================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Monday, July 6, 2026 - 9:06 PM EDT ================================================================ Attackers pounce on fresh NetScaler and ColdFusion flaws as a 16-year-old Linux KVM bug lets guest machines escape to their host. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Autonomous AI browsing agents were hijacked by indirect prompt injections planted on malicious sites to divert cryptocurrency payments away from the users they act for. see: AI Agents Turned Against Their Users * [TREND] Criminals leaned on trusted channels, impersonating IT staff over Microsoft Teams voice calls to deploy EtherRAT while weaponizing OAuth device-code phishing for access. see: Social Engineering Over Trusted Channels * [TREND] France's ANSSI will stop certifying products without quantum-resistant encryption from 2027, landing the same day OpenSSH shipped a post-quantum signature option. see: France Mandates Quantum-Safe Encryption * [UPDATE (new)] Exploitation surged as attackers hit Citrix's new NetScaler memory-disclosure flaw and Adobe ColdFusion CVE-2026-48282 within hours, while researchers disclosed the Januscape KVM host-escape. see: NetScaler and ColdFusion Under Active Attack; 16-Year-Old KVM Escape and Bad Epoll PoC * [UPDATE (new)] Check Point tied a new modular C2 framework, Cavern, to Iran's intelligence ministry targeting Israeli IT providers and government bodies. see: Iran's Cavern C2 and Operation DragonReturn SECURITY ---------------------------------------------------------------- 1. SOCIAL ENGINEERING OVER TRUSTED CHANNELS Ransomware and Cybercrime · [phishing, social-engineering, fraud] Latest developments: Threat actors on July 6 were impersonating corporate IT staff over Microsoft Teams voice calls to push EtherRAT for initial network access, while Kaspersky's Securelist detailed device-code phishing that weaponizes OAuth 2.0's Device Authorization Grant through a legitimate Microsoft site, a campaign impersonated Adobe, Netflix, and OpenAI in fake job interviews to steal Google credentials from marketers, and Frank on Fraud recounted a digital-arrest scam whose fake night officer watched a college professor sleep over Teams to drain her savings. Each attack rides a trusted brand or channel—Teams, OAuth, a job offer, a police impersonation—to bypass technical controls through the user. Organizations should verify IT contacts out of band and train staff on device-code and consent-phishing lures. - BleepingComputer: https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/ - Securelist (Kaspersky): https://securelist.com/microsoft-device-code-phishing-attack/120350/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/ - Frank on Fraud: https://frankonfraud.com/fake-police-watched-her-sleep-then-stole-her-life-savings/ 2. NETSCALER AND COLDFUSION UNDER ACTIVE ATTACK Vulnerabilities and Exploits · [exploit, patch, zero-day] Latest developments: Researchers published a proof-of-concept for Citrix's newest NetScaler memory-disclosure flaw on July 6 and attackers began hitting it within hours, as KEVIntel confirmed exploitation of maximum-severity Adobe ColdFusion flaw CVE-2026-48282 and Sysdig caught probes against Gitea Docker flaw CVE-2026-20896 thirteen days after its patch. The CitrixBleed-style flaw leaks memory from NetScaler ADC and Gateway appliances, echoing the 2023 bug that fueled mass ransomware intrusions; the Gitea flaw carries a 9.8 rating for trusting the X-WEBAUTH-USER header from any client. Administrators should patch all three at once and rotate exposed credentials. - Dark Reading: https://www.darkreading.com/vulnerabilities-threats/citrixbleed-ing-again-netscaler-vulnerability-under-attack - BleepingComputer: https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/ - The Hacker News: https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html 3. IRAN'S CAVERN C2 AND OPERATION DRAGONRETURN Nation-State Activity · [apt, espionage, phishing] Latest developments: Check Point Research on July 6 attributed a previously undocumented modular C2 framework called Cavern to a cluster tied to Iran's Ministry of Intelligence and Security that targets Israeli IT providers and government bodies, as Seqrite Labs detailed Operation DragonReturn, a suspected China-nexus campaign phishing Indian taxpayers with a fake Income Tax Department of India utility to drop DcRAT, and Ukraine reported fresh Russian attacks on its television