daily plain-text briefing: security, markets, business, and pittsburgh
A credential-theft campaign that pried open some 75,000 Fortinet firewalls now feeds the INC and Lynx ransomware gangs, while an 81-million-attempt password spray batters Azure CLI and vendors rush out maximum-severity patches.
Latest developments: Dark Reading declared ClickFix the dominant malware-delivery technique across current attacks, as separate research found phishing kits fingerprinting a victim's user-agent data to serve OS-specific payloads, Securonix detailed the VEIL#DROP chain dropping the PureLogs stealer through Blogger pages, and BleepingComputer flagged ChocoPoC, a Python remote-access trojan hidden in trojanized GitHub proof-of-concept exploits aimed at security researchers.
Social-engineering delivery keeps evolving, with ClickFix's fake human-verification prompts now the norm and campaigns tailoring payloads to each victim's device. Defenders should block manual command-paste tricks, scrutinize proof-of-concept code, and train staff on the ClickFix pattern.
Sources: Dark Reading · Dark Reading · The Hacker News · BleepingComputer · ↑ top
Latest developments: Adobe patched seven maximum-severity CVSS 10.0 flaws in ColdFusion and Campaign Classic on July 1, Citrix fixed six NetScaler bugs including the new HTTP/2 Bomb and a CitrixBleed-style information-disclosure flaw, Apple issued dozens of iOS, macOS, and Safari fixes, and Google closed 382 Chrome vulnerabilities.
Four major vendors released critical updates in one day, the Adobe and Citrix flaws opening paths to code execution, file reads, and denial of service. Administrators should apply the ColdFusion, NetScaler, Apple, and Chrome patches immediately.
Sources: SecurityWeek · SecurityWeek · SecurityWeek · SecurityWeek · ↑ top
Latest developments: Palo Alto Networks' Unit 42 documented phantom squatting, where attackers register the web addresses large language models hallucinate and host phishing pages to catch misdirected traffic; researchers used DeepSeek to build working browser ransomware abusing the Chromium API on Windows and Android; and Cato AI Labs disclosed DuneSlide, two 9.8-rated Cursor flaws, CVE-2026-50548 and CVE-2026-50549, that let a single prompt escape the AI editor's sandbox and run commands.
Three separate findings show frontier AI powering offensive operations, from squatting on invented domains to generating novel ransomware and hijacking a developer's machine through prompt injection. Enterprises should watch for AI-suggested domains, restrict Cursor's command execution, and treat AI-generated code as untrusted.
Sources: The Hacker News · The Hacker News · The Hacker News · Dark Reading · ↑ top
Latest developments: Huntress reported an automated password-spray campaign that fired more than 81 million login attempts at Microsoft's Azure command-line interface between June 12 and June 26, compromising at least 78 accounts, all traced to an IPv6 range LSHIY LLC controls under AS32167.
Attackers hammered Azure CLI and Microsoft 365 logins from LSHIY infrastructure in the range 2a0a:d683::/32, breaking into dozens of accounts. Administrators should enforce multi-factor authentication and block the offending address range.
Sources: The Hacker News · SecurityWeek · BleepingComputer · ↑ top
Latest developments: CISA added Microsoft SharePoint Server deserialization flaw CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on July 1, eSentire's Threat Response Unit flagged active exploitation attempts against Progress Kemp LoadMaster command-injection flaw CVE-2026-8037, and BleepingComputer counted over 900 exposed Oracle E-Business Suite instances under attack through CVE-2026-46817.
Attackers are actively hitting three enterprise products, with CISA's SharePoint listing binding federal agencies to patch and roughly 900 Oracle E-Business Suite servers left exposed online. Teams should patch all three and check for web shells and rogue accounts.
Sources: CISA Advisories · The Hacker News · BleepingComputer · ↑ top
Latest developments: BleepingComputer tied the FortiBleed campaign to the INC and Lynx ransomware operations on July 1, indicating the stolen Fortinet credentials will seed future network intrusions.
FortiBleed pried open roughly 75,000 Fortinet firewalls and harvested credentials that the INC and Lynx gangs will likely use to break into corporate networks. Organizations running Fortinet gear should rotate credentials, audit access, and expect fallout for years.
Sources: BleepingComputer · Graham Cluley · ↑ top
Tonight: Clear, low 74F.
Thursday: Sunny, high 99F.
Thursday Night: Mostly Clear, low 77F.
Pirates (43-43)
Tue Jun 30 · Pirates 0 · Phillies 8 · Final
Sánchez fans 9 in 7 innings, becomes 1st starter to reach 10 wins in 8-0 victory over Pirates
Wed Jul 1 · Pirates 4 · Phillies 8 · Bot 6th (in progress at last update)
Up Next · Pirates @ Phillies · Thu Jul 2, 12:35 PM
S&P 500 7,426.91 = +0.0% Dow 52,120.78 ▲ +0.9% Nasdaq 25,746.02 ▼ -0.8% WTI crude 70.35 ▼ -6.8% EUR/USD 1.1387 ▼ -0.5% GBP/USD 1.3211 ▼ -0.2% USD/JPY 161.98 ▲ +0.4%