================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Friday, August 14, 2026 - 7:06 AM EDT ================================================================ The ShinyHunters extortion group published personal data on 1.6 million RingCentral accounts, the largest of a day thick with third-party vendor breaches. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] ShinyHunters dumped 1.6 million RingCentral records while Trezor's shipper ShipMonk and the Beacon charity platform fell to a leaked AWS key, all trusted third-party vendors. see: RingCentral Breach and Third-Party Data Theft * [TREND] Attackers are racing to exploit an unpatched GeoServer SQL injection zero-day for remote code execution, days after WordPress shipped 7.0.4 to close its own RCE flaw. see: GeoServer Zero-Day and WordPress RCE * [TREND] Watermark-removal tools rushed to strip Anthropic's Claude labels and a litigant hid a prompt injection in a court filing, even as Ben Thompson calls the watermarking misguided. see: AI Watermark Evasion and Prompt Injection; Anthropic's Watermarking, How It (Probably) Works, Worse Than It Seems * [UPDATE (new)] Kaspersky found HoneyMyte's CoolClient backdoor now hides a kernel-mode rootkit while the Jewelbug group runs espionage against governments and militaries. see: HoneyMyte, Jewelbug, and Mercenary Spyware * [UPDATE (new)] Ukrainian police raided 94 fraudulent call centers seizing $2 million, and a US court sentenced a former Brightly Software contractor for insider extortion. see: Ukraine Call-Center Bust and Insider Extortion * [UPDATE (new)] SecurityWeek detailed AmnesiaStealer, a Rust-based macOS infostealer harvesting keychain and browser data, alongside a stealthier new Mirai variant. see: AmnesiaStealer and a Stealthier Mirai SECURITY ---------------------------------------------------------------- 1. RINGCENTRAL BREACH AND THIRD-PARTY DATA THEFT Data Breaches · [breach, extortion, supply-chain] Latest developments: The ShinyHunters group published data on 1.6 million RingCentral accounts, Trezor disclosed 14,000 customers exposed through logistics provider ShipMonk, and a compromised AWS access key found in public JavaScript build artifacts drove a Beacon CRM breach hitting more than 1,000 charities. RingCentral, a cloud communications provider, lost names, addresses, emails, and phone numbers on 1.6 million accounts to ShinyHunters, which broke in during July; hardware wallet maker Trezor and over 1,000 charities using Beacon CRM lost similar records through hacked suppliers. Audit vendor access, rotate exposed keys, and watch for phishing against affected customers. - BleepingComputer: https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/ - SecurityWeek: https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/ - SecurityWeek: https://www.securityweek.com/over-1000-charities-hit-by-beacon-crm-data-breach/ 2. HONEYMYTE, JEWELBUG, AND MERCENARY SPYWARE Nation-State Activity · [apt, spyware, espionage] Latest developments: Kaspersky found HoneyMyte's CoolClient backdoor now ships a kernel-mode rootkit driver that hides processes, files, and network connections; BleepingComputer tied the Jewelbug group to espionage against governments and militaries running in parallel with cryptocurrency fraud; and Apple sent fresh threat notifications warning targets of mercenary spyware attacks. HoneyMyte, a China-linked APT, deepened CoolClient's stealth with a Windows rootkit, while Jewelbug blends state espionage against government webmail with crypto theft and Apple's alerts flag commercial spyware aimed at individual iPhones. Targets should preserve alerts, harden endpoints, and seek forensic help. - Securelist (Kaspersky): https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/ - BleepingComputer: https://www.bleepingcomputer.com/news/apple/apple-sends-new-threat-notification-alerts-over-mercenary-spyware-attacks/ 3. UKRAINE CALL-CENTER BUST AND INSIDER EXTORTION Ransomware and Cybercrime · [cybercrime, fraud, insider] Latest developments: Ukrainian police raided 94 fraudulent call centers in more than 400 searches, seizing roughly $2 million and thousands of computers, phones, and SIM cards, and a US court sentenced a former Brightly Software data-analyst contractor to two years for a $2.5 million data-theft extortion scheme. The Ukrainian call centers impersonated bank employees and pushed fake investment and cryptocurrency services to drain victims' accounts, while the Brightly insider stole company data to extort his employer. Both cases show law enforcement striking fraud operations and rogue contractors alike. - Help Net Security: https://www.helpnetsecurity.com/2026/08/14/ukraine-fraudulent-call-centers-shut-down/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/ukraine-shuts-down-94-fraudulent-call-centers-seize-millions-in-cash/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/data-analyst-sent-to-prison-for-stealing-data-extorting-employer/ 4. GEOSERVER ZERO-DAY AND WORDPRESS RCE Vulnerabilities and Exploits · [zero-day, patch, rce] Latest developments: SecurityWeek reports hackers are exploiting an unpatched GeoServer SQL injection zero-day for remote code execution, and WordPress shipped 7.0.4 to close a separate remote code execution flaw that Author-level users could trigger through malicious