infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

A build-time supply-chain attack on three widely used Rust crates leads a day of attackers subverting trusted software, from multiplying Android banking trojans to an encrypted prompt-injection flaw that leaks Grok chats.


Emerging Trends and Key Updates

Security

1. New Critical Flaws and KEV Additions

Vulnerabilities and Exploits · [patch, exploited]

Latest developments: CISA added TrueConf Server flaws CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities catalog on August 20, 2026, as researchers disclosed Elementor Pro's CVSS 9.0 file-upload bug CVE-2026-32475 and a CVSS 9.4 chain in NASA/JPL's AIT-GUI that lets unauthenticated attackers issue spacecraft commands, and Cisco patched critical Crosswork and Secure Workload holes.

read more

A fresh batch of critical flaws spans video conferencing, WordPress, spacecraft ground software, and Cisco management tools; prioritize the actively exploited TrueConf bugs and patch the RCE-capable Elementor Pro plugin.

Sources: CISA Advisories · The Hacker News · The Hacker News · SecurityWeek · ↑ top

2. Android Banking Trojans Multiply

Ransomware and Cybercrime · [malware, android]

Latest developments: Researchers detailed Manic, which targets Ukrainian banks and Russian and European financial institutions and falls back to relaying stolen data through nearby infected devices when a phone sits offline, while Zimperium zLabs documented ToxicPanda 2.0 wielding 167 remote commands and PIN harvesting across more than 140 banking and cryptocurrency apps.

read more

Android banking malware is proliferating—Manic, ToxicPanda 2.0, GoldDigger, and a revived Grandoreiro campaign in Mexico—adding on-device fraud and novel exfiltration; users should install apps only from official stores and scrutinize accessibility-permission requests.

Sources: The Hacker News · The Hacker News · BleepingComputer · Dark Reading · ↑ top

3. Rust Supply-Chain Attack Poisons Crates

Vulnerabilities and Exploits · [supply-chain, malware]

Latest developments: The Rust Project deleted arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 from crates.io on August 20, 2026 after a hijacked maintainer account slipped in a typosquatted dependency whose build script fetched and ran an infostealer during compilation.

read more

The three crates together draw 245 million downloads, so the malware executed on developers' machines at build time across the Rust ecosystem; teams should audit recent builds and pin known-good versions.

Sources: The Hacker News · BleepingComputer · ↑ top

4. Cryptographic Context Injection Leaks Grok Chats

AI Security · [ai, data-theft]

Latest developments: Adversa AI disclosed Cryptographic Context Injection, which hides encrypted malicious instructions inside a web page so that when a user asks Grok to summarize it, xAI's chatbot ships the person's name, approximate location, subscription tier, and conversation prompts to an attacker-controlled server.

read more

Encoding the payload defeats Grok's safety guardrails and exposes user data through an ordinary summarize request; treat AI assistants that browse untrusted pages as an exfiltration channel.

Sources: The Hacker News · Ars Technica Security · ↑ top

5. Police Hide Flock Camera Surveillance

Policy and Regulation · [policy, surveillance]

Latest developments: A leaked Wapello County, Iowa policy instructs officers never to mention automated license plate reader use to drivers or in reports, exposing how police conceal Flock camera surveillance, while a satirical 'Darth Vader' speaker mocked the technology at a San Diego city council meeting.

read more

Flock's license plate readers spread across US jurisdictions with little public disclosure, raising accountability and privacy concerns; the secrecy policy shows departments hiding the tool from the people they surveil and from courts.

Sources: Schneier on Security · 404 Media · ↑ top

6. Russian Clusters Abuse OAuth and WhatsApp

Nation-State Activity · [apt, espionage]

Latest developments: Investigators tied three suspected Russian espionage clusters—UNC6293, UNC7005, and UNC5976—to abuse of Google OAuth flows and WhatsApp device linking to hijack accounts of academics, aerospace and defense workers, government staff, and think-tank researchers across Europe and the United States.

read more

The actors ride legitimate authentication flows, so multifactor prompts and OAuth consent screens become the attack surface; scrutinize unexpected device-linking and app-authorization requests.

Sources: The Hacker News · ↑ top

Business and Politics

Treasury Buyback Bid Fails to Halt Bond Selloff

Latest developments: A second straight day of falling stocks and rising long-bond yields on August 20 showed investors had brushed off Treasury Secretary Scott Bessent's buyback pledge as too small, and the turmoil rattled quantitative and momentum funds already unsettled by the AI-stock selloff.

read more

The Treasury Department, under Secretary Scott Bessent, promised August 19 to at least double its buybacks of long-dated bonds to arrest a selloff that had driven 30-year yields to their highest since 2001; on August 20 those yields climbed again and the S&P 500 fell as investors judged the purchases too small to matter.

Sources: FT Markets · WSJ Markets · FT Markets · ↑ top

Pittsburgh

Weather

Tonight: Slight Chance Rain Showers then Patchy Fog, low 60F.

Friday: Patchy Fog then Sunny, high 81F.

Friday Night: Mostly Clear then Patchy Fog, low 63F.

Business

Allegheny County Pension Fund Faces $1.4 Billion Gap

Latest developments: County Executive Sara Innamorato said August 20 her administration will stop deferring the shortfall, telling the retirement board it must find roughly $100 million to keep the fund from running dry.

read more

Allegheny County's employee pension fund carries a $1.4 billion shortfall that will drain it without large cash infusions, and the county's retirement board, whose members say they inherited the problem, is weighing how to raise the roughly $100 million the fund needs.

