================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Friday, August 21, 2026 - 7:36 PM EDT ================================================================ Microsoft walked back its claim that attackers exploited a CVSS 10.0 Entra ID flaw, even as fresh malware families in npm, Teams, and FTP banners and a wave of AI-brand abuse crowded the day. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Attackers weaponized AI's brand and its code, impersonating Perplexity and Claude to seed stealers while trojanized npm packages launched the AI-assisted RedC2 backdoor. see: AI Brand Abuse and Guardrail Bypasses; New Malware Families in npm, Teams, and FTP Banners * [TREND] Identity and collaboration servers stayed the front line as Microsoft revised its Entra ID CVSS 10.0 flaw and CISA ordered federal patches for TrueConf and Zimbra. see: Microsoft Entra ID CVSS 10.0 Flaw; CISA Orders Patches for TrueConf and Zimbra * [UPDATE (new)] Check Point disclosed how Microsoft Defender's own signed BTR.sys driver can be abused to delete security tools at boot across Windows 7 through 11. see: Microsoft Defender Driver Weaponized to Kill Security Tools * [UPDATE (new)] Third-party software failures exposed employee data at Toronto's SickKids hospital and fueled breach claims tied to U.S. Bank. see: Third-Party Breaches Hit SickKids and U.S. Bank * [TREND] Public-health alarms rose locally as Pittsburgh doctors braced for more measles after UPMC's first case since 2019 and officials recalled alfalfa sprouts in a multistate outbreak. see: Pittsburgh Doctors Brace for More Measles; Alfalfa Sprouts Recalled in Outbreak SECURITY ---------------------------------------------------------------- 1. MICROSOFT ENTRA ID CVSS 10.0 FLAW Vulnerabilities and Exploits · [patch, identity, rce] Latest developments: Microsoft on August 21, 2026 corrected CVE-2026-69836's exploitation status from 'Yes' to 'No' after The Hacker News pressed it, reversing the earlier claim that attackers hit the CVSS 10.0 Entra ID remote-code-execution bug in the wild. Microsoft principal security engineer Robert Fitzpatrick found CVE-2026-69836, which lets an attacker run code remotely against Entra ID, the cloud identity service formerly called Azure Active Directory that guards Microsoft 365 and Azure logins. Microsoft shipped it among 22 patches and says the cloud-side fix demands no customer action. - Help Net Security: https://www.helpnetsecurity.com/2026/08/21/microsoft-entra-id-vulnerability-cve-2026-69836/ - The Hacker News: https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html - BleepingComputer: https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/ - SecurityWeek: https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches/ 2. AI BRAND ABUSE AND GUARDRAIL BYPASSES AI Security · [ai, malware, jailbreak] Latest developments: Sophos X-Ops confirmed 34 malicious cases over a year in which attackers impersonated Perplexity, Claude, ChatGPT, and Copilot to plant stealers, backdoors, and rogue browser extensions; researchers extended Cryptographic Context Injection to jailbreak Google's Gemini alongside xAI's Grok; and OpenAI added access controls following last month's Hugging Face intrusion. Criminals now trade on AI's popularity and probe its safety layers at once, cloning marquee chatbot brands to spread malware and hiding encrypted instructions that decrypt inside a trusted execution environment to slip past guardrails. OWASP also published a new top-10 list and Universal Skill Format for AI add-ons. - Help Net Security: https://www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/ - SecurityWeek: https://www.securityweek.com/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini/ - Dark Reading: https://www.darkreading.com/application-security/openai-adds-controls-already - Dark Reading: https://www.darkreading.com/application-security/owasp-flags-top-ai-skill-risks-security-blueprint 3. CISA ORDERS PATCHES FOR TRUECONF AND ZIMBRA Vulnerabilities and Exploits · [exploit, kev, patch] Latest developments: CISA ordered federal agencies to patch two actively exploited TrueConf Server flaws that the Head Mare hacktivist group abuses to deploy PhantomCore malware, and added Zimbra Collaboration Suite's OS command-injection bug CVE-2026-73570 to its Known Exploited Vulnerabilities catalog. The TrueConf holes CVE-2026-72529 and CVE-2026-72530 sit in the self-hosted communications platform, and Head