daily plain-text briefing: security, markets, business, and pittsburgh
Washington posted a $10 million bounty on the Russian operatives who hijacked Signal and WhatsApp accounts as ShinyHunters turned Oracle's enterprise software flaws into a breach spree.
Latest developments: The U.S. State Department on June 29 posted a reward of up to $10 million for information identifying or locating members of UNC5792 and UNC4221, the groups tied to Russia's intelligence and military services behind the Signal and WhatsApp account takeovers.
UNC5792 and UNC4221 socially engineer their way into the messaging accounts of government officials, military leaders, and allied personnel, a campaign running since at least March 2026. Officials urge targeted users to lock down device-linking and backup recovery keys.
Sources: Ars Technica Security · The Record · BleepingComputer · SecurityWeek · ↑ top
Latest developments: Nissan disclosed June 29 that attackers exploiting an Oracle PeopleSoft zero-day stole current and former employee data, the National Association of Insurance Commissioners confirmed ShinyHunters breached its PeopleSoft server while the group claimed 3.1 terabytes, and Defused reported fresh exploitation of a separate critical Oracle E-Business Suite flaw, CVE-2026-46817.
The ShinyHunters extortion group chains Oracle enterprise software flaws to steal corporate and regulator data, with PeopleSoft and the E-Business Suite financial application now both under active attack. Affected organizations should apply Oracle's emergency fixes and hunt for data-theft indicators.
Sources: BleepingComputer · BleepingComputer · SecurityWeek · BleepingComputer · ↑ top
Latest developments: CISA added CVE-2026-48558, a critical authentication-bypass flaw in SimpleHelp remote-support software, to its Known Exploited Vulnerabilities catalog June 29 as attackers used it to drop Djinn Stealer and the TaskWeaver loader.
Djinn Stealer is a previously undocumented cross-platform infostealer hitting Windows, macOS, and Linux, targeting cloud and AI credentials that link development and admin environments to wider enterprise systems. SimpleHelp operators must patch immediately under CISA's binding directive.
Sources: Dark Reading · BleepingComputer · CISA Advisories · ↑ top
Latest developments: A public proof-of-concept dropped June 29 for CVE-2026-55200, a critical libssh2 flaw that lets a malicious SSH server corrupt a connecting client's memory without credentials or interaction, the same day SecurityWeek detailed DirtyClone, a DirtyFrag variant that gives unprivileged Linux users root by manipulating the page cache, and PTC's advisory confirmed JSP webshells dropping on unpatched Windchill instances.
CVE-2026-55200 affects every libssh2 release through 1.11.1 at CVSS 9.2, exposing any tool that links the client-side library, while DirtyClone and the Windchill CVE-2026-12569 webshells add local-root and remote-code-execution risk. Administrators should rebuild against patched libssh2, apply kernel fixes, and pull Windchill indicators of compromise.
Sources: The Hacker News · SecurityWeek · Help Net Security · ↑ top
Latest developments: Microsoft removed 119 Edge Add-ons it ties to a single actor active since 2021, a campaign it calls StegoAd that hides payloads inside image and font files before waking days later to steal credentials and run ad fraud, while JFrog found two hijacked npm packages and a cluster of Go packages abusing VS Code tasks to deploy a Python infostealer.
Both operations smuggle malware past store and registry defenses, StegoAd through steganography in benign-looking files and the package attack by avoiding npm lifecycle scripts to dodge npm v12 hardening. Developers and users should audit installed extensions and pin dependency sources.
Sources: The Hacker News · The Hacker News · ↑ top
Latest developments: Kaspersky researchers published June 29 an analysis of incidents tied to The Gentlemen ransomware-as-a-service group, disclosing its custom backdoors and tradecraft and flagging a new ransomware variant.
The Gentlemen runs a ransomware-as-a-service operation built around bespoke backdoors and evolving tactics. Kaspersky's tools, techniques, and indicators give defenders detection signatures for the group's intrusions.
Sources: Securelist (Kaspersky) · ↑ top
Latest developments: The Supreme Court ruled June 29, letting President Trump fire the heads of independent agencies at will while blocking his attempt to remove Federal Reserve governor Lisa Cook.
The 6-3 decision exposes dozens of federal agencies to presidential control and strikes down long-standing for-cause removal protections; it carves out the Federal Reserve and keeps Cook in her seat after Trump moved to oust her.
Sources: WSJ US Business · The Economist · ↑ top
Tonight: Mostly Clear, low 71F.
Tuesday: Mostly Sunny, high 94F.
Tuesday Night: Partly Cloudy, low 76F.
