================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Monday, June 29, 2026 - 12:06 PM EDT ================================================================ The U.S. State Department posted a $10 million bounty on the Russian hackers prying into officials' Signal and WhatsApp accounts as freshly exploited flaws in SimpleHelp, Oracle, and libssh2 widened the day's attack surface. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] The State Department posted a $10 million reward for UNC5792 and UNC4221, the Russia-linked crews that phished their way into Signal and WhatsApp accounts. see: $10 Million Bounty for Russian Messaging-App Hackers * [TREND] Attackers weaponized Oracle E-Business Suite and SimpleHelp to drop Djinn Stealer, while ShinyHunters claimed a 3.1-terabyte NAIC breach through compromised Oracle PeopleSoft. see: Critical Flaws Exploited in SimpleHelp and Oracle E-Business Suite; NAIC Breached in Oracle PeopleSoft Hack * [TREND] Microsoft pulled 119 StegoAd Edge add-ons hiding payloads in image files as DCloud's legitimate Uni-App framework was found powering more than 236,000 fraudulent scam sites. see: StegoAd Edge Extensions and Hijacked Open-Source Packages; DCloud Uni-App Powers 236,000 Scam Sites * [UPDATE (new)] A poisoned Bing search delivered the Bumblebee loader and AdaptixC2 framework, ending in Akira ransomware across two intrusions analyzed with Swisscom's CSIRT. see: Akira Ransomware Delivered via Bumblebee and AdaptixC2 * [TREND] The Supreme Court let Lisa Cook keep her Federal Reserve seat for now and ruled states may count mail ballots arriving after Election Day. see: Supreme Court Shields Fed's Cook; Supreme Court Upholds Late-Arriving Mail Ballots SECURITY ---------------------------------------------------------------- 1. $10 MILLION BOUNTY FOR RUSSIAN MESSAGING-APP HACKERS Nation-State Activity · [apt, phishing, policy] Latest developments: The U.S. State Department on June 29 posted a reward of up to $10 million for information identifying or locating members of UNC5792 and UNC4221, the Russia-linked groups that socially engineered their way into Signal and WhatsApp accounts of U.S. and allied officials. UNC5792 and UNC4221, tied to Russia's intelligence and military services, phish messaging accounts of government officials, military leaders, and activists across Ukraine, Europe, and the United States; the State Department's Rewards for Justice program now seeks tips on both crews. - The Record: https://therecord.media/10million-reward-us-russian-hackers-unc4221-unc5792 - BleepingComputer: https://www.bleepingcomputer.com/news/security/us-offers-10-million-for-hackers-targeting-whatsapp-signal-users/ - SecurityWeek: https://www.securityweek.com/us-offers-10-million-bounty-for-russian-state-hackers-as-messaging-app-attacks-evolve/ 2. CRITICAL FLAWS EXPLOITED IN SIMPLEHELP AND ORACLE E-BUSINESS SUITE Vulnerabilities and Exploits · [zero-day, patch, infostealer] Latest developments: Attackers on June 29 began exploiting CVE-2026-46817 in Oracle E-Business Suite and weaponized SimpleHelp flaw CVE-2026-48558 to drop Djinn Stealer, a previously undocumented cross-platform infostealer, while a public proof-of-concept surfaced for CVE-2026-55200, a critical libssh2 client-side bug. SimpleHelp remote-support software now delivers Djinn Stealer and TaskWeaver malware to Windows, macOS, and Linux; Oracle's E-Business Suite financial application faces active attacks per Defused; libssh2 releases through 1.11.1 carry a CVSS 9.2 flaw that lets a malicious SSH server corrupt a connecting client's memory. Patch all three immediately. - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-simplehelp-flaw-deploy-new-djinn-infostealer-taskweaver-malware/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-flaw-now-exploited-in-attacks/ - The Hacker News: https://thehackernews.com/2026/06/public-poc-released-for-critical.html 3. STEGOAD EDGE EXTENSIONS AND HIJACKED OPEN-SOURCE PACKAGES Ransomware and Cybercrime · [supply-chain, infostealer, breach] Latest developments: Microsoft on June 29 pulled 119 Edge add-ons tied to a single StegoAd actor active since 2021 that hid payloads inside image and font files, the same day JFrog flagged two hijacked npm packages and a cluster of Go packages abusing VS Code tasks to plant a Python infostealer. The StegoAd extensions woke days after install to steal credentials and run ad fraud; the hijacked npm and Go packages dodge lifecycle scripts to drop a Python stealer on Windows, Linux, and macOS. Audit installed browser extensions and pin trusted package versions. - The Hacker News: https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html - The Hacker News: https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html 4. NAIC BREACHED IN ORACLE PEOPLESOFT HACK Data Breaches · [breach, extortion] Latest developments: SecurityWeek reported June 29 that the ShinyHunters extortion group claims it stole 3.1 terabytes of data from the National Association of Insurance Commissioners through a compromise of Oracle PeopleSoft. The NAIC, the U.S. standard-setting body for state insurance regulators, suffered