================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Saturday, June 13, 2026 ================================================================ Washington forced Anthropic to pull its most capable AI models worldwide as an Oracle PeopleSoft zero-day let ShinyHunters drain gigabytes from hundreds of organizations. CONTENTS: Emerging Trends | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS ---------------------------------------------------------------- * AI Weaponization: Attackers wired Gemini into phishing kits and turned AI coding agents into code-execution vectors, while Washington pulled frontier models offline over national-security fears. * Supply Chain: Hijacked Arch packages, npm's script-execution overhaul, and dark-web access sales all point to the software pipeline as the soft underbelly defenders keep missing. * Coordinated Takedowns: Europol, INTERPOL, and US prosecutors struck the laundering services, phishing platforms, and operators that bankroll ransomware inside a single 48-hour window. * Dormant Flaws: A decade-old Velvet Ant login backdoor, a ten-year phpBB auth bypass, and freshly weaponized edge-device bugs show old access paths still swing doors open. SECURITY ---------------------------------------------------------------- :: AI SECURITY 1. WASHINGTON ORDERS ANTHROPIC TO PULL FABLE 5 AND MYTHOS 5 [ai, policy, zero-day] Last 24h: Anthropic took Fable 5 and Mythos 5 offline worldwide on June 13 after the Trump administration ordered it to block all foreign nationals. The order arrived at 5:21 p.m. ET and demanded Anthropic cut access for foreign nationals inside and outside the United States, citing national security. Anthropic complied yet disputes the rationale, calling the cited jailbreak narrow and the underlying capability common across rival models. The suspension knocks the company's flagship models out of service globally and signals that export controls now reach frontier AI the way they reach advanced chips. A researcher's jailbreak claim, which Anthropic rejects as inauthentic, framed the security debate around the launch. - BleepingComputer: https://www.bleepingcomputer.com/news/security/us-gov-asks-anthropic-to-ban-foreign-national-access-to-fable-mythos/ - The Hacker News: https://thehackernews.com/2026/06/us-orders-anthropic-to-suspend-fable-5.html - SecurityWeek: https://www.securityweek.com/anthropic-says-it-has-taken-its-latest-ai-models-offline-to-comply-with-new-export-controls/ - SecurityWeek: https://www.securityweek.com/anthropic-disputes-fable-5-ai-jailbreak/ 2. AI AGENTS BECOME BOTH WEAPON AND TARGET [ai, phishing, exploit] Last 24h: Google sued the China-based Outsider network for weaponizing Gemini in smishing, and researchers disclosed the Agentjacking attack and a LangGraph RCE chain. Google's suit accuses Outsider Enterprise of using Gemini to build phishing sites and run a phishing-as-a-service kit that hit hundreds of thousands of victims across more than 9,000 fake sites. Tenet Security's Agentjacking tricks AI coding agents into running arbitrary code through a booby-trapped Sentry error report. A separate LangGraph vulnerability chain, which includes SQL injection, exposes self-hosted AI agents to remote code execution. Together the items mark AI agents as both attacker tooling and a fresh attack surface. - The Hacker News: https://thehackernews.com/2026/06/google-sues-chinese-smishing-network.html - The Hacker News: https://thehackernews.com/2026/06/agentjacking-attack-tricks-ai-coding.html - The Hacker News: https://thehackernews.com/2026/06/langgraph-flaw-chain-exposes-self.html :: VULNERABILITIES AND EXPLOITS 3. SHINYHUNTERS LOOTS PEOPLESOFT VIA ORACLE ZERO-DAY [zero-day, exploit, breach] Last 24h: Google confirmed ShinyHunters exploited the flaw, and CISA added CVE-2026-35273 to its known exploited catalog on June 12. The bug, a missing-authentication flaw in Oracle PeopleSoft Enterprise PeopleTools, lets unauthenticated attackers reach critical functions and