infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

Russian intelligence escalated its assault on encrypted messaging by coaxing targets into surrendering Signal backup keys, while attackers weaponized a Cisco Unified CM flaw within a day of disclosure.


Emerging Trends and Key Updates

Security

1. Russian Spies Hunt Signal Backup Keys

Nation-State Activity · [apt, phishing, nation-state]

Latest developments: The FBI and CISA updated their March 2026 warning on June 26, revealing that Russian Intelligence Services operators now talk targets into surrendering their Signal Backup Recovery Key, which lets the attacker restore the account's backup, read its private and group history, and keep persistent access.

read more

Russian intelligence runs phishing campaigns against Signal and other commercial messaging apps; Ukraine's SBU traced a parallel long-running operation in which fake tech-support workers extracted messaging credentials. Treat unsolicited device-linking or backup-key requests as hostile.

Sources: The Hacker News · CISA Advisories · The Record · ↑ top

2. Open-Source Supply Chain: Miasma Spreads as Akrites Launches

Software Supply Chain · [supply-chain, npm, open-source]

Latest developments: The Miasma worm, part of the Mini Shai-Hulud and Hades family, infected fresh npm releases of LeoPlatform and RStreams, abused GitHub Actions workflows, and crossed into the Go ecosystem, while the Linux Foundation launched Akrites, an industry framework uniting tech firms, banks, and AI companies to report, patch, and disclose open-source vulnerabilities as AI compresses the time from discovery to exploitation.

read more

Self-propagating malware keeps poisoning the package registries that feed enterprise builds, and a new coordinated-disclosure framework aims to speed remediation. Pin dependencies and audit CI/CD tokens.

Sources: The Hacker News · Help Net Security · SecurityWeek · ↑ top

3. AI Agents Become an Identity Battleground

AI Security · [ai, identity, phishing]

Latest developments: Threat actors began creating OpenAI tenants that impersonate real companies and inviting employees to join, harvesting sensitive data through chats and projects, while Cisco acquired Astrix and WideField to secure non-human identities and Proof launched x401, an open protocol that verifies the identity behind AI agents before a service acts.

read more

AI agents and machine identities now operate with human-level access and little oversight, drawing both attackers and a wave of governance tooling. Inventory non-human identities and scrutinize unexpected platform invitations.

Sources: BleepingComputer · Dark Reading · Help Net Security · ↑ top

4. Cisco Unified CM Flaw Draws CISA Deadline

Vulnerabilities and Exploits · [cisco, exploit, patch]

Latest developments: CISA ordered federal civilian agencies to patch Cisco Unified Communications Manager flaw CVE-2026-20230 by Sunday, June 28, after attackers weaponized the server-side request forgery bug within 24 hours of disclosure to forge root-level access.

read more

CVE-2026-20230 lets unauthenticated attackers reach internal services and escalate to root on Cisco Unified CM and Unified CM Session Management Edition deployments. Patch internet-facing systems immediately.

Sources: BleepingComputer · Dark Reading · ↑ top

5. DirtyClone Joins Linux Kernel Root Exploits

Vulnerabilities and Exploits · [linux, privilege-escalation, exploit]

Latest developments: JFrog Security Research published the first working exploit for DirtyClone, CVE-2026-43503, on June 25—a DirtyFrag-family kernel bug rated CVSS 8.8 that corrupts file-backed memory through a cloned network packet—landing days after a public exploit for pedit COW, CVE-2026-46331, gave local users root the same way.

read more

Both flaws let an unprivileged local user gain root on Linux by poisoning shared page-cache memory through crafted packets. Apply kernel updates; Red Hat rates pedit COW high severity.

Sources: The Hacker News · The Hacker News · ↑ top

6. Surveillance Tools Reach Police, Military, and Officials' Data

Privacy and Surveillance · [surveillance, privacy, policy]

Latest developments: Meta began prototyping real-time facial recognition with a Pentagon supplier for police and military use, and the Pentagon opened an inquiry into the Dialog data exposure after leaked records unmasked a senior White House intelligence official and an active-duty special operations officer.

read more

Government-linked surveillance prototypes and data-exposure incidents are putting the personal details of national security personnel at risk. Officials and agencies face mounting privacy and operational-security exposure.