Latest developments: KDKA reported June 29 that hundreds of distressed properties Rising Tide Partners bought to revive Pittsburgh neighborhoods still sit decaying five years on.
Rising Tide Partners, a Pittsburgh nonprofit led by chief executive Diamonte Walker, has acquired hundreds of distressed properties since 2021 promising neighborhood revival; residents near its Homewood holdings say the buildings keep decaying.
Latest developments: WTAE reported June 29 that Swissvale business owner Dave Guerin warns a coming 25-day Parkway East closure will choke deliveries and supplier routes.
A planned 25-day closure of the Parkway East, Interstate 376 east of Pittsburgh, threatens deliveries for businesses in Swissvale, where owner Dave Guerin says detours will complicate suppliers' access.
Latest developments: WPXI's 11 Investigates reported June 29 that Allegheny County filed court paperwork to halt deed transfers to the LLCs tied to a wave of fraudulent property transfers.
Allegheny County is seeking a court order to block any deed transfers to limited-liability companies connected to recent deed-fraud cases, after a Pittsburgh real estate agent documented dozens of fraudulent transfers concentrated on the South Side.
Latest developments: KDKA reported June 29 that Commercial Street officially closed as the bridge-replacement project near Frick Park entered its construction phase, a shutdown expected to last about five weeks.
PennDOT closed Commercial Street in Pittsburgh's Swisshelm Park neighborhood for roughly five weeks so crews can replace the bridge carrying it near Frick Park, rerouting local traffic through surrounding streets.
Latest developments: The U.S. Justice Department sued Pennsylvania, Kentucky, Michigan, and Minnesota on June 29 for refusing to hand the Agriculture Department data on food-stamp applicants.
The Justice Department alleges the four states withheld five years of Supplemental Nutrition Assistance Program applicant records the U.S. Department of Agriculture sought to verify residents' eligibility and household benefit levels.
Latest developments: WTAE reported June 29 that the Monroeville Public Library removed its Pride Month children's book display after local officials demanded it.
The Monroeville Public Library took down a Pride Month book display in its children's room after Monroeville Councilman Bill Krut called the books 'sexual grooming' in a June 19 Facebook post, ending a rotation the library uses to mark different communities.
Pirates (42-42)
Sun Jun 28 · Reds 4 · Pirates 9 · Final
Ryan O'Hearn homers twice, helps Pirates avoid sweep with 9-4 win over Reds
Mon Jun 29 · Pirates 8 · Phillies 5 · Bot 8th (in progress at last update)
Up Next · Pirates @ Phillies · Tue Jun 30, 6:40 PM
Latest developments: In a June 29 Post-Gazette video, beat writer Gerry Dulac weighed how complicated the Steelers' contract negotiations with cornerback Joey Porter Jr. could become.
Gerry Dulac broke down the looming extension talks between the Pittsburgh Steelers and cornerback Joey Porter Jr., assessing how complex a long-term deal for the young defender may prove.
Sources: Post-Gazette Steelers · ↑ top
Latest developments: Post-Gazette columnist Noah Hiles argued June 29 that internal arms could fix the Pirates' bullpen better than trade-deadline acquisitions.
In his weekend column, Noah Hiles wrote that the Pittsburgh Pirates can shore up a shaky bullpen by leaning on relievers already in the organization, naming Dennis Santana and Isaac Mattson, ahead of the trade deadline.
Sources: Post-Gazette Pirates · ↑ top
Latest developments: ESPN reported June 30 that Sebastian Berhalter scored his first World Cup goal in the United States' group-stage win over Türkiye, moving his father, former U.S. coach Gregg Berhalter, to tears.
Midfielder Sebastian Berhalter, son of former U.S. men's national team coach Gregg Berhalter, scored for the United States against Türkiye in the World Cup group stage, a goal that left his father, now Chicago Fire manager, in tears.
Sources: ESPN Soccer · ↑ top
Latest developments: ESPN convened coaches and analysts June 29 who judged the United States capable of a surprise deep run after a strong group stage as co-host.
A panel ESPN assembled of coaches and analysts weighed whether the United States men's national team can become the 2026 World Cup's surprise package, citing its group-stage form ahead of a round-of-32 meeting with Bosnia and Herzegovina on Wednesday, July 1.
Sources: ESPN Soccer · ↑ top
S&P 500 7,375.12 ▼ -1.6% Dow 51,899.04 ▲ +0.4% Nasdaq 25,508.01 ▼ -3.2% WTI crude 71.90 ▼ -9.0% EUR/USD 1.1382 ▼ -1.3% GBP/USD 1.3200 ▼ -0.8% USD/JPY 161.70 ▲ +0.6%