================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Tuesday, August 25, 2026 - 7:35 PM EDT ================================================================ Attackers turned trusted platforms into weapons—npm mirrors into phishing hosts and AI summarizers into liars—as at least 274 Zimbra servers fell to active exploitation of CVE-2026-73570. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Attackers keep converting trusted infrastructure into attack tooling, hosting fake Cloudflare CAPTCHA pages on npm mirrors like unpkg and slipping hidden HTML into emails to hijack AI summarizers. see: Phishing-as-a-Service Scales on npm Mirrors; Attackers Weaponize AI Summaries and Brand Trust * [UPDATE (new)] Active exploitation surged as Shadowserver counted 274 compromised Zimbra servers via CVE-2026-73570, while CISA added a Gitea code-injection flaw and flagged a critical Siemens SIMATIC RCE. see: Mass Compromise of Zimbra Servers via CVE-2026-73570; Fresh KEV Addition and Critical ICS Advisories * [TREND] Identity verification and account recovery proved the soft underbelly as ReliaQuest lost credentials to a single social-engineered employee, with Paylogix and LACMA also disclosing breaches. see: Data Breaches Hit ReliaQuest, Paylogix, and LACMA * [UPDATE (new)] INTERPOL's Operation Jackal IV arrested 58 people across 22 countries and uncovered a 196-person crime-as-a-service network in Argentina supplying domains and money mules. see: INTERPOL Operation Jackal IV Dismantles West African Crime Rings * [UPDATE (new)] Pennsylvania logged its first measles deaths in 35 years as two unvaccinated Lancaster County residents died, and Attorney General Dave Sunday sued Snapchat over child harm. see: Pennsylvania Logs First Measles Deaths in 35 Years; Pennsylvania Sues Snapchat SECURITY ---------------------------------------------------------------- 1. FRESH KEV ADDITION AND CRITICAL ICS ADVISORIES Vulnerabilities and Exploits · [kev, ics, patch] Latest developments: CISA added Gitea code-injection flaw CVE-2026-60004 to its Known Exploited Vulnerabilities catalog and published seven ICS advisories, among them a maximum-privilege Node-RED remote-code-execution hole in Siemens SIMATIC IoT2050 Advanced, hard-coded credentials in the FURUNO FA-50 AIS transponder, and Bendix EC80 brake-ECU flaws that can disable ABS and steering assist. The Gitea flaw threatens self-hosted code repositories, and the ICS bugs reach maritime navigation, heavy-truck braking, and industrial gear. Operators should apply vendor updates and isolate affected devices from untrusted networks. - CISA Advisories: https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog - CISA Advisories: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03 - CISA Advisories: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-05 - CISA Advisories: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-07 2. PHISHING-AS-A-SERVICE SCALES ON NPM MIRRORS Ransomware and Cybercrime · [phishing, supply-chain, mfa-bypass] Latest developments: Researchers exposed a wave of trusted-platform phishing: a cluster of 24 npm packages on unpkg mirrors serving fake Cloudflare CAPTCHA pages that redirect to ClickFix lures, the Mirage2FA toolkit hitting 4,500 US and EU companies through Microsoft 365 login flows, and AnonyMousKIT using voice AI agents to phish iPhone passcodes. Phishing-as-a-service kits let low-skill criminals rent turnkey infrastructure; ANY.RUN found Mirage2FA potentially compromised 48% of the addresses it targeted, and AnonyMousKIT automates unlocking stolen Apple devices by disabling Activation Lock. Organizations should enforce phishing-resistant authentication and block newly registered redirect domains. - The Hacker News: https://thehackernews.com/2026/08/24-npm-packages-abuse-unpkg-mirrors-to.