Sources: Schneier on Security · Wired Security · ↑ top

Business and Politics

Trump Threatens 100% Tariff Over Digital Services Taxes

Latest developments: Trump issued a 100% tariff threat against Europe on June 26, a day after the European Union approved tariff cuts on American goods.

read more

President Trump threatened a 100% tariff on any country that taxes United States digital services, saying the levy would override existing trade deals and putting major European economies on notice as they weigh new taxes on American tech companies.

Sources: WSJ World News · FT World · ↑ top

Iran Cargo-Ship Strike Tests Ceasefire

Latest developments: Trump on June 26 blamed Iran for a drone strike on a cargo ship in the Strait of Hormuz, calling it a foolish violation of the ceasefire.

read more

A drone strike hit a cargo ship in the Strait of Hormuz on Thursday, snarling traffic through the world's busiest oil chokepoint and threatening President Trump's preliminary deal to wind down the Iran war, even as oil futures settled near pre-war levels.

Sources: WSJ World News · WSJ Markets · ↑ top

Pittsburgh

Weather

This Afternoon: Mostly Cloudy, high 81F.

Tonight: Mostly Cloudy then Slight Chance Showers And Thunderstorms, low 64F.

Saturday: Showers And Thunderstorms, high 79F.

Business

Cranberry Costco Starts Selling Beer and Wine

Latest developments: WTAE reported June 26 that the Cranberry Township Costco became the first Costco in Pennsylvania to sell beer and wine.

read more

The Costco warehouse in Cranberry Township, Butler County, began selling beer and wine, the first store in the chain's Pennsylvania locations to do so.

Sources: WTAE · ↑ top

Downtown Tax-Diversion District Draws Backlash

Latest developments: Residents lashed out at the proposed Golden Triangle tax-diversion district at a Thursday meeting, TribLive reported June 26.

read more

Pittsburgh's plan to earmark future tax revenue from new Downtown construction for Golden Triangle redevelopment met stiff opposition from residents who questioned its transparency and fairness.

Sources: TribLive · ↑ top

Around Town

Parkway East Closure Looms; PRT Urges Transit

Latest developments: Pittsburgh Regional Transit on June 26 pressed drivers to ride the East Busway during next month's three-week Parkway East closure.

read more

Pittsburgh Regional Transit is steering commuters toward public transit, especially the Wilkinsburg East Busway, ahead of a three-week Parkway East shutdown next month to replace the Commercial Street Bridge.

Sources: KDKA · ↑ top

Overnight I-279 Closures for Bridge Demolition

Latest developments: Allegheny County released the schedule June 26 for overnight northbound I-279 closures next week.

read more

The Allegheny County Department of Public Works will close northbound I-279 overnight next week to demolish Jacks Run Bridge No. 3, which carries Jacks Run Road over the highway.

Sources: WPXI · ↑ top

Pennsylvania Measles Outbreak Worsens

Latest developments: State health officials issued a strong call to action June 26 as Pennsylvania's measles count climbed.

read more

Pennsylvania health officials, declaring they will not sit back as the virus spreads, escalated their response to a worsening statewide measles outbreak.

Sources: Pittsburgh Post-Gazette · ↑ top

Events

Anthrocon Marks 20th Anniversary

Latest developments: Organizers confirmed June 26 that Anthrocon returns July 2-5 for its 20th anniversary.

read more

Anthrocon, one of the world's largest furry conventions, runs July 2 through July 5 at the David L. Lawrence Convention Center Downtown under the theme 'Critters, Cryptids and Curses,' with more than 16,000 pre-registered and an expected economic impact above $18 million.

