Attackers hammered the software that runs other people's machines and stores, chaining an unpatched Magento zero-day, a maximum-severity N-able hole, and backdoored ScreenConnect clients.
Emerging Trends and Key Updates
- Trend N-able shipped a fourth N-central hotfix in five weeks for CVE-2026-86218 while backdoored ScreenConnect consoles pushed scripted malware to every desktop that dialed in.
- Trend Pre-authentication holes keep landing with attackers, as StyleSmuggler plants Linux backdoors on Magento stores, CERT Polska's MikroTrick chain hijacks MikroTik routers, and Nightmare Eclipse drops unpatched Nvidia exploits.
- Trend Attackers now walk around multi-factor authentication, with BigBear vishing help desks to steal Microsoft 365 executive tokens and JSCeal replaying session cookies into Google accounts.
- Update · updated Brent pushed toward $100 as U.S.-Iran strikes and an Iranian exclusion zone near Hormuz drove the national gasoline average to a Labor Day record.
- Update · updated Friedrich Merz called himself shocked as Alternative for Germany finished three seats short of the majority it needs to lead Saxony-Anhalt.
- Update · new Pittsburgh's Labor Day parade pushed county paid parental leave, the North Huntingdon Walmart stayed shut after storm fire damage, and outfielder Kyler Fedko signed with the Pirates.
Security
1. ScreenConnect File Transfers Carry Malware
Latest developments: Huntress documented three unrelated intrusions in which backdoored ScreenConnect instances pushed a four-stage Visual Basic Script payload to every newly connected host, a worm-like spread that began with a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake update; ConnectWise separately published temporary mitigations for the underlying file transfer flaw, confirmed it hits both its cloud service and on-premises installations, and promised a CVE identifier and a fix within the week.
read more
ScreenConnect is the remote support and access tool that corporate IT departments and managed service providers use to take over user desktops, and the flaw abuses the file transfer built into live sessions. ConnectWise dated its advisory September 3, 2026; administrators should apply the interim mitigations now, audit connected clients, and update as soon as the patch ships.
Sources: BleepingComputer · Help Net Security · The Hacker News · SecurityWeek · ↑ top
2. N-able Ships Fourth N-central Hotfix in Five Weeks
Latest developments: N-able assigned the maximum-severity pre-authentication remote code execution flaw CVE-2026-86218 and released Hotfix 4 for N-central 2026.3 on September 5, 2026, its fourth hotfix for the platform in five weeks, and told every on-premises operator running a build below 2026.3.1.14 to install it, including anyone who applied Hotfix 3 a day earlier.
read more
N-central is the remote monitoring and management platform managed service providers use to administer customer machines, so one compromised server exposes every network beneath it. N-able's incident notice says attackers have exploited the flaw in the wild while its release notes call that unconfirmed; operators should patch immediately and hunt for intrusion.
Sources: The Hacker News · BleepingComputer · Help Net Security · ↑ top
3. MikroTik RouterOS Flaws Chained to Hijack Routers
Latest developments: CERT Polska, Poland's national computer security incident response team, disclosed six RouterOS vulnerabilities it coordinated with MikroTik and named the exploit chain MikroTrick, two bugs that together hand an attacker full control of any device with SSH reachable from the internet, and BleepingComputer confirmed attackers now fire the pair together.
read more
MikroTik patched the SSH authentication bypass late last week after exploitation had already started, and the SANS Internet Storm Center told administrators to assume compromise because attackers add new accounts to the devices to survive the update. Anyone running RouterOS with SSH exposed should patch, audit the user list, and rotate credentials.