Mare uses them to plant PhantomCore. Federal agencies must patch both products under CISA's risk-based directive, and private operators of either should upgrade at once. - BleepingComputer: https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/ - SecurityWeek: https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-trueconf-vulnerabilities/ - CISA Advisories: https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog 4. NEW MALWARE FAMILIES IN NPM, TEAMS, AND FTP BANNERS Ransomware and Cybercrime · [malware, supply-chain, phishing] Latest developments: Trend Micro's TrendAI found 14 trojanized npm packages posing as calendar and streak utilities that launch RedC2 4.0, an AI-assisted Linux backdoor; BleepingComputer detailed SynkLoader stealing credentials behind a fake lock screen in Microsoft Teams phishing; and threat actors hid commands inside FTP server banners to drop the E4del and PINHOLE Windows remote access trojans. Three previously undocumented families surfaced in one day, each riding a trusted channel—a package registry, a corporate chat app, and an old file-transfer protocol. Developers should audit npm dependencies, and defenders should watch Teams lures and FTP banner traffic. - The Hacker News: https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/ 5. THIRD-PARTY BREACHES HIT SICKKIDS AND U.S. BANK Data Breaches · [breach, healthcare, third-party] Latest developments: Toronto's Hospital for Sick Children said a flaw in third-party software exposed personal data of current and former employees and job applicants while sparing clinical systems and patient records, and U.S. Bank tied breach claims against it to a fourth-party incident, finding no sign attackers reached its own systems, networks, or data. SickKids, which a 2022 ransomware attack already knocked offline, again lost data through a supplier's software. Both cases show breaches arriving through vendors and vendors' vendors rather than the named organizations' own networks. - BleepingComputer: https://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/ - The Record: https://therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data - The Record: https://therecord.media/us-bank-says-breach-claims-related-to-fourth-party-incident 6. MICROSOFT DEFENDER DRIVER WEAPONIZED TO KILL SECURITY TOOLS Vulnerabilities and Exploits · [defense-evasion, windows, malware] Latest developments: Check Point Research disclosed how BTR.sys, Microsoft Defender's own legitimately signed Boot Time Removal Tool driver, runs arbitrary kernel-level file and registry operations to delete security software at boot across Windows 7 through Windows 11 25H2, exploiting no flaw and importing no outside driver. The technique turns a trusted, Microsoft-signed component into a kernel-level weapon, letting an attacker wipe defenses before they load. Because it abuses a legitimate driver already on the machine, blocklists aimed at rogue drivers miss it, and defenders should monitor BTR.sys behavior directly. - The Hacker News: https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html BUSINESS AND POLITICS ---------------------------------------------------------------- * Bond Selloff Spreads to Dollar and Crypto Latest developments: Investors kept dumping long-dated Treasuries on August 21 despite Treasury Secretary Scott Bessent's buyback push, and the retreat hit the dollar—the WSJ Dollar Index fell 0.7% for the week—while bitcoin logged its best week in more than three years and gold jumped 5.56%. Traders reading Bessent's bond-buyback intervention as an effort to cap rising yields piled into 'debasement' trades, pushing bitcoin toward $80,000 and Comex gold to $4,624.10 an ounce as the Dow headed for its worst week since March. - FT Markets: https://www.ft.com/content/7e0c8dc0-e957-420a-bba3-d33666d919b8?syn-25a6b1a6=1 - WSJ Markets: https://www.wsj.com/finance/investing/bond-yields-rise-despite-treasury-efforts-to-curb-borrowing-costs-8aed2b0f?mod=rss_markets_main * Turmoil Grips Fannie Mae's Executive Ranks Latest developments: Fannie Mae dismissed roughly 12 senior executives, the Wall Street Journal reported August 21, and the departures are stoking concerns about stability inside the government-controlled mortgage giant. Fannie Mae, the federally controlled company standing behind a large share of U.S. home loans, let go about a dozen high-ranking officials, unsettling investors and regulators who watch the firm