infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

Washington posted a $10 million bounty on the Russian operatives who hijacked Signal and WhatsApp accounts as ShinyHunters turned Oracle's enterprise software flaws into a breach spree.


Emerging Trends and Key Updates

Security

1. $10 Million Bounty for Russian Messaging-App Hackers

Nation-State Activity · [apt, policy]

Latest developments: The U.S. State Department on June 29 posted a reward of up to $10 million for information identifying or locating members of UNC5792 and UNC4221, the groups tied to Russia's intelligence and military services behind the Signal and WhatsApp account takeovers.

read more

UNC5792 and UNC4221 socially engineer their way into the messaging accounts of government officials, military leaders, and allied personnel, a campaign running since at least March 2026. Officials urge targeted users to lock down device-linking and backup recovery keys.

Sources: Ars Technica Security · The Record · BleepingComputer · SecurityWeek · ↑ top

2. ShinyHunters Mine Oracle PeopleSoft and E-Business Suite

Data Breaches · [breach, zero-day, extortion]

Latest developments: Nissan disclosed June 29 that attackers exploiting an Oracle PeopleSoft zero-day stole current and former employee data, the National Association of Insurance Commissioners confirmed ShinyHunters breached its PeopleSoft server while the group claimed 3.1 terabytes, and Defused reported fresh exploitation of a separate critical Oracle E-Business Suite flaw, CVE-2026-46817.

read more

The ShinyHunters extortion group chains Oracle enterprise software flaws to steal corporate and regulator data, with PeopleSoft and the E-Business Suite financial application now both under active attack. Affected organizations should apply Oracle's emergency fixes and hunt for data-theft indicators.

Sources: BleepingComputer · BleepingComputer · SecurityWeek · BleepingComputer · ↑ top

3. SimpleHelp Flaw Deploys Djinn Stealer

Vulnerabilities and Exploits · [patch, infostealer, kev]

Latest developments: CISA added CVE-2026-48558, a critical authentication-bypass flaw in SimpleHelp remote-support software, to its Known Exploited Vulnerabilities catalog June 29 as attackers used it to drop Djinn Stealer and the TaskWeaver loader.

read more

Djinn Stealer is a previously undocumented cross-platform infostealer hitting Windows, macOS, and Linux, targeting cloud and AI credentials that link development and admin environments to wider enterprise systems. SimpleHelp operators must patch immediately under CISA's binding directive.

Sources: Dark Reading · BleepingComputer · CISA Advisories · ↑ top

4. libssh2 and DirtyClone Open Clients and Kernels

Vulnerabilities and Exploits · [vulnerability, patch, poc]

Latest developments: A public proof-of-concept dropped June 29 for CVE-2026-55200, a critical libssh2 flaw that lets a malicious SSH server corrupt a connecting client's memory without credentials or interaction, the same day SecurityWeek detailed DirtyClone, a DirtyFrag variant that gives unprivileged Linux users root by manipulating the page cache, and PTC's advisory confirmed JSP webshells dropping on unpatched Windchill instances.

read more

CVE-2026-55200 affects every libssh2 release through 1.11.1 at CVSS 9.2, exposing any tool that links the client-side library, while DirtyClone and the Windchill CVE-2026-12569 webshells add local-root and remote-code-execution risk. Administrators should rebuild against patched libssh2, apply kernel fixes, and pull Windchill indicators of compromise.

Sources: The Hacker News · SecurityWeek · Help Net Security · ↑ top

5. 119 Edge Extensions and Hijacked Packages Spread Malware

Ransomware and Cybercrime · [supply-chain, infostealer, adware]

Latest developments: Microsoft removed 119 Edge Add-ons it ties to a single actor active since 2021, a campaign it calls StegoAd that hides payloads inside image and font files before waking days later to steal credentials and run ad fraud, while JFrog found two hijacked npm packages and a cluster of Go packages abusing VS Code tasks to deploy a Python infostealer.

read more

Both operations smuggle malware past store and registry defenses, StegoAd through steganography in benign-looking files and the package attack by avoiding npm lifecycle scripts to dodge npm v12 hardening. Developers and users should audit installed extensions and pin dependency sources.

Sources: The Hacker News · The Hacker News · ↑ top

6. The Gentlemen Ransomware Crew Refines Its Backdoors

Ransomware and Cybercrime · [ransomware, raas]

Latest developments: Kaspersky researchers published June 29 an analysis of incidents tied to The Gentlemen ransomware-as-a-service group, disclosing its custom backdoors and tradecraft and flagging a new ransomware variant.

read more

The Gentlemen runs a ransomware-as-a-service operation built around bespoke backdoors and evolving tactics. Kaspersky's tools, techniques, and indicators give defenders detection signatures for the group's intrusions.

Sources: Securelist (Kaspersky) · ↑ top

Business and Politics

Supreme Court Expands Trump's Removal Power, Spares the Fed

Latest developments: The Supreme Court ruled June 29, letting President Trump fire the heads of independent agencies at will while blocking his attempt to remove Federal Reserve governor Lisa Cook.

read more

The 6-3 decision exposes dozens of federal agencies to presidential control and strikes down long-standing for-cause removal protections; it carves out the Federal Reserve and keeps Cook in her seat after Trump moved to oust her.

Sources: WSJ US Business · The Economist · ↑ top

Pittsburgh

Weather

Tonight: Mostly Clear, low 71F.

Tuesday: Mostly Sunny, high 94F.

Tuesday Night: Partly Cloudy, low 76F.