Sources: BleepingComputer · Help Net Security · SANS Internet Storm Center · ↑ top
4. Mathspace, Berlin, and Trezor Report Fresh Data Theft
Latest developments: Mathspace, the online maths learning platform, disclosed over the weekend that attackers breached its Metabase internal reporting system and stole data on more than 1 million students, staff, and parents; Berlin's government said a second trove of stolen city data appeared online, with hackers publishing login credentials, while Germany's Federal Office for Information Security warned separately about the Rhysida cybercrime group; and Trezor put the total from the August breach at its fulfillment provider ShipMonk at 81,000 customers after adding 67,000 in the United States.
read more
All three disclosures grew from intrusions at systems that sit behind the primary product—an internal analytics tool, city agency accounts, and a third-party shipping vendor. Customers and residents should treat exposed names, addresses, and credentials as material for targeted phishing, and reset any password reused elsewhere.
Sources: BleepingComputer · The Record · BleepingComputer · ↑ top
5. Astra Reaches $20 Subscribers as OpenAI Automates Research
Latest developments: OpenAI began rolling ChatGPT Astra out to $20-a-month Plus subscribers with no date announced for free users, and separately said it hit the goal it set last fall of fielding an automated research intern by September 2026, a system that completes well-defined research tasks under human direction that would occupy a skilled researcher for several days.
read more
Astra is the first model OpenAI rates as crossing the critical cyber threshold under its Preparedness Framework; the company scored it at 100 percent on ExploitBench and made it refuse user requests for proof-of-concept exploits. OpenAI aims for a fully automated AI researcher by March 2028, and is testing a Writing Style feature that reads examples from a user's connected personal apps to imitate how they write.
Sources: BleepingComputer · Help Net Security · BleepingComputer · ↑ top
6. StyleSmuggler Zero-Day Plants Linux Backdoor on Magento Stores
Latest developments: Attackers exploiting StyleSmuggler now drop a stealthy Linux backdoor on the servers they reach, and researchers put the exposure at every version of Magento Open Source and Adobe Commerce.
read more
StyleSmuggler lets an attacker run code on an online store's server without logging in; Sansec, the Dutch e-commerce security firm, dated the first attacks to September 4, 2026, and no patch exists. Store operators should apply Sansec's mitigations, hunt for unfamiliar processes and files on the web server, and rotate admin and payment credentials.
Sources: BleepingComputer · SecurityWeek · ↑ top
7. Help Desk Vishing and BigBear Phish Microsoft 365 Executives
Latest developments: Threat hunters detailed a data theft and extortion cluster that calls corporate IT help desks, steals authentication tokens through adversary-in-the-middle pages, and signs in through residential proxies, singling out directors, vice presidents, and other executives on Microsoft 365 and other software-as-a-service platforms; BleepingComputer separately reported that the phishing-as-a-service framework BigBear 2.0 walked past multi-factor authentication at 258 organizations and collected more than 5,000 Microsoft 365 credentials.
read more
Both operations defeat multi-factor authentication by relaying the victim's own login session, so a stolen token works even when the password holds. Companies should require phishing-resistant FIDO2 keys for executives, tighten help desk identity verification before any password or MFA reset, and alert on sign-ins from residential proxy ranges.
Sources: The Hacker News · BleepingComputer · ↑ top
8. Nightmare Eclipse Drops CrowdStrike, Nvidia, and Avast Zero-Days
Latest developments: SecurityWeek reported that the researcher known as Nightmare Eclipse widened the release beyond the CrowdStrike Falcon Sensor bug published last week, dropping proof-of-concept exploits for unpatched privilege-escalation flaws in Nvidia and Avast software that each spawn a shell with SYSTEM privileges.
read more
Nightmare Eclipse, also called Chaotic Eclipse, has now hit four security and driver vendors in eight days, following the HardBreacher exploit that forced a Kaspersky patch on August 31, 2026, and the FalconFlank exploit against CrowdStrike's macro-remediation routine. Endpoint software runs with the highest privileges on a machine, so defenders should watch vendor advisories for fixes and monitor for local escalation attempts.