media. State-aligned crews across Iran, China, and Russia are building custom frameworks and impersonating tax authorities to breach government, IT-provider, and media targets. Defenders in those sectors should treat tax-season lures and third-party IT access as high risk. - The Hacker News: https://thehackernews.com/2026/07/iran-linked-hackers-use-new-cavern-c2.html - The Hacker News: https://thehackernews.com/2026/07/suspected-china-nexus-hackers-use-fake.html - The Record: https://therecord.media/ukraine-media-organizations-priority-hacking-targets-russia 4. AI AGENTS TURNED AGAINST THEIR USERS AI Security · [ai, prompt-injection, ransomware] Latest developments: SecurityWeek reported July 6 two campaigns embedding indirect prompt injections in malicious websites to trick autonomous AI browsing agents into making cryptocurrency payments, as Hong Kong University of Science and Technology researchers unveiled SkillCloak, a self-extracting packing trick that slips malicious AI-agent skills past every scanner tested more than 90 percent of the time, and Dark Reading recounted JadePuffer, the first ransomware intrusion a large language model ran end to end via a Langflow flaw. Attackers now aim at the AI agents themselves—their prompts, their skills, and their autonomy. Teams deploying browsing or coding agents should constrain payment and shell permissions and add runtime skill checks. - SecurityWeek: https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/ - The Hacker News: https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html - Dark Reading: https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack 5. 16-YEAR-OLD KVM ESCAPE AND BAD EPOLL POC Vulnerabilities and Exploits · [vulnerability, patch, linux] Latest developments: The Hacker News disclosed Januscape (CVE-2026-53359) on July 6, a 16-year-old use-after-free in the shadow-MMU code KVM shares across Intel and AMD that lets a guest virtual machine corrupt and escape to its host kernel, the same day SecurityWeek reported a public proof-of-concept for the Linux Bad Epoll root-escalation flaw. Januscape's released proof-of-concept panics the host, and the researcher claims a separate unreleased exploit achieves full escape; Bad Epoll, tracked as CVE-2026-46242, hands any unprivileged user root across desktops, servers, and Android. Cloud and virtualization operators should apply the KVM and kernel patches now. - The Hacker News: https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html - SecurityWeek: https://www.securityweek.com/proof-of-concept-exploit-released-for-linux-bad-epoll-root-access-vulnerability/ 6. FRANCE MANDATES QUANTUM-SAFE ENCRYPTION Policy and Regulation · [policy, encryption, quantum] Latest developments: France's cybersecurity agency ANSSI said July 6 it will stop certifying security products that lack quantum-resistant encryption starting in 2027, forcing government bodies and critical operators off older systems, the same day OpenSSH shipped version 10.4 with eight security fixes and a new post-quantum signature option. The moves push post-quantum cryptography from roadmap to requirement ahead of harvest-now-decrypt-later threats, extending the urgency Microsoft flagged in accelerating its own quantum-safe timeline. Operators should inventory the encryption in use and prioritize quantum-safe replacements. - Schneier on Security: https://www.schneier.com/blog/archives/2026/07/france-to-stop-certifying-non-quantum-safe-encryption.html - Help Net Security: https://www.helpnetsecurity.com/2026/07/06/openssh-10-4-released/ BUSINESS AND POLITICS ---------------------------------------------------------------- * Iran Fires Missiles at Ships in the Strait of Hormuz Latest developments: Iran's Revolutionary Guard opened a new front, firing missiles at vessels in the Strait of Hormuz, an escalation beyond the Khamenei funeral that had dominated the war's coverage. Iran's Islamic Revolutionary Guard Corps fired missiles at ships transiting the Strait of Hormuz, the chokepoint for roughly a fifth of the world's seaborne oil, a strike that threatens talks to end the U.S. war with Iran and firmed crude prices. - WSJ World News: https://www.wsj.com/world/middle-east/irgc-fires-missiles-at-ships-in-strait-of-hormuz-c3fbadd0 * Germany to Borrow 800 Billion Euros to Rearm Latest developments: Chancellor Friedrich Merz committed Germany to 800 billion euros in debt-financed rearmament, the largest borrowing push since reunification. Germany's