Business

Rising Tide Partners' Distressed Properties Languish

Latest developments: KDKA reported June 29 that hundreds of distressed properties Rising Tide Partners bought to revive Pittsburgh neighborhoods still sit decaying five years on.

read more

Rising Tide Partners, a Pittsburgh nonprofit led by chief executive Diamonte Walker, has acquired hundreds of distressed properties since 2021 promising neighborhood revival; residents near its Homewood holdings say the buildings keep decaying.

Sources: KDKA · ↑ top

Swissvale Businesses Brace for Parkway East Closure

Latest developments: WTAE reported June 29 that Swissvale business owner Dave Guerin warns a coming 25-day Parkway East closure will choke deliveries and supplier routes.

read more

A planned 25-day closure of the Parkway East, Interstate 376 east of Pittsburgh, threatens deliveries for businesses in Swissvale, where owner Dave Guerin says detours will complicate suppliers' access.

Sources: WTAE · ↑ top

Allegheny County Moves to Block Deed Fraud

Latest developments: WPXI's 11 Investigates reported June 29 that Allegheny County filed court paperwork to halt deed transfers to the LLCs tied to a wave of fraudulent property transfers.

read more

Allegheny County is seeking a court order to block any deed transfers to limited-liability companies connected to recent deed-fraud cases, after a Pittsburgh real estate agent documented dozens of fraudulent transfers concentrated on the South Side.

Sources: WPXI · ↑ top

Around Town

Commercial Street Closes for Bridge Replacement

Latest developments: KDKA reported June 29 that Commercial Street officially closed as the bridge-replacement project near Frick Park entered its construction phase, a shutdown expected to last about five weeks.

read more

PennDOT closed Commercial Street in Pittsburgh's Swisshelm Park neighborhood for roughly five weeks so crews can replace the bridge carrying it near Frick Park, rerouting local traffic through surrounding streets.

Sources: KDKA · ↑ top

Justice Department Sues Pennsylvania Over SNAP Data

Latest developments: The U.S. Justice Department sued Pennsylvania, Kentucky, Michigan, and Minnesota on June 29 for refusing to hand the Agriculture Department data on food-stamp applicants.

read more

The Justice Department alleges the four states withheld five years of Supplemental Nutrition Assistance Program applicant records the U.S. Department of Agriculture sought to verify residents' eligibility and household benefit levels.

Sources: KDKA · ↑ top

Monroeville Library Pulls Pride Display

Latest developments: WTAE reported June 29 that the Monroeville Public Library removed its Pride Month children's book display after local officials demanded it.

read more

The Monroeville Public Library took down a Pride Month book display in its children's room after Monroeville Councilman Bill Krut called the books 'sexual grooming' in a June 19 Facebook post, ending a rotation the library uses to mark different communities.

Sources: WTAE · ↑ top

Sports

Pirates (42-42)

Sun Jun 28 · Reds 4 · Pirates 9 · Final

Ryan O'Hearn homers twice, helps Pirates avoid sweep with 9-4 win over Reds

Mon Jun 29 · Pirates 8 · Phillies 5 · Bot 8th (in progress at last update)

Up Next · Pirates @ Phillies · Tue Jun 30, 6:40 PM

Around the Teams

Steelers Face Joey Porter Jr. Contract Puzzle

Latest developments: In a June 29 Post-Gazette video, beat writer Gerry Dulac weighed how complicated the Steelers' contract negotiations with cornerback Joey Porter Jr. could become.

read more

Gerry Dulac broke down the looming extension talks between the Pittsburgh Steelers and cornerback Joey Porter Jr., assessing how complex a long-term deal for the young defender may prove.

Sources: Post-Gazette Steelers · ↑ top

Hiles: Pirates Should Look Within for Bullpen Help

Latest developments: Post-Gazette columnist Noah Hiles argued June 29 that internal arms could fix the Pirates' bullpen better than trade-deadline acquisitions.

read more

In his weekend column, Noah Hiles wrote that the Pittsburgh Pirates can shore up a shaky bullpen by leaning on relievers already in the organization, naming Dennis Santana and Isaac Mattson, ahead of the trade deadline.

Sources: Post-Gazette Pirates · ↑ top

Team USA

Sebastian Berhalter Scores in US Win Over Türkiye

Latest developments: ESPN reported June 30 that Sebastian Berhalter scored his first World Cup goal in the United States' group-stage win over Türkiye, moving his father, former U.S. coach Gregg Berhalter, to tears.

read more

Midfielder Sebastian Berhalter, son of former U.S. men's national team coach Gregg Berhalter, scored for the United States against Türkiye in the World Cup group stage, a goal that left his father, now Chicago Fire manager, in tears.

Sources: ESPN Soccer · ↑ top

Analysts See USMNT as World Cup Dark Horse

Latest developments: ESPN convened coaches and analysts June 29 who judged the United States capable of a surprise deep run after a strong group stage as co-host.

read more

A panel ESPN assembled of coaches and analysts weighed whether the United States men's national team can become the 2026 World Cup's surprise package, citing its group-stage form ahead of a round-of-32 meeting with Bosnia and Herzegovina on Wednesday, July 1.

Sources: ESPN Soccer · ↑ top

Reading

Markets

weekly average, change vs prior week

S&P 500     7,375.12  ▼ -1.6%
Dow        51,899.04  ▲ +0.4%
Nasdaq     25,508.01  ▼ -3.2%
WTI crude      71.90  ▼ -9.0%
EUR/USD       1.1382  ▼ -1.3%
GBP/USD       1.3200  ▼ -0.8%
USD/JPY       161.70  ▲ +0.6%