Sources: SecurityWeek · ↑ top
9. North Korean Crews Backdoor HAProxy in South Korea
Latest developments: SecurityWeek tied the previously undocumented Linux toolkit that hides inside trojanized HAProxy load balancers to North Korean hackers, and named automotive and media organizations in South Korea as the targets of the long-term surveillance operation.
read more
The toolkit, whose own debug strings call it ted, compiles a backdoor directly into the HAProxy binary, so the load balancer that fronts a web application also intercepts its traffic and serves altered pages to chosen visitors. Anyone running HAProxy in the region should verify binary integrity against vendor builds and review outbound connections from load balancers.
Sources: SecurityWeek · ↑ top
10. JSCeal Steals Session Cookies to Walk Past Google Logins
Latest developments: Check Point Research published a teardown of JSCeal, malware compiled to V8 JavaScript bytecode that harvests credentials, watches the user, intercepts traffic, and replays stolen session cookies to enter Google accounts without triggering authentication.
read more
JSCeal's operators wrap the payloads in javascript-obfuscator, protecting strings with RC4 and flattening control flow through proxy functions and operation wrappers to frustrate analysis. Defenders should treat stolen browser session cookies as a credential and shorten session lifetimes on Google accounts.
Sources: The Hacker News · ↑ top
Business and Politics
Brent Tops $97 as the U.S. and Iran Trade Strikes
Latest developments: Brent marched toward $100 a barrel through Monday, September 7, with traders warning that "something has to break" as attacks on shipping drain inventories, the U.S. national average pump price set a Labor Day record, and the Wall Street Journal reported that the American blockade has choked off Tehran's oil earnings and deepened its economic crisis.
read more
The war continues to choke traffic through the Strait of Hormuz: new strikes hit Saudi Aramco facilities at Jizan near the Yemeni border, European natural gas climbed more than 2% to just under 74 euros a megawatt-hour with Qatari supply flows severely disrupted, eurozone government bond yields opened higher ahead of the European Central Bank's rate decision Thursday, September 10, and Tehran announced it will raise petrol prices because war-driven shortages have made its fuel subsidies, among the cheapest in the world, unsustainable.
Sources: FT Home · WSJ Markets · WSJ World News · FT Home · FT Home · WSJ US Business · ↑ top
Germany Weighs Letting the AfD Govern
Latest developments: Chancellor Friedrich Merz described himself as shocked Monday, September 7, and now walks a narrow path to hold his federal government together, with Alternative for Germany three seats short of the majority it needs to lead Saxony-Anhalt and its co-leader Alice Weidel calling the result a dream and setting a target of 40% in the next federal election.
read more
The AfD finished well ahead of every rival in the September 6 Saxony-Anhalt election, the best showing in the party's history, and landed short of a majority in the state parliament, leaving Merz and the mainstream parties to choose between an awkward coalition of opponents and the first far-right state government in Germany since World War II; the result reopens the argument over the firewall that has kept the party out of power.
Sources: FT Home · WSJ World News · FT Home · WSJ World News · The Economist · ↑ top
Yen Hits a Six-Month High
Latest developments: The yen touched 154.04 per dollar Monday, September 7, its strongest intraday level since late February, with the steepest part of the climb landing in the London morning as traders watched for signs of Japanese intervention.
read more
The currency has recovered for a week as rate expectations shift, with markets pricing a Bank of Japan increase and, after last week's U.S. payrolls surprise, a Federal Reserve increase at the September 16 meeting; the same rate bets pushed German Bund yields higher and left gold under pressure before Thursday's producer price report and Friday's consumer price data, while copper hit a record on the London Metal Exchange on mine supply worries and the prospect of U.S. tariffs.
Sources: FT World · WSJ Markets · WSJ Markets · WSJ Markets · WSJ Markets · ↑ top
Beijing Recapitalizes Banks and Insurers
Latest developments: Beijing said Monday, September 7, that it will inject $54 billion of fresh capital into state-controlled banks and insurers, widening the program to more institutions than the first round covered.
read more
The infusion is China's second recapitalization of its financial system in less than two years and lands as growth momentum sputters; separately, China's foreign-exchange reserves edged higher in August on a weaker dollar and a surging trade surplus, renewing concern about the yuan's appreciation.