for signs of instability in the mortgage market. - WSJ Markets: https://www.wsj.com/finance/regulation/fannie-mae-hit-by-turmoil-in-senior-ranks-as-at-least-10-executives-depart-9f0f40e0?mod=rss_markets_main * Iran's President Signals Openness to End War Latest developments: Iranian President Masoud Pezeshkian on August 21 called for ending the war with the United States from a 'position of strength,' exposing a debate within Tehran over how much economic pressure the country can bear. Pezeshkian's remarks landed as Washington moved to tighten the economic squeeze on Iran; oil futures ended the week higher with the Strait of Hormuz standoff unresolved. - FT Markets: https://www.ft.com/content/9a094571-604d-4f1e-b5ff-c0b5dc032dc1 PITTSBURGH ---------------------------------------------------------------- Weather: Tonight: Mostly Clear, low 61F. Saturday: Patchy Fog then Chance Showers And Thunderstorms, high 83F. Saturday Night: Chance Showers And Thunderstorms then Showers And Thunderstorms, low 62F. Business: * Steelworkers Rally Downtown for Safety Latest developments: Dozens of United Steelworkers members marched through downtown Pittsburgh at midday August 21, turning a vigil into a rally demanding stronger workplace-safety protections. The United Steelworkers, the Pittsburgh-based union, drew marchers through the city center to press for better safety protections for members. - TribLive: https://triblive.com/business/united-steelworkers-march-through-pittsburgh-in-rally-for-workplace-safety/ * Alfalfa Sprouts Recalled in Outbreak Latest developments: Federal health officials on August 21 tied an E. coli and salmonella outbreak that sickened dozens across 15 states to alfalfa sprouts from Minneapolis-based Everything Sprouts. The Food and Drug Administration said sprouts sold under the Everything Sprouts and Calco brands to restaurants and grocery stores carried the contamination, prompting a recall. - KDKA: https://www.cbsnews.com/pittsburgh/news/alfalfa-sprouts-recall-e-coli-salmonella-outbreak/ Around town: * DA Says Millions Missing From City's Books Latest developments: District Attorney Stephen Zappala said August 21 that the Ed Gainey administration paid money to outside organizations that then failed to document how they spent it, leaving 'millions' of taxpayer dollars unaccounted for. Zappala's office, armed with a search warrant, will comb thousands of financial records from the city of Pittsburgh; the district attorney said trouble began when recipients could not prove how the funds were used. - KDKA: https://www.cbsnews.com/pittsburgh/news/allegheny-county-district-attorneys-office-pittsburgh-finances-investigation/ * County Council Appeals Term-Limits Ruling Latest developments: Allegheny County Council voted 9-6 on August 21 to appeal to Commonwealth Court a judge's ruling that blocked November ballot questions on term limits for county officials. The ruling held that voters must first create a study commission before deciding whether to cap terms for the county executive, council members, and row officers; the council's appeal seeks to revive the ballot measure. - TribLive: https://triblive.com/news/politics-election/allegheny-county-council-takes-term-limits-fight-to-commonwealth-court/ * Pittsburgh Doctors Brace for More Measles Latest developments: With Pennsylvania cases climbing, Pittsburgh doctors warned August 21 that more local measles cases are likely after UPMC Children's Hospital confirmed the region's first infection since 2019, exposing about 100 people. The Allegheny County Health Department said the patient visited UPMC Children's Hospital of Pittsburgh's emergency department on August 12 and August 18; officials are urging MMR vaccination as statewide cases rise. - TribLive: https://triblive.com/news/health-now/pittsburgh-doctors-brace-for-more-measles-as-pa-cases-surge/ Events: * Renaissance Festival Delays Opening to Aug. 29 Latest developments: The Pittsburgh Renaissance Festival postponed its opening weekend to Saturday, August 29, and Sunday, August 30, citing weather, organizers announced August 21. The Pittsburgh Renaissance Festival, which had planned to open this weekend, will now begin the weekend of August 29 and 30. - WPXI: https://www.wpxi.com/news/local/pittsburgh-renaissance-festival-postpones-opening-weekend/JNC6PPFPNVDF3IDTI72Q2FOQXI/ * Westmoreland Fair Opens for 72nd Year Latest developments: The Westmoreland Fair opened Friday, August 