================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Monday, June 29, 2026 - 9:05 PM EDT ================================================================ Washington posted a $10 million bounty on the Russian operatives who hijacked Signal and WhatsApp accounts as ShinyHunters turned Oracle's enterprise software flaws into a breach spree. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] ShinyHunters weaponized Oracle PeopleSoft zero-days within days, stealing Nissan employee records and breaching the National Association of Insurance Commissioners' server in a cascading extortion spree. see: ShinyHunters Mine Oracle PeopleSoft and E-Business Suite * [TREND] Attackers keep poisoning the software supply chain as Microsoft pulled 119 StegoAd Edge extensions and JFrog flagged hijacked npm and Go packages dropping a cross-platform Python infostealer. see: 119 Edge Extensions and Hijacked Packages Spread Malware * [UPDATE (new)] Washington answered state hacking with cash, posting a $10 million reward for the Russian UNC5792 and UNC4221 operatives who phished US officials' Signal and WhatsApp accounts. see: $10 Million Bounty for Russian Messaging-App Hackers * [TREND] Freshly exploited flaws stack up as CISA flags SimpleHelp's CVE-2026-48558 dropping Djinn Stealer, a libssh2 proof-of-concept lands, and Kaspersky details The Gentlemen ransomware crew's new backdoors. see: SimpleHelp Flaw Deploys Djinn Stealer; libssh2 and DirtyClone Open Clients and Kernels; The Gentlemen Ransomware Crew Refines Its Backdoors * [TREND] Tech skeptics dominate today's reading as Cal Newport warns of productivity paradoxes, Figma's Dylan Field calls AI a tailwind, and Ed Zitron catalogs signs of an investment bubble. see: Beware of Productivity Paradoxes; An Interview with Figma CEO Dylan Field About Design and AI; Premium: Notes From The Bubble, Volume 1 * [UPDATE (new)] Pittsburgh property woes mount as Allegheny County moves to void fraudulent deed transfers while Rising Tide Partners' distressed homes still decay five years on. see: Allegheny County Moves to Block Deed Fraud; Rising Tide Partners' Distressed Properties Languish SECURITY ---------------------------------------------------------------- 1. $10 MILLION BOUNTY FOR RUSSIAN MESSAGING-APP HACKERS Nation-State Activity · [apt, policy] Latest developments: The U.S. State Department on June 29 posted a reward of up to $10 million for information identifying or locating members of UNC5792 and UNC4221, the groups tied to Russia's intelligence and military services behind the Signal and WhatsApp account takeovers. UNC5792 and UNC4221 socially engineer their way into the messaging accounts of government officials, military leaders, and allied personnel, a campaign running since at least March 2026. Officials urge targeted users to lock down device-linking and backup recovery keys. - Ars Technica Security: https://arstechnica.com/information-technology/2026/06/us-offers-10-million-for-info-on-group-behind-signal-and-whatsapp-hacking-spree/ - The Record: https://therecord.media/10million-reward-us-russian-hackers-unc4221-unc5792 - BleepingComputer: https://www.bleepingcomputer.com/news/security/us-offers-10-million-for-hackers-targeting-whatsapp-signal-users/ - SecurityWeek: https://www.securityweek.com/us-offers-10-million-bounty-for-russian-state-hackers-as-messaging-app-attacks-evolve/ 2. SHINYHUNTERS MINE ORACLE PEOPLESOFT AND E-BUSINESS SUITE Data Breaches · [breach, zero-day, extortion] Latest developments: Nissan disclosed June 29 that attackers exploiting an Oracle PeopleSoft zero-day stole current and former employee data, the National Association of Insurance Commissioners confirmed ShinyHunters breached its PeopleSoft server while the group claimed 3.1 terabytes, and Defused reported fresh exploitation of a separate critical Oracle E-Business Suite flaw, CVE-2026-46817. The ShinyHunters extortion group chains Oracle enterprise software flaws to steal corporate and regulator data, with PeopleSoft and the E-Business Suite financial application now both under active attack. Affected organizations should apply Oracle's emergency fixes and hunt for data-theft indicators. - BleepingComputer: https://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/naic-says-public-data-stolen-in-shinyhunters-peoplesoft-breach/ - SecurityWeek: https://www.securityweek.com/insurance-regulators-group-naic-hit-in-oracle-peoplesoft-hack/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-flaw-now-exploited-in-attacks/ 3. SIMPLEHELP FLAW DEPLOYS DJINN STEALER Vulnerabilities and Exploits · [patch, infostealer, kev] Latest developments: CISA added CVE-2026-48558, a critical authentication-bypass flaw in SimpleHelp remote-support software, to its Known Exploited Vulnerabilities catalog June 29 as attackers used it to drop Djinn Stealer and the TaskWeaver loader. Djinn Stealer is a previously undocumented cross-platform infostealer hitting Windows, macOS, and Linux, targeting cloud and AI credentials that link development and admin environments to wider enterprise systems. SimpleHelp operators must patch immediately under CISA's binding directive. - Dark Reading: https://www.darkreading.com/cyberattacks-data-breaches/djinn-stealer-targets-cloud-ai-credentials - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-simplehelp-flaw-deploy-new-djinn-infostealer-taskweaver-malware/ - CISA Advisories: https://www.cisa.gov/news-events/alerts/2026/06/29/cisa-adds-one-known-exploited-vulnerability-catalog 4. LIBSSH2 AND DIRTYCLONE OPEN CLIENTS AND KERNELS Vulnerabilities and Exploits · [vulnerability, patch, poc] Latest developments: A public proof-of-concept dropped June 29 for CVE-2026-55200, a critical libssh2 flaw that lets a malicious SSH server corrupt a connecting client's memory without credentials or interaction, the same day SecurityWeek detailed DirtyClone, a DirtyFrag variant that gives unprivileged Linux users root by manipulating the page cache, and PTC's advisory confirmed JSP webshells dropping on unpatched Windchill instances. CVE-2026-55200 affects every libssh2 release through 1.11.1 at CVSS 9.2, exposing any tool that links the client-side library, while DirtyClone and the Windchill CVE-2026-12569 webshells add local-root and remote-code-execution risk. Administrators should rebuild against patched libssh2, apply kernel fixes, and pull Windchill indicators of compromise. - The Hacker News: https://thehackernews.com/2026/06/public-poc-released-for-critical.html - SecurityWeek: https://www.securityweek.com/dirtyclone-linux-kernel-vulnerability-leads-to-root-access/ - Help Net Security: https://www.helpnetsecurity.com/2026/06/29/ptc-windchill-cve-2026-12569-exploited/ 5. 119 EDGE EXTENSIONS AND HIJACKED PACKAGES SPREAD MALWARE Ransomware and Cybercrime · [supply-chain, infostealer, adware] Latest developments: Microsoft removed 119 Edge Add-ons it ties to a single actor active since 2021, a campaign it calls StegoAd that hides payloads inside image and font files before waking days later to steal credentials and run ad fraud, while JFrog found two hijacked npm packages and a cluster of Go packages abusing VS Code tasks to deploy a Python infostealer. Both operations smuggle malware past store and registry defenses, StegoAd through steganography in benign-looking files and the package attack by avoiding npm lifecycle scripts to dodge npm v12 hardening. Developers and users should audit installed extensions and pin dependency sources. - The Hacker News: https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html - The Hacker News: https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html 6. THE GENTLEMEN RANSOMWARE CREW REFINES ITS BACKDOORS Ransomware and Cybercrime · [ransomware, raas] Latest developments: Kaspersky researchers published June 29 an analysis of incidents tied to The Gentlemen ransomware-as-a-service group, disclosing its custom backdoors and tradecraft and flagging a new ransomware variant. The Gentlemen runs a ransomware-as-a-service operation built around bespoke backdoors and evolving tactics. Kaspersky's tools, techniques, and indicators give defenders detection signatures for the group's intrusions. - Securelist (Kaspersky): https://securelist.com/the-gentlemen-raas/120447/ BUSINESS AND POLITICS ---------------------------------------------------------------- * Supreme Court Expands Trump's Removal Power, Spares the Fed Latest developments: The Supreme Court ruled June 29, letting President Trump fire the heads of independent agencies at will while blocking his attempt to remove Federal Reserve governor Lisa Cook. The 6-3 decision exposes dozens of federal agencies to presidential control and strikes down long-standing for-cause removal protections; it carves out the Federal Reserve and keeps Cook in her seat after Trump moved to oust her. - WSJ US Business: https://www.wsj.com/politics/policy/supreme-court-blocks-trumps-bid-to-fire-lisa-cook-4fcc3569?mod=pls_whats_news_us_business_f - The Economist: https://www.economist.com/united-states/2026/06/29/the-supreme-court-has-handed-donald-trump-yet-more-power PITTSBURGH ---------------------------------------------------------------- Weather: Tonight: Mostly Clear, low 71F. Tuesday: Mostly Sunny, high 94F. Tuesday Night: Partly Cloudy, low 76F. Business: * Rising Tide Partners' Distressed Properties Languish Latest developments: KDKA reported June 29 that hundreds of distressed properties Rising Tide Partners bought to revive Pittsburgh neighborhoods still sit decaying five years on. Rising Tide Partners, a Pittsburgh nonprofit led by chief executive Diamonte Walker, has acquired hundreds of distressed properties since 2021 promising neighborhood revival; residents near its Homewood holdings say the buildings keep decaying. - KDKA: https://www.cbsnews.com/pittsburgh/news/rising-tide-partners-pittsburgh/ * Swissvale Businesses Brace for Parkway East Closure Latest developments: WTAE reported June 29 that Swissvale business owner Dave Guerin warns a coming 25-day Parkway East closure will choke deliveries and supplier routes. A planned 25-day closure of the Parkway East, Interstate 376 east of Pittsburgh, threatens deliveries for businesses in Swissvale, where owner Dave Guerin says detours will complicate suppliers' access. - WTAE: https://www.wtae.com/article/swissvale-business-concerns-parkway-east-closure/71773450 * Allegheny County Moves to Block Deed Fraud Latest developments: WPXI's 11 Investigates reported June 29 that Allegheny County filed court paperwork to halt deed transfers to the LLCs tied to a wave of fraudulent property transfers. Allegheny County is seeking a court order to block any deed transfers to limited-liability companies connected to recent deed-fraud cases, after a Pittsburgh real estate agent documented dozens of fraudulent transfers concentrated on the South Side. - WPXI: https://www.wpxi.com/news/local/allegheny-county-takes-steps-prevent-further-deed-fraud/4V33Q7HAGNE7LPZB7BXZFZP5MA/ Around town: * Commercial Street Closes for Bridge Replacement Latest developments: KDKA reported June 29 that Commercial Street officially closed as the bridge-replacement project near Frick Park entered its construction phase, a shutdown expected to last about five weeks. PennDOT closed Commercial Street in Pittsburgh's Swisshelm Park neighborhood for roughly five weeks so crews can replace the bridge carrying it near Frick Park, rerouting local traffic through surrounding streets. - KDKA: https://www.cbsnews.com/pittsburgh/news/commercial-street-closed-parkway-east-bridge-replacement/ * Justice Department Sues Pennsylvania Over SNAP Data Latest developments: The U.S. Justice Department sued Pennsylvania, Kentucky, Michigan, and Minnesota on June 29 for refusing to hand the Agriculture Department data on food-stamp applicants. The Justice Department alleges the four states withheld five years of Supplemental Nutrition Assistance Program applicant records the U.S. Department of Agriculture sought to verify residents' eligibility and household benefit levels. - KDKA: https://www.cbsnews.com/pittsburgh/news/doj-lawsuit-michigan-minnesota-kentucky-pennsylvania-snap-data/ * Monroeville Library Pulls Pride Display Latest developments: WTAE reported June 29 that the Monroeville Public Library removed its Pride Month children's book display after local officials demanded it. The Monroeville Public Library took down a Pride Month book display in its children's room after Monroeville Councilman Bill Krut called the books 'sexual grooming' in a June 19 Facebook post, ending a rotation the library uses to mark different communities. - WTAE: https://www.wtae.com/article/monroeville-library-removes-pride-month-display-officials-request/71775356 SPORTS ---------------------------------------------------------------- Pirates (42-42) Sun Jun 28 · Reds 4 · Pirates 9 · Final Ryan O'Hearn homers twice, helps Pirates avoid sweep with 9-4 win over Reds https://plaintextsports.com/mlb/2026-06-28/cin-pit Mon Jun 29 · Pirates 8 · Phillies 5 · Bot 8th (in progress at last update) https://plaintextsports.com/mlb/2026-06-29/pit-phi Up Next · Pirates @ Phillies · Tue Jun 30, 6:40 PM https://plaintextsports.com/mlb/2026-06-30/pit-phi Around the Teams: * Steelers Face Joey Porter Jr. Contract Puzzle Latest developments: In a June 29 Post-Gazette video, beat writer Gerry Dulac weighed how complicated the Steelers' contract negotiations with cornerback Joey Porter Jr. could become. Gerry Dulac broke down the looming extension talks between the Pittsburgh Steelers and cornerback Joey Porter Jr., assessing how complex a long-term deal for the young defender may prove. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/06/29/nfl-news-rumors-joey-porter-jr-contract-gerry-dulac/stories/202606290035 * Hiles: Pirates Should Look Within for Bullpen Help Latest developments: Post-Gazette columnist Noah Hiles argued June 29 that internal arms could fix the Pirates' bullpen better than trade-deadline acquisitions. In his weekend column, Noah Hiles wrote that the Pittsburgh Pirates can shore up a shaky bullpen by leaning on relievers already in the organization, naming Dennis Santana and Isaac Mattson, ahead of the trade deadline. - Post-Gazette Pirates: https://www.post-gazette.com/sports/columns/2026/06/29/mlb-pirates-dennis-santana-isaac-mattson/stories/202606280071 Team USA: * Sebastian Berhalter Scores in US Win Over Türkiye Latest developments: ESPN reported June 30 that Sebastian Berhalter scored his first World Cup goal in the United States' group-stage win over Türkiye, moving his father, former U.S. coach Gregg Berhalter, to tears. Midfielder Sebastian Berhalter, son of former U.S. men's national team coach Gregg Berhalter, scored for the United States against Türkiye in the World Cup group stage, a goal that left his father, now Chicago Fire manager, in tears. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49219089/gregg-berhalter-tears-son-sebastian-scores-world-cup-goal * Analysts See USMNT as World Cup Dark Horse Latest developments: ESPN convened coaches and analysts June 29 who judged the United States capable of a surprise deep run after a strong group stage as co-host. A panel ESPN assembled of coaches and analysts weighed whether the United States men's national team can become the 2026 World Cup's surprise package, citing its group-stage form ahead of a round-of-32 meeting with Bosnia and Herzegovina on Wednesday, July 1. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49213271/why-outsiders-believe-usmnt-make-deep-world-cup-run READING ---------------------------------------------------------------- * Cal Newport -- Beware of Productivity Paradoxes Newport argues that technologies poised to be productivity slam dunks, like the personal computer, often failed to deliver straightforward gains, a caution he applies to today's claims for AI. https://calnewport.com/beware-of-productivity-paradoxes/ * Stratechery -- An Interview with Figma CEO Dylan Field About Design and AI Field discusses how he built Figma and why he believes AI works as a tailwind for the company rather than a threat to design tools. https://stratechery.com/2026/an-interview-with-figma-ceo-dylan-field-about-design-and-ai/ * Ed Zitron -- Premium: Notes From The Bubble, Volume 1 Zitron launches an ongoing series cataloguing what he reads as mounting warning signs of an AI investment bubble across the tech industry. https://www.wheresyoured.at/premium-notes-from-the-bubble-volume-1/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,375.12 ▼ -1.6% Dow 51,899.04 ▲ +0.4% Nasdaq 25,508.01 ▼ -3.2% WTI crude 71.90 ▼ -9.0% EUR/USD 1.1382 ▼ -1.3% GBP/USD 1.3200 ▼ -0.8% USD/JPY 161.70 ▲ +0.6% ================================================================ Generated 2026-06-29 21:05 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================