Sources: FT World · WSJ World News · WSJ World News · ↑ top
Pittsburgh
Weather
Labor Day: Sunny, high 80F.
Tonight: Partly Cloudy, low 59F.
Tuesday: Mostly Sunny, high 86F.
Business
North Huntingdon Walmart Stays Closed
Latest developments: The Walmart in North Huntingdon remained closed Monday morning, September 7, TribLive reported, as crews assessed and cleared damage from a smoldering fire that broke out after last week's severe storms.
read more
The store sits in North Huntingdon, Westmoreland County, one of the communities the storms of late last week battered across Western Pennsylvania, and the fire that followed has kept one of the township's largest retailers shut through the holiday weekend.
Gasoline Sets a Labor Day Record
Latest developments: Iran announced a plan to create an exclusion zone around the Strait of Hormuz, WTAE reported Monday, September 7, as the national average price of regular gasoline reached an all-time Labor Day high for the holiday, three days after retail diesel set its own record at $5.85 a gallon.
read more
The war with Iran and refinery problems drive the increase, which lands on the last big driving weekend of the summer; WPXI and WTAE note the average for regular gasoline still sits below the all-time record of $5.02 a gallon set in June 2022.
Sources: WPXI · WTAE · WTAE · ↑ top
East Ohio Street Booms in Deutschtown
Latest developments: The Post-Gazette reported Monday, September 7, that investment along East Ohio Street has the corridor changing fast, four days after KDKA covered the campaign by Pittsburgh leaders to revive the district.
read more
East Ohio Street is the commercial spine of Deutschtown on Pittsburgh's North Side, where longtime merchants asked the city for help and now watch new businesses arrive; residents and owners told the Post-Gazette they want the growth to lift everyone already there rather than price them out.
Sources: Pittsburgh Post-Gazette · ↑ top
Around Town
Labor Day Parade Pushes Paid Parental Leave
Latest developments: Steelworkers, firefighters, police officers, and carpenters marched through downtown Pittsburgh on Monday, September 7, for the annual Labor Day parade, where the group Worker Speak Out pressed Allegheny County Council to pass a proposed paid parental leave measure for county employees.
read more
Thousands lined the downtown route for the region's largest annual show of union strength, and the parental leave bill now before Allegheny County Council gave this year's march a specific legislative ask.
Fetterman Texts Show Refusals of Constituent Work
Latest developments: KDKA reported Monday, September 7, that newly released text messages show U.S. Senator John Fetterman dismissing and at times refusing core constituent-service duties, a day after Fetterman told CNN that his curt text to Children's Hospital of Philadelphia leaders was a dumb joke.
read more
A former staffer confirmed the pattern to KDKA. The Pennsylvania Democrat's messages surfaced through Wall Street Journal reporting on his rejection of Children's Hospital of Philadelphia leaders' concerns about Medicaid cuts, coverage Fetterman has called a hit piece.
Street Cameras Start Talking to AI
Latest developments: The Post-Gazette reported Monday, September 7, that the automatic license plate readers posted along Pennsylvania streets increasingly feed artificial-intelligence systems, five days after Governor Josh Shapiro and state Treasurer Stacy Garrity called for a statewide ban on Flock cameras.
read more
Police departments across Pennsylvania query camera networks that photograph every passing plate and log vehicle movements into searchable national databases, a practice that has drawn privacy objections in Harrisburg and from communities around Pittsburgh.
Sources: Pittsburgh Post-Gazette · ↑ top
Blawnox Dresses Up Freeport Road
Latest developments: Blawnox officials are moving ahead with a beautification project for the borough's business district, TribLive reported Monday, September 7.
read more
The plan adds benches, tables, trash cans, and new signage along Freeport Road, the commercial strip that carries traffic through the small Allegheny River borough northeast of Pittsburgh.
