================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Thursday, August 13, 2026 - 7:05 AM EDT ================================================================ A compromised AI gateway package bleeds 153 gigabytes of corporate credentials as North Korea's Lazarus Group turns a freshly patched Windows zero-day on defense contractors across four countries. CONTENTS: Emerging Trends and Key Updates | Security | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] North Korea's Lazarus rode the freshly patched afd.sys WinSock flaw to SYSTEM within a day, as researchers disclosed two more local Windows paths to SYSTEM. see: Lazarus Exploits Windows Zero-Day Against Defense Firms; New Local Attacks Seize SYSTEM on Windows * [TREND] A compromised LiteLLM AI gateway spilled 153GB of tokens and CI-runner secrets tied to 2,488 firms, among them AWS, Samsung, and Cisco. see: LiteLLM Supply-Chain Leak Exposes 153GB of Credentials * [TREND] The line between statecraft and crime kept blurring as Jewelbug ran espionage and crypto heists from one panel while the White House hired firms to strike cybercrime gangs. see: Jewelbug APT Mixes Espionage and Crypto Theft; White House Enlists Security Firms to Hit Cybercrime Gangs * [UPDATE (new)] Fortinet patched FortiWeb and FortiManager authentication bypasses while Adobe fixed three CVSS 10.0 bugs, including a ColdFusion OS-command flaw. see: Critical Enterprise Flaws Draw Fresh Patches and Exploits * [TREND] Commentators pressed AI's contradictions, with Zitron doubting the boom's economics, Newport probing coding tools, and Thompson faulting Anthropic's watermarking. see: Don't Look Up; On AI Coding and Its Discontents; Anthropic's Watermarking, How It (Probably) Works, Worse Than It Seems * [UPDATE (new)] Wegmans broke ground on its first Pittsburgh-region store as the city switched on red-light cameras at two intersections. see: Wegmans Breaks Ground in Cranberry; Red-Light Cameras Go Live SECURITY ---------------------------------------------------------------- 1. CRITICAL ENTERPRISE FLAWS DRAW FRESH PATCHES AND EXPLOITS Vulnerabilities and Exploits · [patch, vulnerability, zero-day] Latest developments: Fortinet patched authentication flaws in FortiWeb and FortiManager that let attackers log in with arbitrary usernames and passwords or impersonate any FortiGate appliance, and Adobe fixed three CVSS 10.0 bugs including ColdFusion OS-command-injection CVE-2026-48362, as attackers pressed active exploitation of VMware vCenter directory-traversal CVE-2026-59310 and SharePoint authentication bypass CVE-2026-55040. The four vendors anchor enterprise perimeters, e-commerce, and collaboration; VMware vCenter CVE-2026-59310 and SharePoint CVE-2026-55040 both grant remote code execution or account takeover and now see in-the-wild abuse following public proof-of-concept releases. Administrators should apply every fix without delay. - SecurityWeek: https://www.securityweek.com/fortinet-patches-authentication-flaws-in-fortiweb-and-fortimanager/ - The Hacker News: https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html - SecurityWeek: https://www.securityweek.com/critical-vmware-vcenter-vulnerability-in-attackers-crosshairs/ - The Hacker News: https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html 2. LITELLM SUPPLY-CHAIN LEAK EXPOSES 153GB OF CREDENTIALS AI Security · [supply-chain, breach, ai] Latest developments: Hudson Rock obtained and analyzed the 153GB archive that intruders stole in the LiteLLM supply-chain attack, counting 433,909 files and 118,829 CI-runner dumps traced to 2,488 corporate domains, among them AWS, Samsung, Cisco, and Salesforce. LiteLLM is a widely deployed open-source gateway that routes application traffic to large language models. Attackers scraped and exfiltrated secrets from roughly 2,500 users of the compromised package; Hudson Rock co-founder and chief technology officer Alon Gal says the firm now runs a global ethical-disclosure effort, and affected organizations should rotate exposed keys and credentials immediately. - Help Net Security: https://www.helpnetsecurity.com/2026/08/13/litellm-breach-stolen-credentials-leak/ - Ars Technica Security: https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/ 3. NEW LOCAL ATTACKS SEIZE SYSTEM ON WINDOWS Vulnerabilities and Exploits · [vulnerability, privilege-escalation, windows] Latest developments: Researchers published two new local paths to SYSTEM on Windows: Nightmare Eclipse's ShieldBreak exploit, dropped on Patch Tuesday, lets any user spawn a shell with SYSTEM privileges, and Plug and Pwn abuses the Windows Plug and Play feature to install vulnerable vendor software from a spoofed USB device. Both techniques hand a low-privileged or physically present attacker full control of a Windows machine, a common step between initial access and domain-wide compromise. Defenders should restrict USB device installation, tighten driver-installation policy, and monitor for unexpected privilege escalation. - SecurityWeek: https://www.securityweek.com/nightmare-eclipse-drops-windows-zero-day-exploit-shieldbreak/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/plug-and-pwn-attack-uses-fake-usb-devices-for-windows-system-access/ 4. JEWELBUG APT MIXES ESPIONAGE AND CRYPTO THEFT Nation-State Activity · [apt, cryptocurrency, espionage] Latest developments: Researchers detailed Jewelbug, a hackers-for-hire group that carries out state-sponsored cyber espionage and financially motivated cryptocurrency heists from the same web control panel. Jewelbug collapses the usual boundary between government spying and criminal profit, running both mission sets through shared tooling. Defenders tracking either motive should treat overlapping infrastructure and toolmarks as signs of one operator. - Dark Reading: https://www.darkreading.com/threat-intelligence/jewelbug-apt-state-espionage-cryptocurrency-theft 5. WHITE HOUSE ENLISTS SECURITY FIRMS TO HIT CYBERCRIME GANGS Policy and Regulation · [policy, cybercrime] Latest developments: The White House began contracting private security companies to run operations against foreign cybercrime gangs, with deals that may require a $1 million bond the firm forfeits if it breaks operational requirements. The arrangement pushes offensive action against overseas criminal groups into private hands under government contract, raising questions about oversight, liability, and rules of engagement. The program marks a shift toward public-private disruption of ransomware and fraud infrastructure. - SecurityWeek: https://www.securityweek.com/white-house-mobilizes-security-firms-for-operations-against-foreign-cybercrime-gangs/ 6. LAZARUS EXPLOITS WINDOWS ZERO-DAY AGAINST DEFENSE FIRMS Nation-State Activity · [apt, zero-day, patch] Latest developments: Check Point Research tied North Korea's Lazarus Group to zero-day exploitation of CVE-2026-68820, the afd.sys WinSock flaw Microsoft patched August 11, which the crew rode to SYSTEM privileges and used to drop a never-before-seen backdoor on defense and aerospace companies in France, Germany, Brazil, and India. The activity extends Operation Dream Job, Lazarus's long-running espionage campaign that lures targets through fake job offers. CISA gave U.S. federal civilian agencies two weeks to patch the flaw; every Windows enterprise should deploy the August update now. - The Hacker News: https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms/ - The Record: https://therecord.media/cisa-gives-federal-agencies-two-weeks-to-patch-dprk-microsoft-bug PITTSBURGH ---------------------------------------------------------------- Weather: Today: Partly Sunny, high 84F. Tonight: Mostly Cloudy then Patchy Fog, low 67F. Friday: Patchy Fog then Chance Showers And Thunderstorms, high 83F. Business: * Wegmans Breaks Ground in Cranberry Latest developments: Wegmans breaks ground August 13 on its first Pittsburgh-region store. Wegmans breaks ground August 13 on its first Pittsburgh-area store at the Cool Springs development in Cranberry Township, near the Penguins' UPMC Lemieux Sports Complex; the grocer expects to open sometime in 2027. - KDKA: https://www.cbsnews.com/pittsburgh/news/wegmans-groundbreaking-today-pittsburgh-area-cranberry-township/ * Charleroi Glass Plant for Sale Latest developments: The former Corelle glass plant in Charleroi went on the market more than a year after closing. The former Corelle Brands glass plant in Charleroi has gone up for sale more than a year after its closure, the Post-Gazette reported, testing appetite for a large idled industrial site in the Mon Valley. - Pittsburgh Post-Gazette: https://www.post-gazette.com/business/development/2026/08/13/charleroi-glass-plant-corelle/stories/202608110017 Around town: * Red-Light Cameras Go Live Latest developments: Pittsburgh switched on automated red-light enforcement cameras at two intersections Wednesday. Pittsburgh activated automated red-light enforcement cameras at North Dallas Avenue and Penn Avenue in Point Breeze and at a Saw Mill Run Boulevard intersection, a system the city says targets dangerous intersection running. - KDKA: https://www.cbsnews.com/pittsburgh/news/pittsburgh-automated-red-light-enforcement-begins-today-what-to-know/ * Indiana Township Rejects Housing Plan Latest developments: Indiana Township supervisors unanimously voted down the Cove Run Road development. Indiana Township supervisors voted unanimously to reject a proposed 172-unit housing plan off Cove Run Road. - TribLive: https://triblive.com/local/valley-news-dispatch/indiana-township-supervisors-vote-down-cove-run-road-housing-development/ Events: * Little Italy Days in Bloomfield Latest developments: Little Italy Days opened Thursday, August 13, and runs through Sunday. Little Italy Days, the 26th annual Italian street festival, runs Thursday, August 13, through Sunday, August 16, along Liberty Avenue from Ella Street to Gross Street in Bloomfield; Thursday hours are 5 to 9 p.m., admission is free, and all ages are welcome. - Pittsburgh City Paper: https://www.pghcitypaper.com/listings/this-weeks-top-events/pittsburghs-top-events-thu-aug-13-wed-aug-19/ * Hannah Whitten in Allison Park Latest developments: Riverstone Books hosts novelist Hannah Whitten on Thursday, August 13. Riverstone Books presents An Evening with fantasy author Hannah Whitten on Thursday, August 13, from 1 to 3:30 p.m. at the Hampton Community Center, 3200 Lochner Way, Allison Park; tickets cost $7.82 through riverstonebookstore.com. - Pittsburgh City Paper: https://www.pghcitypaper.com/listings/this-weeks-top-events/pittsburghs-top-events-thu-aug-13-wed-aug-19/ SPORTS ---------------------------------------------------------------- Around the Teams: * Steelers Re-Sign Elandon Roberts Latest developments: The Steelers are bringing back linebacker Elandon Roberts, a Post-Gazette source said. The Steelers are re-signing veteran linebacker Elandon Roberts, the Post-Gazette reported, adding an experienced run defender to Patrick Graham's front seven. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/08/12/nfl-steelers-elandon-roberts-afc/stories/202608120055 * Packers to Play Starters in Opener Latest developments: Green Bay will play quarterback Jordan Love and other starters in Thursday's preseason opener at Acrisure Stadium. TribLive's First Call reported the Packers plan to play Jordan Love and other starters in Thursday's preseason opener at Acrisure Stadium; the Post-Gazette's five things to watch flags Aaron Rodgers sitting while backups Will Howard and Drew Allar and receiver Germie Bernard audition. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/08/13/nfl-preseason-packers-germie-roman-wilson-allar-howard/stories/202608120032 * Kelly: Pirates 'Felt Sorry for Ourselves' Latest developments: Manager Don Kelly said the Pirates 'felt sorry for ourselves' after a rout by the Marlins. After the Miami Marlins routed Pittsburgh, manager Don Kelly said the Pirates 'felt sorry for ourselves,' the Post-Gazette reported, as the club's second-half slide dragged on. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/08/12/mlb-carmen-mlodzinski-pirates-marlins-evan-sisk-lake-bachar/stories/202608120033 Team USA: * Ledecky Wins as U.S. Sets Record Latest developments: Katie Ledecky won the 1,500-meter freestyle and the United States set a world record in the 4x100 mixed medley relay to open the Pan Pacific Championships. Katie Ledecky won the 1,500-meter freestyle on the opening night of the Pan Pacific Championships, and the United States closed the session with a world record in the 4x100 mixed medley relay, ESPN reported. - ESPN Olympics: https://www.espn.com/olympics/swimming/story/_/id/49596355/walsh-berkoff-day-1-pan-pacific-championships-winners * Meyers Taylor Out for Bobsled Season Latest developments: Elana Meyers Taylor will miss the coming World Cup bobsled season with post-concussion symptoms. Olympic monobob gold medalist Elana Meyers Taylor said post-concussion symptoms she has dealt with for months will keep her out of the entire coming World Cup bobsled season. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49591194/olympian-elana-meyers-taylor-miss-world-cup-bobsled-season * USA Swimming Sidelines Its CFO Latest developments: USA Swimming placed chief financial officer Cory Hilliard on leave after learning of his arrest. USA Swimming placed chief financial officer Cory Hilliard, 54, hired last December, on leave after learning of his arrest on theft and embezzlement charges tied to a prior job in the University of Colorado athletic department. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49578646/usa-swimming-places-cfo-cory-hilliard-leave-arrest READING ---------------------------------------------------------------- * Stratechery -- Anthropic's Watermarking, How It (Probably) Works, Worse Than It Seems Ben Thompson argues Anthropic's move to watermark AI output in response to the European Union's AI law is a mistake, faulting it on philosophical grounds and contending the mechanism works worse in practice than it appears. https://stratechery.com/2026/anthropics-watermarking-how-it-probably-works-worse-than-it-seems/ * Ed Zitron -- Don't Look Up Zitron argues the tech industry and its boosters keep refusing to confront mounting evidence that the AI boom rests on shaky economics. https://www.wheresyoured.at/dont-look-up/ * Cal Newport -- On AI Coding and Its Discontents Newport works through the account of a senior Silicon Valley engineer who turned from AI skeptic to convert, weighing what AI coding tools actually change about software work and where the disillusionment sets in. https://calnewport.com/on-ai-coding-and-its-discontents/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,739.48 ▲ +2.3% Dow 53,892.03 ▲ +1.2% Nasdaq 26,535.65 ▲ +3.3% WTI crude 80.81 ▲ +1.1% EUR/USD 1.1546 ▲ +0.3% GBP/USD 1.3487 ▲ +0.4% USD/JPY 158.46 ▼ -0.5% ================================================================ Generated 2026-08-13 07:05 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================