PostScript files. GeoServer, the open-source geospatial server, carries a SQL injection defect attackers exploit for code execution with no fix yet available, so operators should restrict exposure and monitor logs; WordPress 7.0.4 patches its own PostScript-based RCE. Update WordPress immediately and isolate exposed GeoServer instances. - SecurityWeek: https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/ - SecurityWeek: https://www.securityweek.com/wordpress-7-0-4-patches-remote-code-execution-vulnerability/ 5. AMNESIASTEALER AND A STEALTHIER MIRAI Ransomware and Cybercrime · [malware, infostealer, botnet] Latest developments: SecurityWeek detailed AmnesiaStealer, a Rust-based macOS infostealer that harvests passwords, keychain contents, Chromium browser data, and Safari cookies while hijacking browser sessions, and The Record documented a new Mirai variant adding encrypted command-and-control traffic and a sniffer that hunts default credentials. AmnesiaStealer targets Mac users' credentials and live sessions, while the upgraded Mirai code quietly recruits exposed devices with default logins into a botnet. Change default passwords, monitor endpoints, and block unusual outbound traffic. - SecurityWeek: https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/ - The Record: https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code 6. AI WATERMARK EVASION AND PROMPT INJECTION AI Security · [ai, prompt-injection] Latest developments: Watermark-removal tools flooded the web days after Anthropic began watermarking Claude's text output, including an open-source project with over 4,500 GitHub stars, though none can prove they work because Anthropic withholds its detector, and 404 Media found a litigant who hid a prompt injection in a legal filing instructing any AI reader to rule in their favor. Anthropic's new text watermark for Claude drew immediate removal tools of unverifiable efficacy, and a court filing's buried instruction shows prompt injection creeping into everyday documents. Treat AI-processed text as untrusted input and validate provenance claims. - BleepingComputer: https://www.bleepingcomputer.com/news/security/ai-watermark-removers-flood-the-web-almost-none-can-prove-they-work/ - 404 Media: https://www.404media.co/person-hides-prompt-injection-in-legal-filing-telling-ai-to-side-with-them/ BUSINESS AND POLITICS ---------------------------------------------------------------- * Stalled Hormuz Talks Lift Oil and Mortgage Rates Latest developments: Talks over the Strait of Hormuz stalled, driving Brent crude toward $88 and a weekly gain near 6% as the United States prepared to send another aircraft carrier to the Middle East, while home-loan rates jumped across America and several large European economies. Iran's blockade of the Strait of Hormuz, the chokepoint for much of the world's seaborne oil, has kept crude elevated for weeks; the Financial Times reports the standoff has now pushed mortgage costs higher for households in the United States and big European economies, spreading the shock far from the Gulf. - WSJ Markets: https://www.wsj.com/finance/commodities-futures/oil-edges-lower-amid-mixed-signals-cbfa6bef?mod=rss_markets_main - FT World: https://www.ft.com/content/319d874b-6d71-4802-ad4b-e2aac04fdf40?syn-25a6b1a6=1 PITTSBURGH ---------------------------------------------------------------- Weather: Today: Slight Chance Showers And Thunderstorms, high 82F. Tonight: Partly Cloudy, low 66F. Saturday: Mostly Sunny, high 86F. Business: * Homewood Endures Decades of Disinvestment Latest developments: PublicSource published an August 14 examination of how Pittsburgh's Homewood neighborhood holds together after decades of lost investment. Homewood, a predominantly Black neighborhood in Pittsburgh's East End, shed population and commerce over decades; PublicSource found its endurance now rests on a handful of small-business owners, preserved local history, and a deep music tradition. - PublicSource: https://www.publicsource.org/homewood-pittsburgh-community-endures/ * Buffalo Township Postal Owner Foils $100K Scam Latest developments: TribLive reported August 14 that the owner of South Pike Postal in Buffalo Township stopped a customer from losing $100,000 to scammers. Two months ago a woman walked into South Pike Postal in Buffalo Township to overnight-ship a coffee pot she had bought at Dollar General; the shop owner recognized a scam underway and intervened, sparing her a $100,000 loss. - TribLive: https://triblive.com/local/valley-news-dispatch/local-woman-helped-prevent-100k-being-lost-to-scammers/ Around town: * North Allegheny School Renovations Stay on Schedule Latest developments: TribLive reported August 14 that renovations at five North Allegheny schools remain on schedule, with construction starting this coming year at slightly higher estimated costs. The North Allegheny School District, in the northern suburbs of Pittsburgh, is renovating five schools; officials say the work stays on schedule though the estimated price crept up, with construction set to begin during the 2026-27 school year. - TribLive: https://triblive.com/news/education-classroom/renovations-of-5-north-allegheny-schools-on-schedule-with-slightly-higher-estimated-costs/ * Woodland Hills Board Member to Resign Latest developments: WPXI reported August 14 that