Sharpsburg Appoints Andrascik to Council
Latest developments: Sharpsburg council appointed borough resident Jon Andrascik as a councilman, TribLive reported Monday, September 7.
read more
Andrascik served on the Sharpsburg parks and recreation commission for a little more than a year and has coached Fox Chapel Area youth soccer and basketball for more than a decade.
Events
Public Image Ltd Returns to Pittsburgh
Latest developments: TribLive reported Monday, September 7, that Public Image Ltd will play Pittsburgh this fall.
read more
Public Image Ltd, the band John Lydon formed after the Sex Pistols, has booked a Pittsburgh stop on its first extensive North American tour in eight years.
'Dear Evan Hansen' Comes to the Lamp Theatre
Latest developments: TribLive reported Monday, September 7, that Split Stage Productions will stage the musical this month in Irwin.
read more
Split Stage Productions brings the Tony Award-winning show to the Lamp Theatre on Main Street in Irwin, Westmoreland County, a year after Music Theatre International released 'Dear Evan Hansen' for licensing to regional and community companies.
Rib Fest Runs Through Labor Day
Latest developments: Judges crowned new barbecue champions over the weekend, with one fan favorite extending its winning streak, and the festival keeps serving through Labor Day, Monday, September 7, TribLive reported.
read more
The Acrisure Stadium Kickoff and Rib Festival sets up at Acrisure Stadium on Pittsburgh's North Shore, where competing rib vendors cook for prizes and for the crowd ahead of the Steelers' home opener against the Atlanta Falcons on Sunday, September 13.
Sports
Pirates (71-73)
Sun Sep 6 · Angels 0 · Pirates 1 · Final
Up Next · Pirates @ White Sox · Tue Sep 8, 7:40 PM
Steelers (0-0, T-1st in AFC North)
Up Next · Falcons @ Steelers · Sun Sep 13, 1:00 PM
Around the Teams
Fedko Signs With His Hometown Pirates
Latest developments: The Post-Gazette's MiLB Monday column on September 7 quoted outfielder Kyler Fedko describing himself as on cloud nine after signing his minor league deal with the Pirates, four days after the club agreed to terms.
read more
Fedko, the son of former Pittsburgh sportscaster John Fedko, grew up in the region and joins the Pirates' farm system; the same column tracked pitching prospects Murf Sanford and Antwone Kelly.
Sources: Post-Gazette Pirates · ↑ top
The Numbers Behind the Pirates' Fading Push
Latest developments: The Post-Gazette's Off The Bat column laid out Monday, September 7, the statistics that explain why a late-season Pirates surge remains unlikely.
read more
The column builds its case around starting pitcher Paul Skenes, Marcell Ozuna, and Oneil Cruz as the Pirates play out September at PNC Park with their postseason odds shrinking.
Sources: Post-Gazette Pirates · ↑ top
Steelers and the Tight End Arms Race
Latest developments: The Post-Gazette wrote Monday, September 7, that head coach Mike McCarthy can put the Steelers one step ahead of the NFL's rush to stockpile tight ends by building the offense around two-tight-end personnel.
read more
Pittsburgh opens the season against the Atlanta Falcons on Sunday, September 13, at Acrisure Stadium with Pat Freiermuth heading the tight end room; the Post-Gazette argues McCarthy's 12 personnel packages give quarterback Aaron Rodgers a way to dictate matchups as the rest of the league chases the same idea.
Sources: Post-Gazette Steelers · ↑ top
Team USA
Pochettino on Balogun and the Teenagers
Latest developments: United States men's coach Mauricio Pochettino said Monday, September 7, that he has yet to speak with striker Folarin Balogun about the collapsed transfer to Everton and plans to call in the coming days to offer support, and he urged caution about the buzz around Philadelphia Union midfielder Cavan Sullivan and New York Red Bulls forward Julian Hall.
read more
Balogun stayed at AS Monaco after his deadline-day move to Everton fell apart, and Pochettino wants him in a place where he can perform; Sullivan, 16, has scored in three straight Major League Soccer matches, and Pochettino says the U.S. pool's young talent needs careful handling ahead of national team camp.