pull gigabytes of records. ShinyHunters hit hundreds of organizations and leaned hard on American universities running the ERP system. Oracle has mitigated CVE-2026-35273 yet has not publicly confirmed in-the-wild exploitation. Federal agencies now face a patch deadline under CISA's directive. - SecurityWeek: https://www.securityweek.com/google-confirms-exploitation-of-oracle-peoplesoft-zero-day-by-shinyhunters/ - Ars Technica Security: https://arstechnica.com/security/2026/06/peoplesoft-0-day-affecting-hundreds-of-organizations-steals-gigabytes-of-data/ - CISA Advisories: https://www.cisa.gov/news-events/alerts/2026/06/12/cisa-adds-one-known-exploited-vulnerability-catalog - Dark Reading: https://www.darkreading.com/vulnerabilities-threats/shinyhunters-oracle-zero-day-higher-ed 4. EDGE VPNS AND ENTERPRISE SOFTWARE UNDER ACTIVE ATTACK [patch, exploit, vpn] Last 24h: CISA gave agencies three days to patch an exploited Ivanti Sentry flaw, and researchers published a proof-of-concept for an exploited Check Point VPN bug. Ivanti Sentry carries a critical OS command injection flaw that grants root-level code execution, and honeypots already show exploitation attempts; CISA's new Binding Operational Directive 26-04 sets a Sunday deadline. Check Point patched CVE-2026-50751, an authentication bypass in its Remote Access and Mobile Access VPN, on June 8 after limited attacks, and WatchTowr's public analysis now invites opportunistic waves. Splunk separately patched CVE-2026-20253, a 9.8-severity flaw that lets unauthenticated users run code on Splunk Enterprise. Anyone running the three should patch immediately. - BleepingComputer: https://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/ - SecurityWeek: https://www.securityweek.com/ivanti-sentry-exploitation-attempts-hitting-honeypots/ - Help Net Security: https://www.helpnetsecurity.com/2026/06/12/cve-2026-50751-poc-exploit/ - The Hacker News: https://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html 5. 400 ARCH LINUX PACKAGES HIJACKED TO PLANT ROOTKIT [supply-chain, malware] Last 24h: Attackers hijacked more than 400 Arch User Repository packages to ship an infostealer and an eBPF rootkit. The rewritten AUR build scripts install a Rust credential stealer on any machine that compiles them, and with root the malware loads an eBPF rootkit to hide. The harvested loot includes developer secrets and access tokens. Npm answered the broader threat by announcing that npm 12 will stop running dependency install scripts by default. Developers who built affected AUR packages should rotate every secret on those machines. - The Hacker News: https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/over-400-arch-linux-packages-compromised-to-push-rootkit-infostealer/ - SecurityWeek: https://www.securityweek.com/npm-12-will-change-script-execution-behavior-to-prevent-supply-chain-attacks/ :: NATION-STATE ACTIVITY 6. VELVET ANT HID IN LINUX LOGIN SOFTWARE FOR A DECADE [apt, espionage] Last 24h: Sygnia detailed how the China-nexus group Velvet Ant backdoored Linux login components to lurk for nearly ten years. Velvet Ant seized a target's authentication stack, planting backdoors in the PAM and OpenSSH components that decide who signs in, and watched administrative activity for close to a decade. The implants sat below the laptops and servers defenders monitor most closely, surviving routine cleanup on an isolated network. The campaign shows how patient espionage groups embed themselves in the plumbing of identity itself. Organizations should audit login binaries and authentication modules for tampering. - BleepingComputer: https://www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade/ - The Hacker News: https://thehackernews.com/2026/06/china-linked-hackers-backdoored-linux.html :: RANSOMWARE AND CYBERCRIME 7. POLICE STRIKE CRYPTO LAUNDERING, PHISHING, AND CONTI [ransomware, phishing] Last 24h: Europol dismantled the AudiA6 laundering service, a Conti operator pleaded guilty, and INTERPOL took