Woodland Hills School Board member Terri Lawson, tied to a theft case, is expected to resign in September. Terri Lawson, a member of the Woodland Hills School Board east of Pittsburgh, faces a theft case and plans to step down from the board next month. - WPXI: https://www.wpxi.com/news/local/woodland-hills-school-board-member-embroiled-theft-case-expected-resign-next-month/3GAWTDORS5HO5MJ47J63ZIDO7Y/ * Rainy Sunday After a Dry Saturday Latest developments: KDKA and WTAE forecast light showers around Pittsburgh on Friday, a dry and pleasant Saturday, and an Impact Day Sunday with rounds of rain. Forecasters call Saturday the best day of the weekend across the Pittsburgh region, with light passing showers Friday and heavier, more widespread rain returning Sunday, the first round arriving before dawn. - KDKA: https://www.cbsnews.com/pittsburgh/news/light-rain-begins-the-weekend-in-pittsburgh-before-a-dry-and-pleasant-saturday/ - WTAE: https://www.wtae.com/article/isolated-showers-today-impact-day-sunday/73434044 Events: * Little Italy Days in Bloomfield Latest developments: KDKA reported August 14 that Little Italy Days opened in Pittsburgh's Bloomfield neighborhood, running through the weekend of August 13-16 in its 24th year. Little Italy Days, a free street festival built around Italian culture, music, and food, fills Liberty Avenue in Pittsburgh's Bloomfield neighborhood through Sunday, August 16; caterer Tambellini Event Catering alone expects to serve roughly 2,400 meatballs, 500 pounds of sausage, and 500 pounds of pasta. - KDKA: https://www.cbsnews.com/pittsburgh/news/little-italy-days-2026/ - NEXTpittsburgh Arts & Entertainment: https://nextpittsburgh.com/events/14-things-to-do-this-weekend-august-13-16/ SPORTS ---------------------------------------------------------------- Around the Teams: * Steelers Bringing Back Elandon Roberts Latest developments: The Post-Gazette cited a source saying the Steelers are set to re-sign veteran linebacker Elandon Roberts. Pittsburgh is bringing Elandon Roberts back, restoring an experienced run-stuffing linebacker to Patrick Graham's front seven for the 2026 season. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/08/12/nfl-steelers-elandon-roberts-afc/stories/202608120055 * Cam Heyward on Camp Battles and Rookie Life Latest developments: The 'Not Just Football with Cam Heyward' episode posted August 12 checked in from week two of Steelers camp at Saint Vincent College. On his 'Not Just Football' podcast, Steelers defensive lineman Cam Heyward and co-host Hayden broke down the first live-tackling reps and Saturday Night Lights standouts, swapped stories about dorm life and expensive rookie dinners, and debated a 2027 Hall of Fame class that includes Antonio Brown. - Not Just Football with Cam Heyward: https://www.youtube.com/watch?v=wqrQO2-iRcE Team USA: * Ledecky Leads US at Pan Pacs Opener Latest developments: ESPN reported that Katie Ledecky won the 1,500-meter freestyle on the August 12 opening night of the Pan Pacific Championships, and the United States closed the session with a world record in the 4x100-meter mixed medley relay. At the Pan Pacific swimming championships, American distance star Katie Ledecky took the 1,500 freestyle and the United States set a world record in the mixed medley relay, with Gretchen Walsh and Katharine Berkoff among the night's winners. - ESPN Olympics: https://www.espn.com/olympics/swimming/story/_/id/49596355/walsh-berkoff-day-1-pan-pacific-championships-winners * Meyers Taylor to Sit Out Bobsled Season Latest developments: ESPN reported August 12 that Olympic monobob champion Elana Meyers Taylor will miss the coming World Cup bobsled season. Elana Meyers Taylor, the United States monobob Olympic gold medalist, said post-concussion symptoms that have lingered for months will keep her out of the entire upcoming World Cup bobsled season. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49591194/olympian-elana-meyers-taylor-miss-world-cup-bobsled-season READING ---------------------------------------------------------------- * Stratechery -- Anthropic's Watermarking, How It (Probably) Works, Worse Than It Seems Ben Thompson argues that Anthropic's plan to watermark AI output, adopted to satisfy the E.U.'s AI law, is a mistake on philosophical grounds and likely to work worse in practice than it appears. https://stratechery.com/2026/anthropics-watermarking-how-it-probably-works-worse-than-it-seems/ * Ed Zitron -- Don't Look Up Zitron argues that markets and the tech press are willfully ignoring mounting evidence of an AI bubble, likening the denial to the asteroid film of the same name. https://www.wheresyoured.at/dont-look-up/ * Cal Newport -- On AI Coding and Its Discontents Newport uses a converted skeptic's account from a senior Silicon Valley engineer to weigh what AI coding tools actually change about software work, and what the hype obscures. https://calnewport.com/on-ai-coding-and-its-discontents/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,757.29 ▲ +1.5% Dow 53,883.00 ▲ +0.5% Nasdaq 26,626.59 ▲ +2.0% WTI crude 81.61 ▲ +3.7% EUR/USD 1.1540 ▲ +0.1% GBP/USD 1.3493 ▲ +0.2% USD/JPY 158.81 ▲ +0.4% ================================================================ Generated 2026-08-14 07:06 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================