Sources: ESPN Soccer · ESPN Soccer · ↑ top
Belgium Balks at Infantino Over the Balogun Ruling
Latest developments: The Belgian football federation said Monday, September 7, that it cannot support Gianni Infantino's bid for another term as FIFA president.
read more
The federation cited transparency and governance concerns along with FIFA's handling of its decision to clear United States forward Folarin Balogun of a mandatory one-game ban at the 2026 World Cup, a call that drew objections from rival national federations.
Sources: ESPN Soccer · ↑ top
Reading
- Cal Newport — Wendell Berry and the Promise of the Deep Life. Newport marks the death of Wendell Berry at 92 at his home in Port Royal, Kentucky, where Berry farmed with traditional methods and wrote, and reads that life of place, slow work, and attention as the fullest case for what Newport calls the deep life.
- Stratechery — An Interview with OpenAI President Greg Brockman About Astra and Alignment. Ben Thompson interviews OpenAI co-founder and President Greg Brockman on the company's history, its Astra model, its approach to alignment, and the weight Brockman feels in building the technology.
- Ed Zitron — Premium: The Hater's Guide To Circular Financing (Part Two). Zitron traces the loops in AI financing—Nvidia funds OpenAI, which spends the money renting Nvidia GPUs back from Microsoft, Google, and Amazon—and argues the clunky agreements manufacture the appearance of demand that props up the boom.
Markets
S&P 500 7,690.10 = +0.0% Dow 53,223.02 ▼ -0.6% Nasdaq 26,355.91 ▲ +0.4% WTI crude 89.95 ▲ +8.0% EUR/USD 1.1603 ▼ -0.5% GBP/USD 1.3524 ▼ -0.8% USD/JPY 158.93 ▼ -0.2%
Feed Health
Security: 24 of 24 feeds loaded, 34 items in the 24-hour window. No recent items: Krebs on Security, Dark Reading, CISA Advisories, Ars Technica Security, Securelist (Kaspersky), Unit 42 (Palo Alto), Google Online Security Blog, Cisco Talos, Microsoft Security Blog, Google Project Zero, The DFIR Report, Kim Zetter (Zero Day), Frank on Fraud, Wired Security.
Pittsburgh: 9 of 9 feeds loaded, 60 items in the 48-hour window. No recent items: PublicSource, Pittsburgh City Paper, NEXTpittsburgh, Pittsburgh Magazine.
Business and Politics: 8 of 8 feeds loaded, 60 items in the 36-hour window.
Events: 4 of 4 feeds loaded, 8 items in the 120-hour window. No recent items: NEXTpittsburgh Events, NEXTpittsburgh Arts & Entertainment.
Sports media: 6 of 6 feeds loaded, 27 items in the 96-hour window. No recent items: Footbahlin with Ben Roethlisberger, Ben Roethlisberger / Channel Seven (YouTube).
Team USA: 3 of 3 feeds loaded, 29 items in the 72-hour window.
Reading: 3 of 3 feeds loaded, 12 items in the 336-hour window.
Markets (Yahoo Finance): 7 of 7 rows
Weather (NWS): 3 forecast periods
Scores (ESPN, plaintextsports): 2 teams via plaintextsports; mlb: ESPN failed (mlb: HTTP 403 (server: AkamaiGHost)); used plaintextsports; nfl: ESPN failed (nfl: HTTP 403 (server: AkamaiGHost)); used plaintextsports; nhl: ESPN failed (nhl: HTTP 403 (server: AkamaiGHost)); used plaintextsports
Summaries: 3 model call(s) served by claude-opus-5 (272s of model time; $1.68 at API list price).