Chancellor Friedrich Merz will borrow 800 billion euros to rebuild the country's military, a debt-fueled shift on a scale unseen since reunification, as Europe moves to stand on its own amid the rupture with Washington. - FT World: https://www.ft.com/content/72878c3e-a4c6-4e4d-86c1-6df11593e4ac * China Test-Fires Long-Range Missile Into the Pacific Latest developments: A Chinese nuclear submarine test-launched a long-range ballistic missile carrying a dummy warhead into a Pacific nuclear-free zone. A Chinese nuclear submarine test-fired a submarine-launched long-range ballistic missile into a Pacific nuclear-free zone, drawing condemnation from Japan, Australia, and New Zealand while Beijing sought to play the launch down. - FT World: https://www.ft.com/content/c52f0a98-2e6a-4acc-a668-d4ce442c4aba PITTSBURGH ---------------------------------------------------------------- Weather: Tonight: Chance Showers And Thunderstorms then Patchy Fog, low 68F. Tuesday: Chance Showers And Thunderstorms, high 86F. Tuesday Night: Showers And Thunderstorms Likely, low 68F. Business: * Data Centers Divide Southwestern Pennsylvania Latest developments: With several data centers proposed across southwestern Pennsylvania, residents and developers clashed publicly over whether the projects justify their strain on the grid. Communities around Pittsburgh, including Springdale resident Matt Lang, are fighting proposed data centers over fears of noise, water and air pollution, higher electric bills, and power outages, while backers cast them as the building blocks of a new economy. - KDKA: https://www.cbsnews.com/pittsburgh/news/data-centers-projects-pittsburgh-area/ * Best of the Batch Foundation Rebuilds After Fire Latest developments: Six days after a fire damaged its Munhall building, Charlie Batch's Best of the Batch Foundation began cleanup and appealed publicly for help. The Best of the Batch Foundation, the Munhall nonprofit run by former Steelers quarterback Charlie Batch, is cleaning up and asking for donations after a fire destroyed parts of its building. - KDKA: https://www.cbsnews.com/pittsburgh/video/best-of-the-batch-foundation-asking-for-help-after-fire-damages-building/ Around town: * Parkway East Closes for 25 Days Latest developments: With the closure days away, PennDOT posted detours and Regent Square and Swissvale neighbors warned that rerouting a road carrying 100,000 vehicles a day through their streets will snarl traffic. PennDOT will shut the Parkway East, Interstate 376, between the Squirrel Hill Tunnel and the Edgewood/Swissvale exit for 25 days to replace the Commercial Street Bridge near Frick Park, pushing roughly 100,000 vehicles a day onto detours through Regent Square and Swissvale. - KDKA: https://www.cbsnews.com/pittsburgh/news/parkway-east-commercial-street-bridge-detour-worries/ * Sinkhole Shuts Road at UPMC Passavant Latest developments: A storm-driven sinkhole opened in front of UPMC Passavant in McCandless, and the township and hospital, disputing who owns the failed drain, said repairs could take weeks. A large sinkhole from storm runoff closed part of the road in front of UPMC Passavant hospital near Babcock Boulevard in McCandless Township, where leaders said the drain belongs to the hospital and coordination on repairs is under way. - WPXI: https://www.wpxi.com/news/local/mccandless-sinkhole-caused-by-storm-could-take-weeks-fix/436NPPT4RBCFVBSLHOWMMPZE3M/ * Sandcastle Adds Chaperone Rule for Teens Latest developments: Starting Friday, Sandcastle will require guests 15 and under to bring an adult, matching a policy sister park Kennywood adopted earlier this summer. Sandcastle water park will require anyone 15 or under to be chaperoned by someone 21 or older beginning Friday, checking IDs at the gate and capping each chaperone at six minors, mirroring rules already in place at sister park Kennywood. - KDKA: https://www.cbsnews.com/pittsburgh/news/sandcastle-chaperone-policy/ SPORTS ---------------------------------------------------------------- Pirates (46-45) Sun Jul 5 · Pirates 11 · Nationals 5 · Final Griffin's big day leads the Pirates to an 11-5 win over the Nationals https://plaintextsports.com/mlb/2026-07-05/pit-wsh Up Next · Braves @ Pirates · Tue Jul 7, 6:40 PM https://plaintextsports.com/mlb/2026-07-07/atl-pit Around the Teams: * Steelers Show Ranks NFL Rosters Latest developments: On the July 6 SNR Drive, Matt Williamson and Wes Uhler broke down ESPN's ranking of all 32 NFL projected