TRAFFIC Ransomware and Cybercrime · [malware, proxy] Latest developments: Researchers found 737 free VPN and proxy extensions across at least 40 Chrome Web Store developer accounts, together carrying 75,486 installs, that impersonate well-known services and quietly route browsing through SOCKS5 proxies a single provider runs, mainly targeting Russian-speaking users chasing blocked sites. Of the set, 274 extensions impersonate 66 legitimate brands while funneling every request through one operator's proxy infrastructure; users should pull any VPN extension that does not come from the vendor's own listing. - BleepingComputer: https://www.bleepingcomputer.com/news/security/hundreds-of-fake-chrome-vpn-extensions-route-traffic-through-a-proxy/ - The Hacker News: https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html 5. AI REASONING API LEAK EXPOSES SECRETS AI Security · [ai, vulnerability] Latest developments: Researchers disclosed a flaw in how OpenAI, Anthropic, and Google carry hidden chain-of-thought between reasoning API calls, letting a block minted in one session replay into another and surrender internal reasoning along with API keys and passwords sitting in session logs. The encrypted reasoning objects the providers pass between calls held recoverable secrets, so replayed blocks leak credentials organizations never expected in a model's plumbing; teams should rotate exposed keys and treat reasoning traces as sensitive data. - The Hacker News: https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html 6. WINDRELAY ANDROID NFC RELAY MALWARE Ransomware and Cybercrime · [malware, android] Latest developments: BleepingComputer detailed WindRelay, a new Android NFC-relay malware that runs alongside the SpyNote remote administration tool to capture live payment-card data, relay it to attackers in real time, and take out loans in victims' names. WindRelay grabs tap-to-pay card details for instant fraudulent purchases while SpyNote hands attackers full remote control of the phone; Android users should shun sideloaded apps and strip NFC and accessibility permissions from unknown software. - BleepingComputer: https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards/ BUSINESS AND POLITICS ---------------------------------------------------------------- * US Inflation Slows to 3.4% Latest developments: July consumer prices rose 3.4% year over year, a slight cooldown that hands the Federal Reserve more room before its next rate decision. US inflation eased to 3.4% in July as falling petrol prices offset lingering fallout from the Iran war, giving Federal Reserve Chair Kevin Warsh time to hold rates steady amid weak jobs numbers and pressure from President Trump. - FT: https://www.ft.com/content/52727749-4360-4463-8822-dc3bfd8ef279?syn-25a6b1a6=1 - WSJ: https://www.wsj.com/world/inflation-pulls-back-slightly-buying-the-fed-more-time-074d812d?mod=rss_worldnews PITTSBURGH ---------------------------------------------------------------- Weather: Tonight: Scattered Rain Showers, low 68F. Thursday: Partly Sunny then Slight Chance Showers And Thunderstorms, high 84F. Thursday Night: Slight Chance Showers And Thunderstorms then Patchy Fog, low 65F. Business: * Steelers Valued at $8.7 Billion Latest developments: Sportico's 2026 franchise rankings pegged the Pittsburgh Steelers at $8.7 billion, placing them in the NFL's middle tier. Sportico's annual valuations put the Steelers at $8.7 billion, ranking the Rooney-owned franchise in the middle of the league's 32 teams. - WTAE: https://www.wtae.com/article/pittsburgh-steelers-sportico-nfl-franchise-valuations-2026/73416388 * Kosher Grocery Named for Old Squirrel Hill Rite Aid Latest developments: A real estate firm identified the incoming kosher grocery at the vacant Forbes and Murray Rite Aid as Murray Avenue Market. Murray Avenue Market, a new kosher grocery, will occupy the vacant former Rite Aid at Forbes and Murray avenues in Pittsburgh's Squirrel Hill. - WTAE: https://www.wtae.com/article/former-squirrel-hill-rite-aid-murray-avenue-market-real-estate-firm-says/73406972 * Rochester Businesses Squeezed by Road Project Latest developments: Merchants along Rochester's $7 million roadway reconstruction say the work is cutting into sales. A $7 million road project in Rochester, Beaver County, is hurting local businesses, among them The Hilltop restaurant, which reopened in February 2025 after its own long closure. - WPXI: https://www.wpxi.com/news/local/rochester-businesses-hit-hard-during-7m-roadway-project/3NEWTVTI35DJ3GIEZVHHKIJUHA/ Around town: * Pittsburgh Airport Pulling Two People Movers Latest developments: Pittsburgh International Airport confirmed it will remove two of its moving walkways, so travelers walk farther to their gates. Pittsburgh International Airport plans to take out two of its people movers, adding walking distance for passengers heading to and from gates. - TribLive: https://triblive.com/local/pittsburgh-international-airport-is-taking-out-2-of-its-people-movers/ * Audit Faults Pittsburgh COVID Relief Records Latest developments: A new audit found Pittsburgh's Urban Redevelopment Authority could not document how it spent federal American Rescue Plan Act relief money. An audit of Pittsburgh's COVID relief spending flagged missing documentation at the Urban Redevelopment Authority, which distributed the city's American Rescue Plan Act funds. