daily plain-text briefing: security, markets, business, and pittsburgh
A compromised AI gateway package bleeds 153 gigabytes of corporate credentials as North Korea's Lazarus Group turns a freshly patched Windows zero-day on defense contractors across four countries.
Latest developments: Fortinet patched authentication flaws in FortiWeb and FortiManager that let attackers log in with arbitrary usernames and passwords or impersonate any FortiGate appliance, and Adobe fixed three CVSS 10.0 bugs including ColdFusion OS-command-injection CVE-2026-48362, as attackers pressed active exploitation of VMware vCenter directory-traversal CVE-2026-59310 and SharePoint authentication bypass CVE-2026-55040.
The four vendors anchor enterprise perimeters, e-commerce, and collaboration; VMware vCenter CVE-2026-59310 and SharePoint CVE-2026-55040 both grant remote code execution or account takeover and now see in-the-wild abuse following public proof-of-concept releases. Administrators should apply every fix without delay.
Sources: SecurityWeek · The Hacker News · SecurityWeek · The Hacker News · ↑ top
Latest developments: Hudson Rock obtained and analyzed the 153GB archive that intruders stole in the LiteLLM supply-chain attack, counting 433,909 files and 118,829 CI-runner dumps traced to 2,488 corporate domains, among them AWS, Samsung, Cisco, and Salesforce.
LiteLLM is a widely deployed open-source gateway that routes application traffic to large language models. Attackers scraped and exfiltrated secrets from roughly 2,500 users of the compromised package; Hudson Rock co-founder and chief technology officer Alon Gal says the firm now runs a global ethical-disclosure effort, and affected organizations should rotate exposed keys and credentials immediately.
Sources: Help Net Security · Ars Technica Security · ↑ top
Latest developments: Researchers published two new local paths to SYSTEM on Windows: Nightmare Eclipse's ShieldBreak exploit, dropped on Patch Tuesday, lets any user spawn a shell with SYSTEM privileges, and Plug and Pwn abuses the Windows Plug and Play feature to install vulnerable vendor software from a spoofed USB device.
Both techniques hand a low-privileged or physically present attacker full control of a Windows machine, a common step between initial access and domain-wide compromise. Defenders should restrict USB device installation, tighten driver-installation policy, and monitor for unexpected privilege escalation.
Sources: SecurityWeek · BleepingComputer · ↑ top
Latest developments: Researchers detailed Jewelbug, a hackers-for-hire group that carries out state-sponsored cyber espionage and financially motivated cryptocurrency heists from the same web control panel.
Jewelbug collapses the usual boundary between government spying and criminal profit, running both mission sets through shared tooling. Defenders tracking either motive should treat overlapping infrastructure and toolmarks as signs of one operator.
Sources: Dark Reading · ↑ top
Latest developments: The White House began contracting private security companies to run operations against foreign cybercrime gangs, with deals that may require a $1 million bond the firm forfeits if it breaks operational requirements.
The arrangement pushes offensive action against overseas criminal groups into private hands under government contract, raising questions about oversight, liability, and rules of engagement. The program marks a shift toward public-private disruption of ransomware and fraud infrastructure.
Sources: SecurityWeek · ↑ top
Latest developments: Check Point Research tied North Korea's Lazarus Group to zero-day exploitation of CVE-2026-68820, the afd.sys WinSock flaw Microsoft patched August 11, which the crew rode to SYSTEM privileges and used to drop a never-before-seen backdoor on defense and aerospace companies in France, Germany, Brazil, and India.
The activity extends Operation Dream Job, Lazarus's long-running espionage campaign that lures targets through fake job offers. CISA gave U.S. federal civilian agencies two weeks to patch the flaw; every Windows enterprise should deploy the August update now.
Sources: The Hacker News · BleepingComputer · The Record · ↑ top
Today: Partly Sunny, high 84F.
Tonight: Mostly Cloudy then Patchy Fog, low 67F.
Friday: Patchy Fog then Chance Showers And Thunderstorms, high 83F.
Latest developments: Wegmans breaks ground August 13 on its first Pittsburgh-region store.
Wegmans breaks ground August 13 on its first Pittsburgh-area store at the Cool Springs development in Cranberry Township, near the Penguins' UPMC Lemieux Sports Complex; the grocer expects to open sometime in 2027.