starting lineups and Jon Ledyard's list of the league's top 35 defensive tackles. The Pittsburgh Steelers' SNR Drive, hosted by Matt Williamson and Wes Uhler, reviewed ESPN's rankings of all 32 NFL rosters and debated where the league's best defensive linemen land, drawing on Jon Ledyard's top-35 list. - Pittsburgh Steelers (YouTube): https://www.youtube.com/watch?v=ybC3uZjrxMc * Pirates Feel Snubbed on All-Star Roster Latest developments: The Post-Gazette reported the Pirates believe Brandon Lowe and Braxton Ashcraft deserved All-Star nods alongside lone selection Paul Skenes, holding out hope both still make the National League roster. The Pittsburgh Pirates said they are disappointed that Brandon Lowe and pitcher Braxton Ashcraft missed the initial National League All-Star roster, leaving ace Paul Skenes as the club's only selection for a third straight year. - Post-Gazette Pirates: https://www.post-gazette.com/sports/2026/07/06/mlb-all-star-game-brandon-lowe-braxton-ashcraft-paul-skenes/stories/202607050090 * Prospect Stafura Rises as Hayes Trade Ages Well Latest developments: The Post-Gazette's MiLB Monday flagged prospect Sammy Stafura's surging bat and argued the Ke'Bryan Hayes trade looks better as its returns develop. The Post-Gazette's MiLB Monday column highlighted Pirates prospect Sammy Stafura's power surge in the minors and made the case that the deal sending third baseman Ke'Bryan Hayes away keeps paying off for Pittsburgh. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/07/06/milb-minor-leagues-stafura-kebryan-moss-hernandez/stories/202607060024 Team USA: * Balogun Starts as U.S. Meets Belgium Latest developments: Coach Mauricio Pochettino named the cleared Folarin Balogun in the United States' starting XI for the World Cup round-of-16 match against Belgium in Seattle. The United States opened its World Cup round-of-16 match against Belgium in Seattle with striker Folarin Balogun in the lineup, days after FIFA's disciplinary committee lifted the red-card suspension he drew against Bosnia and Herzegovina. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49289290/folarin-balogun-named-starting-xi-us-vs-belgium - Guardian World Cup 2026: https://www.theguardian.com/football/live/2026/jul/06/usa-v-belgium-world-cup-2026-last-16-live * Trump's FIFA Call Splits Soccer's Governing Bodies Latest developments: President Trump confirmed he phoned FIFA president Gianni Infantino to seek review of Balogun's red card, prompting UEFA to accuse FIFA of crossing 'a red line' and Infantino to defend the body's integrity. President Trump said he called FIFA president Gianni Infantino to review Folarin Balogun's suspension, and after FIFA reversed it, European federation UEFA said the governing body 'crossed a red line' while Infantino defended FIFA's integrity. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49286603/us-president-donald-trump-confirms-asked-fifa-review-balogun-red-card - Guardian World Cup 2026: https://www.theguardian.com/football/2026/jul/06/uefa-fifa-folarin-balogun-controversy-decision-usa-belgium-gianni-infantino-aleksander-ceferin READING ---------------------------------------------------------------- * Ed Zitron -- Premium: The Hater's Guide To SoftBank A caustic dissection of SoftBank and Masayoshi Son's finances, arguing the conglomerate's chaotic 46th shareholder meeting and grandiose AI slides mask an overleveraged, shaky bet. https://www.wheresyoured.at/premium-the-haters-guide-to-softbank/ * Stratechery -- An Interview with Figma CEO Dylan Field About Design and AI Figma chief executive Dylan Field discusses building the design platform and makes the case that AI is a tailwind for the company rather than a threat. https://stratechery.com/2026/an-interview-with-figma-ceo-dylan-field-about-design-and-ai/ * Cal Newport -- Beware of Productivity Paradoxes Newport argues that powerful new tools like the personal computer often fail to deliver the productivity gains they promise, a warning against assuming AI will automatically make knowledge work more efficient. https://calnewport.com/beware-of-productivity-paradoxes/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,488.74 ▲ +1.5% Dow 52,552.63 ▲ +1.4% Nasdaq 26,005.54 ▲ +1.7% WTI crude 69.35 ▼ -5.5% EUR/USD 1.1415 ▲ +0.3% GBP/USD 1.3295 ▲ +0.7% USD/JPY 162.00 ▲ +0.2% ================================================================ Generated 2026-07-06 21:06 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================