down the Sniper Dz phishing platform. AudiA6 washed more than €336 million for ransomware gangs between 2022 and 2025 before investigators seized it. A Ukrainian national extradited from Ireland admitted conspiracy charges tied to Conti, one of the most prolific ransomware crews. INTERPOL's Operation Ramz disrupted the decade-old Sniper Dz phishing-as-a-service platform and drove 201 arrests across 13 countries in the Middle East and North Africa. The sweep squeezes the financial and tooling layers that sustain cybercrime. - Help Net Security: https://www.helpnetsecurity.com/2026/06/12/europol-audia6-crypto-laundering-service-ransomware-groups/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/ukrainian-national-pleads-guilty-to-role-in-conti-ransomware-operation/ - The Hacker News: https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html :: DATA BREACHES 8. RECORD FINES AND FRESH BREACHES MOUNT [breach, policy] Last 24h: South Korea fined Coupang a record $409 million, a court approved a $47 million 23andMe settlement, and Novo Nordisk disclosed a clinical-trials breach. Coupang's penalty, the largest the Korean commission has ever issued, eclipses the $88.8 million SK Telecom fine from earlier in 2026. The 23andMe fund compensates roughly 7 million customers whose genetic data thieves stole starting in April 2023 and posted to the dark web. Novo Nordisk, the world's largest insulin maker, said attackers took patient information from some clinical trials, and France confirmed a Tchap messenger breach exposing 73,000 public-sector accounts. Regulators and courts keep raising the price of losing personal data. - The Record: https://therecord.media/south-korea-data-breach-record-fine-coupang - The Record: https://therecord.media/bankruptcy-admin-approves-settlement-for-23andme-breach-victims - BleepingComputer: https://www.bleepingcomputer.com/news/security/pharmaceutical-giant-novo-nordisk-discloses-security-breach/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/french-govt-says-tchap-breach-affected-over-73-000-accounts/ BUSINESS AND POLITICS ---------------------------------------------------------------- * Trump said the United States and Iran will sign an agreement Sunday to reopen the Strait of Hormuz, ending a war that swung from a helicopter-crash escalation back to a ceasefire. Pakistan, a mediator, called a deal closer than ever, though Tehran's Revolutionary Guard controls the harder phase ahead—talks over the nuclear program. - Financial Times: https://www.ft.com/content/726f4afe-c3ff-4ec0-bfc9-b572b419e11f - Wall Street Journal: https://www.wsj.com/world/middle-east/trumps-iran-deal-still-has-to-get-past-the-revolutionary-guard-c13ea381 * SpaceX raised $75 billion and debuted at a $2.1 trillion valuation, the largest initial public offering in history; shares climbed 19% and Elon Musk became the world's first trillionaire. Financial stocks carried the Dow up 0.7%. - Wall Street Journal: https://www.wsj.com/business/spacex-now-worth-2-1-trillion-pulls-off-goldilocks-debut-bcc59ace?mod=rss_markets_main - Financial Times: https://www.ft.com/content/16387550-4d13-4d2d-b487-c4f6f4a5e9c8 * US headline annual inflation reached 4.2%, the highest since April 2023, sharpening the Federal Reserve's dilemma over a wait-and-see policy that some economists warn echoes 2008. - Financial Times: https://www.ft.com/content/20509c5d-e995-4670-83f5-d3d705671ee1 - Financial Times: https://www.ft.com/content/01c5ea35-a0fa-469f-b8bb-356d98c05fb0 PITTSBURGH ---------------------------------------------------------------- Weather: Tonight: Partly Cloudy, low 64F. Sunday: Showers And Thunderstorms, high 81F. Sunday Night: Showers And Thunderstorms then Mostly Cloudy, low 55F. Business: * A Pittsburgh restaurant that fire gutted more than two years ago will sell its building, having never managed to reopen. - WPXI: https://www.wpxi.com/news/local/pittsburgh-restaurant-destroyed-by-fire-sell-its-building-after-being-unable-reopen/QAWE4U7CCZBSBPO4LHQBLARBAM/ * The 12th annual Beers of the Burgh festival drew a few thousand people to the Carrie Blast Furnaces on Saturday to sample dozens of regional breweries, wineries, and cideries, a showcase of Western Pennsylvania's craft-beverage industry. - KDKA: https://www.cbsnews.com/pittsburgh/news/beers-of-the-burgh-festival-carrie-blast-furnaces/ Around town: * Pennsylvania American Water lifted a boil-water advisory that had covered about 1,500 customers in Clairton for nearly a week. - WTAE: https://www.wtae.com/article/boil-water-advisory-customers-clairton-pa-american-water/71516396 * Volunteers planted gardens along Mount Washington's famous Grandview promenade, reclaiming beds that weeds had overrun for decades. - Pittsburgh Post-Gazette: https://www.post-gazette.com/local/city/2026/06/13/after-decades-of-weeds-volunteers-plant-gardens-along-mount-washington-s-famous/stories/202606130033 * A water-main break crumbled a road in Forest Hills, forcing its closure Saturday. - WPXI: https://www.wpxi.com/news/local/crumbling-road-closed-after-water-main-break-forest-hills/XEBP2OBCZRD3XED2BQ4HDSAN2I/ * The Kittanning Firemen's Band played outside the Armstrong County Courthouse on Saturday, a send-off three weeks before it represents Pennsylvania in the National Independence Day Parade in Washington. - TribLive: https://triblive.com/local/valley-news-dispatch/kittanning-firemens-band-receives-hometown-send-off-before-representing-pennsylvania-in-national-independence-day-parade/ Events: * The Yough River Rally continues Sunday along the Youghiogheny River with family entertainment, following Saturday's "Yough River Rat" mullet contest. - TribLive: https://triblive.com/local/westmoreland/yough-river-rally-continues-sunday-with-more-family-entertainment/ * The Ligonier Valley Farmers Market opened its season, with regional growers such as Sand Hill Berries of Mt. Pleasant returning for the summer. - TribLive: https://triblive.com/local/westmoreland/ligonier-valley-farmers-market-holds-1st-event-of-the-season/ SPORTS ---------------------------------------------------------------- Pirates (36-35) Fri Jun 12 · Marlins 8 · Pirates 3 · Final Marlins beat the Pirates 8-3 for their 6th straight victory https://plaintextsports.com/mlb/2026-06-12/mia-pit Sat Jun 13 · Marlins 2 · Pirates 3 · Final Spencer Horwitz hit by pitch with the bases loaded to lift the Pirates past the Marlins, 3-2 https://plaintextsports.com/mlb/2026-06-13/mia-pit Up Next · Marlins @ Pirates · Sun Jun 14, 12:15 PM https://plaintextsports.com/mlb/2026-06-14/mia-pit Headlines: · Marlins try to extend road win streak in matchup against the Pirates · 2026 MLB ABS challenge system tracker: Team, player rankings READING ---------------------------------------------------------------- * Ed Zitron -- Premium: The Silicon Valley Bubble (Part 1) Zitron argues the AI era is ending as OpenAI and Anthropic file to go public, racing for exit liquidity despite burning billions a year with no path to profitability. https://www.wheresyoured.at/premium-the-silicon-valley-bubble-part-1/ * Stratechery -- Fable 5, Anthropic Alignment, AI Tiers Thompson holds that Fable 5, the public version of Mythos, is highly capable yet sets troubling precedents around model alignment and tiered AI access. https://stratechery.com/2026/fable-5-anthropic-alignment-ai-tiers/ * Cal Newport -- Why Isn’t AI Taking Our Jobs? Newport questions the AI-as-industrial-automation comparison, examining why the predicted wave of job losses has yet to materialize. https://calnewport.com/why-isnt-ai-taking-our-jobs/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,377.03 ▼ -2.2% Dow 50,725.58 ▼ -0.7% Nasdaq 25,695.30 ▼ -3.8% WTI crude 88.42 ▼ -5.0% EUR/USD 1.1550 ▼ -0.4% GBP/USD 1.3378 ▼ -0.3% USD/JPY 160.28 ▲ +0.2% ================================================================ Generated 2026-06-13 21:02 EDT. Sources: 18 security feeds; 9 Pittsburgh feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================