21, kicking off its 72nd year with food and family traditions. The annual Westmoreland Fair, now in its 72nd year, features fair food and family activities; opening day fell on Friday, August 21. - WPXI: https://www.wpxi.com/news/local/westmoreland-fair-kicks-off-72nd-year-showcasing-food-family-traditions/FVMRB2UBXNGCLNPSWCMCCE2BZU/ * Josh Turner Headlines Weekend Guide Latest developments: The Post-Gazette's August 20 weekend guide spotlights country singer Josh Turner in concert and a vintage 'base ball' game among things to do around Pittsburgh this weekend. Country artist Josh Turner performs in the Pittsburgh area this weekend, one outing in the Post-Gazette's roundup, which also lists a vintage 'base ball' game played by 19th-century rules. - Post-Gazette Arts & Entertainment: https://www.post-gazette.com/life/recreation/2026/08/20/things-to-do-this-weekend-pittsburgh-9/stories/202608200005 SPORTS ---------------------------------------------------------------- Around the Teams: * Weidl's 'Bigger Is Better' Shapes the Roster Latest developments: A Post-Gazette profile August 21 detailed how personnel executive Andy Weidl's preference for bigger players continues to shape the Steelers' roster under general manager Omar Khan. The Post-Gazette traced Weidl's size-first philosophy, drawn from his years with the Philadelphia Eagles and Baltimore Ravens, through the Steelers' recent draft and roster-building choices. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/08/21/nfl-draft-weidl-omar-khan-eagles-ravens-superbowl/stories/202608200050 * SportsNet Pittsburgh Extends Pirates Deal Latest developments: SportsNet Pittsburgh extended its broadcast agreement with the Pirates into the 2027 season, the Post-Gazette reported August 21, amid what the network calls positive momentum. SportsNet Pittsburgh, which carries Pirates and Penguins games, renewed its rights arrangement with the Pittsburgh Pirates. - Post-Gazette Pirates: https://www.post-gazette.com/sports/penguins/2026/08/21/sportsnet-pittsburgh-pirates-2027-season/stories/202608210020 * Cam Heyward's Podcast Runs Camp Series Latest developments: Cam Heyward's 'Not Just Football' podcast rolled out a Steelers training-camp series, posting episodes August 19 and 21 with teammates from the defense. Heyward and co-host Hayden hosted defensive linemen Keeanu Benton and Sebastian Joseph-Day, plus safety DeShon Elliott and linebacker Patrick Queen, in camp conversations the show releases Monday, Wednesday, and Friday. - Not Just Football with Cam Heyward: https://www.youtube.com/watch?v=3OTIxTpCMCU - Not Just Football with Cam Heyward: https://www.youtube.com/watch?v=ZQGSMsozME4 Team USA: * Jenny Simpson Ends Her Running Career Latest developments: United States Olympic bronze medalist Jenny Simpson said her competitive running 'has ended' after she collapsed while pacing a mile group this summer, ESPN reported August 21. Simpson, a bronze medalist for the United States, told ESPN her running chapter is over following the collapse. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49680958/olympic-medalist-simpson-running-chapter-collapse READING ---------------------------------------------------------------- * Stratechery -- Apple Settles With E.U., U.S. App Store Fees, ATT Rules in Germany Ben Thompson argues Apple's App Store is finally accepting lower fees under EU pressure, and that the settlement, though late, leaves the EU justified in its case. https://stratechery.com/2026/apple-settles-with-e-u-u-s-app-store-fees-att-rules-in-germany/ * Ed Zitron -- What Happens If OpenAI Dies? Zitron games out the fallout of an OpenAI collapse, arguing the company's precarious finances make its potential failure a systemic risk for the broader AI industry. https://www.wheresyoured.at/what-happens-if-openai-dies/ * Cal Newport -- On AI Coding and Its Discontents Newport examines a self-described AI skeptic turned convert among software engineers, weighing what AI coding tools actually change about programming work. https://calnewport.com/on-ai-coding-and-its-discontents/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,714.34 ▼ -0.6% Dow 53,351.57 ▼ -1.0% Nasdaq 26,412.41 ▼ -0.8% WTI crude 85.10 ▲ +4.3% EUR/USD 1.1620 ▲ +0.7% GBP/USD 1.3575 ▲ +0.6% USD/JPY 159.05 = +0.0% ================================================================ Generated 2026-08-21 19:36 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================