Latest developments: The former Corelle glass plant in Charleroi went on the market more than a year after closing.
The former Corelle Brands glass plant in Charleroi has gone up for sale more than a year after its closure, the Post-Gazette reported, testing appetite for a large idled industrial site in the Mon Valley.
Sources: Pittsburgh Post-Gazette · ↑ top
Latest developments: Pittsburgh switched on automated red-light enforcement cameras at two intersections Wednesday.
Pittsburgh activated automated red-light enforcement cameras at North Dallas Avenue and Penn Avenue in Point Breeze and at a Saw Mill Run Boulevard intersection, a system the city says targets dangerous intersection running.
Latest developments: Indiana Township supervisors unanimously voted down the Cove Run Road development.
Indiana Township supervisors voted unanimously to reject a proposed 172-unit housing plan off Cove Run Road.
Latest developments: Little Italy Days opened Thursday, August 13, and runs through Sunday.
Little Italy Days, the 26th annual Italian street festival, runs Thursday, August 13, through Sunday, August 16, along Liberty Avenue from Ella Street to Gross Street in Bloomfield; Thursday hours are 5 to 9 p.m., admission is free, and all ages are welcome.
Sources: Pittsburgh City Paper · ↑ top
Latest developments: Riverstone Books hosts novelist Hannah Whitten on Thursday, August 13.
Riverstone Books presents An Evening with fantasy author Hannah Whitten on Thursday, August 13, from 1 to 3:30 p.m. at the Hampton Community Center, 3200 Lochner Way, Allison Park; tickets cost $7.82 through riverstonebookstore.com.
Sources: Pittsburgh City Paper · ↑ top
Latest developments: The Steelers are bringing back linebacker Elandon Roberts, a Post-Gazette source said.
The Steelers are re-signing veteran linebacker Elandon Roberts, the Post-Gazette reported, adding an experienced run defender to Patrick Graham's front seven.
Sources: Post-Gazette Steelers · ↑ top
Latest developments: Green Bay will play quarterback Jordan Love and other starters in Thursday's preseason opener at Acrisure Stadium.
TribLive's First Call reported the Packers plan to play Jordan Love and other starters in Thursday's preseason opener at Acrisure Stadium; the Post-Gazette's five things to watch flags Aaron Rodgers sitting while backups Will Howard and Drew Allar and receiver Germie Bernard audition.
Sources: Post-Gazette Steelers · ↑ top
Latest developments: Manager Don Kelly said the Pirates 'felt sorry for ourselves' after a rout by the Marlins.
After the Miami Marlins routed Pittsburgh, manager Don Kelly said the Pirates 'felt sorry for ourselves,' the Post-Gazette reported, as the club's second-half slide dragged on.
Sources: Post-Gazette Pirates · ↑ top
Latest developments: Katie Ledecky won the 1,500-meter freestyle and the United States set a world record in the 4x100 mixed medley relay to open the Pan Pacific Championships.
Katie Ledecky won the 1,500-meter freestyle on the opening night of the Pan Pacific Championships, and the United States closed the session with a world record in the 4x100 mixed medley relay, ESPN reported.
Sources: ESPN Olympics · ↑ top
Latest developments: Elana Meyers Taylor will miss the coming World Cup bobsled season with post-concussion symptoms.
Olympic monobob gold medalist Elana Meyers Taylor said post-concussion symptoms she has dealt with for months will keep her out of the entire coming World Cup bobsled season.
Sources: ESPN Olympics · ↑ top
Latest developments: USA Swimming placed chief financial officer Cory Hilliard on leave after learning of his arrest.
USA Swimming placed chief financial officer Cory Hilliard, 54, hired last December, on leave after learning of his arrest on theft and embezzlement charges tied to a prior job in the University of Colorado athletic department.
Sources: ESPN Olympics · ↑ top
S&P 500 7,739.48 ▲ +2.3% Dow 53,892.03 ▲ +1.2% Nasdaq 26,535.65 ▲ +3.3% WTI crude 80.81 ▲ +1.1% EUR/USD 1.1546 ▲ +0.3% GBP/USD 1.3487 ▲ +0.4% USD/JPY 158.46 ▼ -0.5%