Sources: KDKA · ↑ top

PRT Starts $58 Million Panhandle Bridge Rehab

Latest developments: Pittsburgh Regional Transit began preparatory work August 20 on the century-old Panhandle Bridge ahead of a nearly three-year, $58 million rehabilitation.

read more

The Panhandle Bridge carries light-rail trains over the Monongahela River between Station Square and First Avenue Downtown; Pittsburgh Regional Transit will spend $58 million over nearly three years rebuilding the more-than-hundred-year-old span.

Sources: TribLive · WPXI · ↑ top

Around Town

Measles Reaches Allegheny County

Latest developments: UPMC confirmed August 20 that an unvaccinated patient tested positive for measles at UPMC Children's Hospital of Pittsburgh, the county's first case since 2019.

read more

An unvaccinated patient who visited the UPMC Children's Hospital of Pittsburgh emergency department on August 12 tested positive for measles, the first case in Allegheny County since 2019; UPMC and the Allegheny County Health Department said they have notified everyone who may have been exposed and see no ongoing risk at the hospital.

Sources: KDKA · Pittsburgh Post-Gazette · ↑ top

DA Probes Missing Millions in Pittsburgh Finances

Latest developments: Allegheny County District Attorney Stephen Zappala said August 20 that an investigation into the city of Pittsburgh's finances, advanced by a search warrant, indicates millions of dollars appear to be missing.

read more

Allegheny County District Attorney Stephen Zappala disclosed an investigation into the city of Pittsburgh's finances in which, he said, millions of dollars appear to be missing, a probe backed by a search warrant.

Sources: Pittsburgh Post-Gazette · ↑ top

Study Confirms Chemical Exposure in East Palestine

Latest developments: Researchers reported that 74% of urine samples collected after the February 2023 Norfolk Southern derailment in East Palestine, Ohio, showed vinyl chloride exposure.

read more

More than three years after a Norfolk Southern train derailed and burned in East Palestine, Ohio, just across the Pennsylvania line, researchers found vinyl chloride exposure in 74% of urine samples taken from area residents, early evidence of the health toll from chemicals released into the air, water, and soil.

Sources: KDKA · ↑ top

Events

Bernard Purdie at Pittsburgh International Jazz Festival

Latest developments: The Post-Gazette previewed drummer Bernard Purdie's coming appearance at the Pittsburgh International Jazz Festival.

read more

The drummer Bernard Purdie, known for a signature groove behind decades of soul and R&B records, will play the Pittsburgh International Jazz Festival.

Sources: Post-Gazette Music · ↑ top

BurnBabyBurn at the August Wilson House

Latest developments: The Post-Gazette profiled playwright A.K. Payne ahead of the Pittsburgh Playwrights staging of her play BurnBabyBurn.

read more

Pittsburgh playwright A.K. Payne's BurnBabyBurn, a work in which she searches for a grandmother she never knew, is staged by Pittsburgh Playwrights at the August Wilson House in the Hill District.

Sources: Post-Gazette Arts & Entertainment · ↑ top

Mary Lou Williams Puppet Show for Kids

Latest developments: The Post-Gazette highlighted a puppet show introducing children to Pittsburgh jazz great Mary Lou Williams.

read more

A puppet show, "Jazz Heart," teaches children about Mary Lou Williams, the Pittsburgh-raised pianist and composer known as the "Queen of Jazz."

Sources: Post-Gazette Music · ↑ top

Sports

Around the Teams

Steelers' Interior Line Central to Graham's Defense

Latest developments: A Post-Gazette breakdown August 20 detailed why coordinator Patrick Graham's scheme hinges on Keeanu Benton, Derrick Harmon, and Cam Heyward controlling the line of scrimmage.

read more

The Post-Gazette reported that defensive coordinator Patrick Graham's plan leans on the Steelers' interior linemen—Keeanu Benton, Derrick Harmon, and Cam Heyward—calling their play up front critical to what the defense wants to do.

Sources: Post-Gazette Steelers · ↑ top

Pirates' Hassell Works to Rebuild His Career

Latest developments: The Post-Gazette profiled outfielder Robert Hassell III's effort to revive his career with the Pirates.

read more

Robert Hassell III, once a top prospect the San Diego Padres sent to Washington in the 2022 Juan Soto trade, is trying to rebuild his career with the Pittsburgh Pirates, the Post-Gazette reported.

Sources: Post-Gazette Pirates · ↑ top

Team USA

Aaronson Signs New Leeds Contract

Latest developments: Leeds United announced August 20 that United States attacker Brenden Aaronson signed a new three-year contract.

read more

United States men's national team attacker Brenden Aaronson agreed to a three-year deal keeping him at Premier League club Leeds United, the team said August 20.

Sources: ESPN Soccer · ↑ top

Reading

Markets

weekly average, change vs prior week

S&P 500     7,745.91  ▲ +0.1%
Dow        53,567.73  ▼ -0.6%
Nasdaq     26,559.58  ▲ +0.1%
WTI crude      83.78  ▲ +3.7%
EUR/USD       1.1588  ▲ +0.4%
GBP/USD       1.3546  ▲ +0.4%
USD/JPY       159.16  ▲ +0.2%