Sources: KDKA · ↑ top

Danny Elfman Joins the Pittsburgh Symphony

Latest developments: Pittsburgh Magazine reported June 26 that Danny Elfman will perform with the Pittsburgh Symphony Orchestra at Heinz Hall.

read more

Composer Danny Elfman brings his 'Symphony of Chaos' to Heinz Hall, Downtown, with the Pittsburgh Symphony Orchestra, his first Pittsburgh appearance in nearly 40 years.

Sources: Pittsburgh Magazine · ↑ top

Picklesburgh Adds Pickleball Courts

Latest developments: Organizers said June 26 that Picklesburgh will debut pickleball courts at Arts Landing this year.

read more

Picklesburgh, the annual Downtown food festival, runs July 16-19 and will add pickleball courts at Arts Landing with tournament play, free instructional clinics, and courts featuring commissioned public artwork.

Sources: WPXI · ↑ top

Sports

Pirates (41-40)

Thu Jun 25 · Mariners 1 · Pirates 5 · Final

Brandon Lowe, Henry Davis each homer to lead Pirates over Mariners 5-1

Up Next · Reds @ Pirates · Fri Jun 26, 6:40 PM

Around the Teams

Pirates Activate Konnor Griffin

Latest developments: The Pirates activated rookie shortstop Konnor Griffin from the injured list June 26 and optioned Jack Brannigan to Double-A Altoona.

read more

Pittsburgh reinstated top prospect Konnor Griffin, sidelined since May 31 with a right forearm strain, giving its injury-thinned lineup a boost after his strong rehab stint at Altoona.

Sources: Post-Gazette Pirates · ↑ top

Eric Ebron on Cam Heyward's Podcast

Latest developments: Former tight end Eric Ebron joined 'Not Just Football with Cam Heyward' in an episode posted June 24.

read more

On 'Not Just Football with Cam Heyward,' Eric Ebron walked through his NFL journey across Detroit, Indianapolis, and Pittsburgh, his retirement at 28, and Andrew Luck's career.

Sources: Not Just Football with Cam Heyward · ↑ top

Pirates Celebrate Don Kelly's 100th Win

Latest developments: The Post-Gazette reported June 26 that the Pirates marked manager Don Kelly's 100th career win.

read more

Pittsburgh players and staff celebrated manager Don Kelly reaching 100 career wins, with teammates voicing hope that more follow in a postseason push.

Sources: Post-Gazette Pirates · ↑ top

Team USA

USMNT Falls to Türkiye in Group Finale

Latest developments: The United States lost 3-2 to Türkiye on June 25, with Pochettino defiantly noting the team still won Group D.

read more

A second-string United States side, already through as Group D winners, fell 3-2 to Türkiye, and coach Mauricio Pochettino sparred with reporters afterward as Christian Pulisic returned from a calf injury before the round-of-32 match against Bosnia-Herzegovina.

Sources: ESPN Soccer · ↑ top

Pochettino, US Soccer in Extension Talks

Latest developments: Sources told ESPN on June 26 that Pochettino and U.S. Soccer are holding positive talks over a contract extension.

read more

United States men's coach Mauricio Pochettino and U.S. Soccer have opened positive discussions about extending his contract as the co-hosts head into the World Cup knockout rounds.

Sources: ESPN Soccer · ↑ top

Milan Rejects NYCFC Bid for Pulisic

Latest developments: AC Milan named Massimo Calvelli chief executive June 26, a day after rejecting New York City FC's approach for Christian Pulisic.

read more

AC Milan turned down New York City FC's approach for United States attacker Christian Pulisic and installed Massimo Calvelli as chief executive in a bid to restore a winning culture.

Sources: ESPN Soccer · ↑ top

Reading

Markets

weekly average, change vs prior week

S&P 500     7,410.91  ▼ -0.7%
Dow        51,742.75  ▲ +0.6%
Nasdaq     25,821.36  ▼ -1.3%
WTI crude      73.38  ▼ -9.7%
EUR/USD       1.1416  ▼ -1.4%
GBP/USD       1.3205  ▼ -1.5%
USD/JPY       161.53  ▲ +0.8%