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/politics-local/2026/08/12/pittsburgh-ura-covid-money-audit-american-rescue-plan-act/stories/202608120049 * Unsafe E. Coli in Pennsylvania Waterways Latest developments: Environmental groups reported that more than half of monitored Pennsylvania waterways showed unsafe E. coli levels last year. More than half of monitored Pennsylvania streams and rivers, Pittsburgh's Saw Mill Run among them, carried unsafe E. coli last year, a problem driven by sewage overflow from aging infrastructure. - KDKA: https://www.cbsnews.com/pittsburgh/news/pittsburgh-area-waterways-unsafe-e-coli/ SPORTS ---------------------------------------------------------------- Around the Teams: * Skenes Questions Pirates' Slide Latest developments: After another loss to the Miami Marlins, ace Paul Skenes said he is unsure why the Pirates are not playing up to their standard as the second-half slide deepens. Post-Gazette beat coverage quoted Pirates pitcher Paul Skenes puzzling over the team's second-half collapse and its failure to meet its own standard. - Pittsburgh Post-Gazette: https://www.post-gazette.com/sports/pirates/2026/08/12/skenes-loss-mlb-kelly-marlins-losing-streak/stories/202608120027 * Graham's Edge-Rusher Disguises Latest developments: The Post-Gazette detailed how new defensive coordinator Patrick Graham plans to deploy and disguise the Steelers' outside linebackers. A Post-Gazette training-camp breakdown examined Patrick Graham's scheme for edge rushers T.J. Watt, Alex Highsmith, and Nick Herbig, built on pre-snap disguises. - Pittsburgh Post-Gazette: https://www.post-gazette.com/sports/steelers/2026/08/11/trainingcamp-patrick-graham-watt-highsmith-herbig-nfl-edge/stories/202608080037 * Backups Get the Reps in Preseason Opener Latest developments: Ahead of Thursday's preseason opener at Acrisure Stadium, Ray Fittipaldo's chat had Aaron Rodgers sitting and the backup quarterbacks auditioning. The Steelers open the preseason Thursday at Acrisure Stadium; Ray Fittipaldo's live chat covered Aaron Rodgers skipping the game and backups Mason Rudolph and Will Howard taking the reps. - Pittsburgh Post-Gazette: https://www.post-gazette.com/sports/steelers/2026/08/12/fittipaldo-live-chat-nfl-preseason-rodgers-allar/stories/202608120035 Team USA: * Rivera Repeats as US Gymnastics Champion Latest developments: Olympic gold medalist Hezly Rivera, 18, rallied from fourth on the final day to win her second straight US women's all-around title on August 10. Hezly Rivera, an 18-year-old Olympic gold medalist, captured back-to-back US women's gymnastics national championships, coming from fourth place with four poised routines on the closing day. - ESPN: https://www.espn.com/olympics/gymnastics/story/_/id/49571409/olympic-gold-medalist-hezly-rivera-rallies-capture-second-straight-us-women-gymnastics-title READING ---------------------------------------------------------------- * Stratechery -- Anthropic's Watermarking, How It (Probably) Works, Worse Than It Seems Ben Thompson argues Anthropic's move to add AI watermarking in response to the EU AI Act is a mistake, weak philosophically and likely far less effective than it appears. https://stratechery.com/2026/anthropics-watermarking-how-it-probably-works-worse-than-it-seems/ * Ed Zitron -- Don't Look Up Ed Zitron argues that investors, the press, and the tech industry keep refusing to acknowledge mounting evidence that the generative-AI boom rests on unsustainable economics. https://www.wheresyoured.at/dont-look-up/ * Cal Newport -- On AI Coding and Its Discontents Cal Newport uses the story of a senior Silicon Valley engineer who went from AI skeptic to convert to weigh what AI coding tools genuinely deliver and where their limits lie. https://calnewport.com/on-ai-coding-and-its-discontents/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,734.49 ▲ +2.9% Dow 54,007.80 ▲ +2.5% Nasdaq 26,490.64 ▲ +3.9% WTI crude 79.20 ▼ -3.1% EUR/USD 1.1546 ▲ +0.3% GBP/USD 1.3487 ▲ +0.4% USD/JPY 158.46 ▼ -0.5% ================================================================ Generated 2026-08-12 19:36 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================