a breach ShinyHunters attributes to Oracle PeopleSoft; the gang says it holds 3.1 TB. Organizations running PeopleSoft should review access and monitor for extortion contact. - SecurityWeek: https://www.securityweek.com/insurance-regulators-group-naic-hit-in-oracle-peoplesoft-hack/ 5. AKIRA RANSOMWARE DELIVERED VIA BUMBLEBEE AND ADAPTIXC2 Ransomware and Cybercrime · [ransomware, malvertising] Latest developments: The DFIR Report on June 29 published a full analysis of two intrusions, worked with Swisscom B2B CSIRT, in which a poisoned Bing search result delivered the Bumblebee loader and the AdaptixC2 framework and ended in Akira ransomware. The campaign lures victims through manipulated Bing results, chains Bumblebee and AdaptixC2 for access and command-and-control, and deploys Akira; the report ties both intrusions to one operation first flagged in mid-2025. Filter search-driven downloads and hunt for AdaptixC2 beacons. - The DFIR Report: https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/ 6. DCLOUD UNI-APP POWERS 236,000 SCAM SITES Ransomware and Cybercrime · [scam, phishing] Latest developments: Infoblox on June 29 raised the count of fraudulent sites built on DCloud's legitimate Uni-App framework to more than 236,000, up from roughly 200,000 reported June 27, and detailed bogus cryptocurrency exchanges, pig-butchering operations, WhatsApp phishing networks, and wallet drainers. Threat actors sell investment-scam templates built with DCloud's Chinese open-source Uni-App toolkit, spinning up fake exchanges and gambling and brand-impersonation pages at scale. Block the associated domains and warn users about crypto-investment lures. - The Hacker News: https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html BUSINESS AND POLITICS ---------------------------------------------------------------- * Supreme Court Shields Fed's Cook Latest developments: The Supreme Court ruled June 29 that Lisa Cook keeps her Federal Reserve seat for now while upholding President Trump's power to remove other top agency officials. The Supreme Court blocked President Trump from firing Federal Reserve governor Lisa Cook, letting her stay on the central bank's board even as it endorsed his authority to dismiss other regulators—a split decision that goes to the heart of the Fed's independence. - Financial Times: https://www.ft.com/content/84db4001-8c8c-4dfa-9c6f-b501c38bc2fb * U.S. and Iran Agree to Halt Strait Fight Latest developments: The White House announced June 29 a formal deal to stop the strikes and resume talks, dispatching Steve Witkoff and Jared Kushner to Doha for high-level meetings, though Tehran disputed that any meeting is set. After days of exchanging strikes over the Strait of Hormuz, the United States and Iran agreed to halt fighting and reopen negotiations toward a long-term deal restraining Tehran's nuclear program; oil futures and Treasury yields rose on the news. - WSJ: https://www.wsj.com/world/middle-east/iran-asserts-sole-control-of-hormuz-warns-challenges-will-bring-more-violence-5abea3c7 - Financial Times: https://www.ft.com/content/a1dc9209-ec77-415c-baae-e3ddab5c0eb1 PITTSBURGH ---------------------------------------------------------------- Weather: This Afternoon: Mostly Sunny, high 90F. Tonight: Partly Cloudy, low 71F. Tuesday: Mostly Sunny, high 94F. Business: * Rockaway Pizzeria Pauses for Owner's Health Latest developments: Pittsburgh Magazine reported June 29 that owner Josh Sickels closed on his doctor's advice, revealing herniated discs in his spine as the reason behind the pause first noted last week. Josh Sickels, owner of Rockaway Pizzeria in Regent Square, shut the shop temporarily on doctor's orders, citing herniated discs at multiple levels of his spine and a bid to stay out of surgery. - Pittsburgh Magazine: https://www.pittsburghmagazine.com/why-rockaway-pizzeria-break/ Around town: * Heat Dome Pushes Feels-Like Past 100 Latest developments: Forecasters said June 29 the heat index could top 100 degrees across western Pennsylvania for several days into the Fourth of July weekend, extending the Code Red advisory issued earlier in the week. A heat dome settling over the region will push heat-index values above 100 degrees in western Pennsylvania through the July 4 weekend, part of a system baking roughly 200 million people across the United States; Pittsburgh is opening cooling centers. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/weather-news/2026/06/29/pittsburgh-weather-heat-wave-high-temperatures/stories/202606290022 - WTAE: https://www.wtae.com/article/pennsylvania-4th-of-july-heat-wave-forecast/71768943 * Supreme Court Upholds Late-Arriving Mail Ballots Latest developments: The Supreme Court ruled 5-4 on June 29 that states may count mail ballots cast by Election Day but arriving afterward, rejecting a Republican challenge. In Watson v. Republican National Committee, the Supreme Court upheld Mississippi's law counting mail ballots that arrive after Election Day, finding 5-4 that the measure squares with the federal statute fixing Election Day and turning back an RNC-led challenge. - KDKA: https://www.cbsnews.com/pittsburgh/news/supreme-court-mail-ballots-mississippi-law-watson-v-rnc/ - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/politics-nation/2026/06/29/supreme-court-late-mail-ballots/stories/202606290027 * Recycled-Plastic Benches Appear in Alle-Kiski Valley Latest developments: TribLive reported June 29 that benches built from recycled plastic grocery bags are popping up in Brackenridge and Harrison, each one consuming about 80,000 bags. A recycling effort is placing benches made from recycled plastic grocery bags around Brackenridge and Harrison, where it takes roughly 80,000 collected bags to produce a single substantial bench. - TribLive: https://triblive.com/local/valley-news-dispatch/benches-made-from-recycled-plastics-popping-up-in-brackenridge-harrison/ Events: * Vandergrift ArtFest Returns in Late July Latest developments: TribLive reported June 29 that this year's Vandergrift ArtFest, set for late July, will carry an other-worldly theme. The Vandergrift ArtFest, an outdoor festival of artisan vendors, art displays, food trucks, and live performances, returns to Vandergrift in late July built around an other-worldly theme. - TribLive: https://triblive.com/local/valley-news-dispatch/vandergrift-artfest-set-for-late-july/ * Polar World Closes at Carnegie Museum Latest developments: The Post-Gazette reported June 27 that the Carnegie Museum of Natural History is retiring its Polar World exhibit after 43 years on view. The Carnegie Museum of Natural History in Oakland is closing Polar World, a fixture of the galleries for 43 years, giving visitors a last window on the long-running exhibit of polar life and culture. - Pittsburgh Post-Gazette: https://www.post-gazette.com/ae/art-architecture/2026/06/27/polar-world-carnegie-museum-of-natural-history-closure/stories/202606280064 SPORTS ---------------------------------------------------------------- Pirates (42-42) Sun Jun 28 · Reds 4 · Pirates 9 · Final Ryan O'Hearn homers twice, helps Pirates avoid sweep with 9-4 win over Reds https://plaintextsports.com/mlb/2026-06-28/cin-pit Up Next · Pirates @ Phillies · Mon Jun 29, 6:40 PM https://plaintextsports.com/mlb/2026-06-29/pit-phi Around the Teams: * Steelers Face Tricky Porter Contract Talks Latest developments: A June 29 Post-Gazette video with Gerry Dulac broke down how complicated Pittsburgh's contract negotiations with cornerback Joey Porter Jr. could become. Post-Gazette beat writer Gerry Dulac assessed the looming contract negotiations between the Steelers and cornerback Joey Porter Jr., weighing how complex an extension for the young corner could get. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/06/29/nfl-news-rumors-joey-porter-jr-contract-gerry-dulac/stories/202606290035 * Hiles Pitches Pirates' In-House Bullpen Fix Latest developments: In his June 29 weekend column, Post-Gazette writer Noah Hiles pointed to internal arms as the Pirates' best path to a steadier bullpen. Post-Gazette columnist Noah Hiles argued the Pirates' own relievers, Dennis Santana and Isaac Mattson among them, can do more to repair the bullpen than any trade-deadline addition. - Post-Gazette Pirates: https://www.post-gazette.com/sports/columns/2026/06/29/mlb-pirates-dennis-santana-isaac-mattson/stories/202606280071 Team USA: * Analysts Weigh USMNT's Deep-Run Odds Latest developments: ESPN convened a panel of coaches and analysts June 29 to judge whether the United States can become the 2026 World Cup's surprise package after a strong group stage as co-host. ESPN assembled coaches and analysts to assess the United States men's national team's chances of a deep World Cup run, with outside observers arguing the co-hosts have the makeup to advance well into the knockout rounds. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49213271/why-outsiders-believe-usmnt-make-deep-world-cup-run READING ---------------------------------------------------------------- * Cal Newport -- Beware of Productivity Paradoxes Cal Newport argues that technologies seemingly destined to lift productivity—the personal computer chief among them—often fail to deliver measurable gains, a cautionary lens he turns on today's AI hype. https://calnewport.com/beware-of-productivity-paradoxes/ * Stratechery -- An Interview with Figma CEO Dylan Field About Design and AI Ben Thompson interviews Figma chief executive Dylan Field about building the design tool and why Field believes AI gives the company a tailwind. https://stratechery.com/2026/an-interview-with-figma-ceo-dylan-field-about-design-and-ai/ * Ed Zitron -- Premium: Notes From The Bubble, Volume 1 Ed Zitron launches an ongoing series collecting running notes and analysis on what he sees as the AI investment bubble and its strained finances. https://www.wheresyoured.at/premium-notes-from-the-bubble-volume-1/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,381.60 ▼ -1.4% Dow 51,805.04 ▲ +0.4% Nasdaq 25,577.30 ▼ -2.7% WTI crude 71.90 ▼ -9.0% EUR/USD 1.1397 ▼ -1.4% GBP/USD 1.3202 ▼ -1.2% USD/JPY 161.63 ▲ +0.7% ================================================================ Generated 2026-06-29 12:06 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================