daily plain-text briefing: security, markets, business, and pittsburgh
The FBI and CISA warn that Russian intelligence phishing now harvests Signal Backup Recovery Keys to seize victims' full message history, as attackers separately weaponize AI coding agents and race federal patch deadlines on Cisco gear.
Latest developments: BleepingComputer reported June 27 that a benign-looking GitHub repository can hide a payload an agentic coding tool runs while cloning and setting it up, staying invisible to security scanners, AI agents, and human reviewers, while threat actors separately spin up fake OpenAI tenants impersonating real companies and invite employees to join, fishing for sensitive data inside chats and projects.
As developers hand setup and coding work to autonomous AI agents, attackers plant malicious instructions in trusted-looking repositories and impersonate AI vendors to harvest corporate data; teams should sandbox agent execution and verify any organization invite before joining.
Sources: BleepingComputer · BleepingComputer · ↑ top
Latest developments: The FBI and CISA updated their March 2026 advisory on June 26, warning that the Russian intelligence phishing campaign against Signal users adds a step, coaxing targets into surrendering their Signal Backup Recovery Key so attackers can restore the account backup, read private and group message history, and hold persistent access.
Russian intelligence services run ongoing phishing against the messaging accounts of government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States; the recovery key keeps working after theft, so affected Signal users should rotate keys and re-secure linked devices.
Sources: BleepingComputer · The Hacker News · CISA Advisories · ↑ top
Latest developments: CISA on June 26 gave federal agencies until Sunday, June 28, to patch CVE-2026-20230, a server-side request forgery flaw in Cisco Unified Communications Manager Server that attackers are actively exploiting.
The Cisco Unified CM flaw lets automated Tor sweeps drop webshells on exposed servers; administrators across government and enterprise should apply Cisco's fix at once rather than wait for the federal deadline.
Sources: BleepingComputer · ↑ top
Latest developments: Synology issued critical fixes June 26 for three MailPlus Server flaws, including CVE-2026-13136 from faulty authorization checks and CVE-2026-13135 from improper channel restriction, that let remote attackers read or write arbitrary files and trigger denial of service.
MailPlus Server runs private email infrastructure on Synology NAS devices; administrators should install the security update immediately to close the remote file-access and denial-of-service paths.
Sources: Help Net Security · ↑ top
Latest developments: Wired reported June 26 that the Pentagon is investigating the Dialog data exposure after leaked records from the private group surfaced the personal information of a senior White House intelligence official and an active-duty special operations officer.
Exposed records from Dialog, a private group, revealed identifying details of sitting national security personnel, raising concern that the leak could unmask officials and operatives; the Defense Department is assessing the damage.
Sources: Wired Security · ↑ top
Latest developments: Fortra detailed Mirage2FA, a phishing kit that pairs short-lived HTML smuggling with obfuscated JavaScript loaders to serve fake Microsoft 365 login pages and steal credentials during multi-factor prompts.
Mirage2FA reaches victims through business-themed email lures carrying HTML and JavaScript attachments, then captures Microsoft 365 credentials mid-authentication; defenders should block HTML-smuggling attachments and enforce phishing-resistant MFA.
Sources: Help Net Security · ↑ top
Latest developments: The United States hit multiple targets inside Iran on June 27, a second straight day of strikes that followed Tehran's drone assault on Bahrain and its attack on a tanker in the Strait of Hormuz a day earlier.
The escalating tit-for-tat threatens the preliminary ceasefire President Trump signed with Tehran, and U.S. crude futures climbed back above $70 a barrel as shipping through the Strait of Hormuz stayed a flashpoint for the global economy.
Sources: FT World · WSJ World News · WSJ Markets · ↑ top
Tonight: Scattered Rain Showers then Widespread Fog, low 67F.
Sunday: Widespread Fog then Scattered Showers And Thunderstorms, high 85F.
Sunday Night: Scattered Showers And Thunderstorms then Partly Cloudy, low 67F.
Latest developments: Allegheny County confirmed June 27 that its code red heat advisory runs Monday June 29 through Wednesday July 1, when temperatures will top 90 degrees.
The county Department of Human Services will check on older residents through home-delivered-meals drivers and care managers, and Pittsburgh will open cooling centers as the region heads into a multi-day heat wave.
Sources: KDKA · Pittsburgh Post-Gazette · ↑ top
Latest developments: A June 27 TribLive op-ed by Rabbi Seth Adelson recounted the East End Food Co-op board's June 15 vote against boycotting the Israeli products on its shelves.
The East End Food Co-op, the member-owned grocery in Pittsburgh's East End, declined to pull its handful of Israeli products, ending a member campaign to remove them.
Pirates (41-42)
Fri Jun 26 · Reds 6 · Pirates 4 · Final
Marte's tiebreaking homer in 8th after 4-run inning against Skenes helps Reds beat Pirates 6-4
Sat Jun 27 · Reds 9 · Pirates 7 · Final
Eugenio Suárez hits 3-run homer in 9th as Reds rally for 9-7 win over Pirates
Up Next · Reds @ Pirates · Sun Jun 28, 1:35 PM
Latest developments: A June 27 Post-Gazette "Off The Bat" column laid out how the MLB Players Association can point to Pirates prospects Konnor Griffin and Endy Rodriguez in the next round of collective-bargaining fights.
The column uses Griffin and Rodriguez as test cases in the union's arguments over service time and pay with Major League Baseball ahead of the next labor deal.
Sources: Post-Gazette Pirates · ↑ top
Latest developments: With the group stage closing June 27, the United States, winners of Group D, will open the World Cup round of 32 against Bosnia and Herzegovina.
The Guardian mapped Mauricio Pochettino's path through the tournament the Americans co-host with Canada and Mexico, figuring they would likely have to beat Spain, France, and England to lift the trophy.
Sources: Guardian World Cup 2026 · ↑ top
Latest developments: ESPN wrote June 27 that international visitors have embraced American ranch dressing, vindicating U.S. midfielder Weston McKennie, whose "Love Ranch" celebration once drew mockery.
Ranch has spread through World Cup memes, reels, and fans' carry-ons across the host cities, turning a running joke about McKennie into a marker of how the tournament has warmed to American tastes.
Sources: ESPN Soccer · ↑ top
S&P 500 7,381.60 ▼ -1.4% Dow 51,805.04 ▲ +0.4% Nasdaq 25,577.30 ▼ -2.7% WTI crude 71.90 ▼ -9.0% EUR/USD 1.1382 ▼ -1.3% GBP/USD 1.3200 ▼ -0.8% USD/JPY 161.68 ▲ +0.6%