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/ - The Hacker News: https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/ 3. ATTACKERS WEAPONIZE AI SUMMARIES AND BRAND TRUST AI Security · [ai, prompt-injection, malware] Latest developments: Dark Reading detailed how attackers embed hidden HTML invisible to users to make AI email summarizers produce false or malicious output, 404 Media exposed an Israel-funded synthetic think tank churning AI-written essays to warp chatbot search results, Cato Networks caught a fake OpenAI Codex download page pushing a ClickFix Terminal command to macOS users, and Unit 42 mapped AI-enabled malware moving from brand abuse to agentic execution. Prompt injection and AI brand impersonation give adversaries fresh leverage over trusted assistants. Defenders should treat model output as untrusted input and lean on behavioral endpoint detection, which Unit 42 says still stops AI-authored code before execution. - Dark Reading: https://www.darkreading.com/cyber-risk/hidden-prompts-trick-ai-false-email-summaries - 404 Media: https://www.404media.co/israel-is-running-a-synthetic-think-tank-to-influence-ai-search-results/ - Help Net Security: https://www.helpnetsecurity.com/2026/08/25/fake-openai-codex-download-macos-users/ - Unit 42 (Palo Alto): https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ 4. INTERPOL OPERATION JACKAL IV DISMANTLES WEST AFRICAN CRIME RINGS Ransomware and Cybercrime · [law-enforcement, fraud, cybercrime] Latest developments: INTERPOL's Operation Jackal IV, running November 2025 through June 2026 across 22 countries, arrested 58 people and identified 263 suspects, and uncovered a 196-person crime-as-a-service network in Argentina that supplied domains and money laundering to West African groups such as Black Axe. West African syndicates like Black Axe run business-email-compromise and romance scams worldwide, and the eight-month operation seized assets and backed prosecutions. Investigators flagged the outsourced crime-as-a-service model as a troubling new trend. - Help Net Security: https://www.helpnetsecurity.com/2026/08/25/interpol-jackal-iv-west-african-crime-groups-arrests/ - The Record: https://therecord.media/58-arrested-international-cybercrime-crackdown-interpol - BleepingComputer: https://www.bleepingcomputer.com/news/security/police-arrests-dozens-of-suspects-in-global-cybercrime-crackdown/ 5. DATA BREACHES HIT RELIAQUEST, PAYLOGIX, AND LACMA Data Breaches · [breach, ransomware, social-engineering] Latest developments: Cybersecurity firm ReliaQuest confirmed one employee fell for a social engineering attack that handed attackers a password and a window into its identity system after ShinyHunters posted leak-site screenshots, benefits manager Paylogix told regulators Akira ransomware stole financial and health data on tens of thousands, and the Los Angeles County Museum of Art disclosed a 2025 breach exposing Social Security numbers and medical data. The incidents share a theme of identity abuse and third-party exposure, and ReliaQuest downplayed ShinyHunters' broader claims. Affected people should reset credentials and watch for fraud. - Help Net Security: https://www.helpnetsecurity.com/2026/08/25/reliaquest-breach-social-engineering/ - The Record: https://therecord.media/paylogix-cyberattack-akira-ransomware - BleepingComputer: https://www.bleepingcomputer.com/news/security/lacma-data-breach-last-year-exposed-social-security-and-medical-data/ 6. MASS COMPROMISE OF ZIMBRA SERVERS VIA CVE-2026-73570 Vulnerabilities and Exploits · [vulnerability, exploit, patch] Latest developments: The Shadowserver Foundation counted at least 274 internet-facing Zimbra instances already compromised through CVE-2026-73570 in ongoing remote-code-execution attacks, turning the flaw CISA cataloged on August 21, 2026 into a mass in-the-wild campaign. Zimbra Collaboration Suite runs email and calendaring for organizations that self-host to keep control of their data, and CVE-2026-73570 is a code-injection flaw Synacor patched. Administrators should update immediately and hunt their servers for web-shell activity. - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-breached-over-270-zimbra-servers-in-ongoing-attacks/ - Help Net Security: https://www.helpnetsecurity.com/2026/08/25/zimbra-cve-2026-73570-compromised/ BUSINESS AND POLITICS ---------------------------------------------------------------- * Iran Squeeze Cracks Open on Hormuz Latest developments: Iran and Oman edged toward an interim deal to manage shipping through the Strait of Hormuz on August 25, the first diplomatic