The attack the article is describing can be used to infect USB devices that are plugged in to a compromised machine. They do not require a malicious actor to provide a compromised USB device. The attacks you describe involve altering, physically, a peripheral in order to perform the compromise. That has been possible as long as computer peripherals have existed.
Can you re-write a USB thumb drive's firmware, over USB? the only reference to that I saw in the article was that it can "spread from USB to PC and back" which is kind of vague. Is there a specific vulnerability on a specific chipset that is exploited?
I understand the point that USB drives are more, well, promiscuous than other bus hardware, but saying "A thumbdrive with modified firmware can affect a computer it is plugged in to" and equating that with "USB security is fundamentally broken" seems like a bit of a reach. i.e. there is no specific provision in the USB protocol for re-flashing device/USB stack firmware. I think "Certain USB thumbdrive chipsets are vulnerable to a specific exploit that allows the USB host to modify the thumb drive's firmware" is a much more accurate headline, given the content of the article. Right now it is no different than saying "I got a virus over email, therefore Ethernet is fundamentally broken"
> However, the one thing that is unique to USB is the nature in which USB storage devices are shared between multiple devices.
That was half of my point. I was not underestimating the vulnerability of SATA and other on-board communications protocols. I was ignoring them because the parts connected to these are generally not moved between machines. Yes, you could infect these devices and hope they spread through the secondary market to a desirable target, but the utility of such an attack is very limited.