progress in weeks, and oil futures posted back-to-back losses. Treasury Secretary Scott Bessent's Operation Economic Outcast blockade has stranded Iranian tankers off Sri Lanka and shut the strait, spiking European LNG prices to their highest since 2023; China warned Washington it would retaliate against the new Iran sanctions, complicating any effort to fully isolate Tehran. - FT World: https://www.ft.com/content/b3e4d264-55f0-485e-8e1a-0ba0cbe006b6?syn-25a6b1a6=1 - WSJ Markets: https://www.wsj.com/finance/commodities-futures/oil-edges-higher-as-traders-assess-u-s-measures-against-iran-2291fac0?mod=rss_markets_main - FT World: https://www.ft.com/content/49f9f010-9ac9-4f6b-8b41-e8d959558785?syn-25a6b1a6=1 PITTSBURGH ---------------------------------------------------------------- Weather: Tonight: Mostly Cloudy then Areas Of Fog, low 60F. Wednesday: Areas Of Fog then Mostly Sunny, high 83F. Wednesday Night: Partly Cloudy, low 64F. Business: * County Council Moves to Ban Data Centers Latest developments: Several Allegheny County Council members introduced a bill August 25 to bar data centers from using county-owned buildings and property. The measure would block operators from siting data centers on Allegheny County land, mirroring a fight now dominating the Pennsylvania governor's race, where Governor Josh Shapiro and Treasurer Stacy Garrity trade attack ads as polls show more than 70% of residents oppose a data center nearby. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/environment/2026/08/25/allegheny-county-council-data-centers-ban/stories/202608250051 - TribLive: https://triblive.com/business/technology/some-allegheny-county-council-members-move-to-prohibit-data-center-related-usage-of-county-owned-property/ - KDKA: https://www.cbsnews.com/pittsburgh/news/pennsylvania-governors-race-data-centers/ * Kennywood Hidden-Fees Class Action Latest developments: A class-action lawsuit filed after a customer bought tickets in July accuses Kennywood, the West Mifflin amusement park, of adding hidden fees to online purchases, WPXI reported August 25. The suit targets what it calls undisclosed charges tacked onto Kennywood ticket sales, a practice federal regulators have moved to curb across the ticketing industry. - WPXI: https://www.wpxi.com/news/local/class-action-lawsuit-targets-alleged-hidden-fees-kennywood-tickets/FDLSY6QQDJGAXK4BATV7JMSNDE/ * PennDOT Hires Quarterhill for Truck Sensors Latest developments: PennDOT signed a $4.6 million agreement with Quarterhill, a Toronto technology company, to operate its network of road sensors that flag overweight commercial trucks, TribLive reported August 25. The sensors help PennDOT protect road surfaces and catch overloaded trucks across Pennsylvania highways. - TribLive: https://triblive.com/local/regional/penndot-partners-with-technology-company-to-track-overweight-commercial-vehicles/ Around town: * Pennsylvania Logs First Measles Deaths in 35 Years Latest developments: The Pennsylvania Department of Health announced August 25 that two unvaccinated people in Lancaster County died of measles, the state's first measles deaths since 1991, as Butler County confirmed its own first case. Governor Josh Shapiro and Health Secretary Debra Bogen said Pennsylvania has confirmed 393 measles cases across 29 counties this year; the Lancaster County deaths are the first U.S. measles deaths of 2026, and Pittsburgh doctors are urging MMR vaccination as local rates sit below the 95% herd-immunity threshold. - KDKA: https://www.cbsnews.com/pittsburgh/news/measles-outbreak-pennsylvania-lancaster-county-deaths-health/ - WTAE: https://www.wtae.com/article/butler-county-confirms-first-case-measles-outbreak/73525337 - KDKA: https://www.cbsnews.com/pittsburgh/news/measles-deaths-pennsylvania-vaccination/ * Pennsylvania Sues Snapchat Latest developments: Attorney General Dave Sunday sued Snapchat on August 25, alleging the app exposes children to harm. The Snapchat suit follows Sunday's lawsuit against TikTok two weeks earlier and Pennsylvania's role in a multistate case against Meta; Pew Research finds half of American teens use Snapchat every day. - KDKA: https://www.cbsnews.com/pittsburgh/news/pennsylvania-sues-snapchat-dave-sunday/ * Mold Forces Remote Start at Laurel Highlands Latest developments: Laurel Highlands Middle School will open its year with two weeks of remote learning while crews address mold and moisture inside the building, KDKA reported August 25. The Laurel Highlands School District's late reversal drew parent criticism over how long administrators knew about the mold before classes were set to begin. - KDKA: https://www.cbsnews.com/pittsburgh/news/laurel-highlands-middle-school-mold/ Events: * Pittsburgh Symphony Tours Europe Latest developments: The Pittsburgh Symphony Orchestra is touring Europe again as the only U.S. orchestra invited to the Salzburg Festival, the Post-Gazette reported August 25. The Salzburg Festival ranks as the world's premier classical-music festival, and the Pittsburgh Symphony's return keeps it the sole American orchestra on the bill. - Post-Gazette Arts & Entertainment: https://www.post-gazette.com/ae/music/2026/08/25/pittsburgh-symphony-european-tour-salzburg-festival/stories/202608250024 SPORTS ---------------------------------------------------------------- Around the Teams: * Ramsey Off PUP, Porter Contract Unsettled Latest developments: Cornerback Jalen Ramsey came off the physically-unable-to-perform list August 24 and returned to practice, while Joey Porter Jr.'s contract situation stayed unresolved. The Steelers welcomed Ramsey back to the secondary as they weigh a new deal for Porter Jr.; Gerry Dulac's August 25 chat fielded reader questions on both, plus Aaron Rodgers, coach Mike McCarthy, and general manager Omar Khan. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/08/24/nfl-injury-news-jalen-ramsey-max-iheanachor-joey-porter/stories/202608240030 - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/08/25/nfl-rumors-joey-porter-contract-ramsey-rodgers-mccarthy-khan/stories/202608250028 * Steelers Passing Game Needs Time Latest developments: The Post-Gazette wrote August 25 that quarterback Aaron Rodgers, receiver DK Metcalf, and receiver Michael Pittman Jr. need more reps together before the passing game clicks. The Steelers' new-look aerial attack has yet to sync in the preseason, and the beat expects the chemistry among Rodgers and his top targets to arrive gradually into the regular season. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/08/25/nfl-news-aaron-rodgers-dk-metcalf-michael-pittman/stories/202608250027 * Steelers Close Preseason Against Buffalo Latest developments: Matt Williamson and Wes Uhler gave their final roster predictions on the Steelers' SNR Drive August 25 ahead of Thursday's preseason finale against the Buffalo Bills. The team show broke down ESPN writer Bill Barnwell's pieces on which NFL teams look most likely to improve in 2026 as the Steelers set their 53-man roster. - Pittsburgh Steelers (YouTube): https://www.youtube.com/watch?v=OL8JJIdf1M4 READING ---------------------------------------------------------------- * Ed Zitron -- The AI Hater's Manifesto Zitron lays out a full case against the AI industry's hype, arguing the technology's boosters oversell capabilities while the economics of the leading labs stay shaky. https://www.wheresyoured.at/the-ai-haters-manifesto/ * Stratechery -- Netflix to Sell Streaming Services?, Streamers as Aggregators, Revisiting Roku Ben Thompson argues Netflix's reported plan to resell rival streaming services is a smart aggregation move, even as it marks a retreat from the company's original ambition to stand alone. https://stratechery.com/2026/netflix-to-sell-streaming-services-streamers-as-aggregators-revisiting-roku/ * Cal Newport -- Has AI Gone Rogue? Newport contends the real AI story of the summer is the shaky financial footing of the labs chasing record IPOs, cutting against the narrative of runaway machine autonomy. https://calnewport.com/has-ai-gone-rogue/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,673.63 ▼ -1.1% Dow 53,251.97 ▼ -0.9% Nasdaq 26,169.72 ▼ -1.8% WTI crude 86.13 ▲ +3.9% EUR/USD 1.1658 ▲ +0.9% GBP/USD 1.3614 ▲ +0.7% USD/JPY 158.95 ▼ -0.2% ================================================================ Generated 2026-08-25 19:35 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================