================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Tuesday, July 7, 2026 - 4:05 PM EDT ================================================================ Attackers weaponized critical Adobe ColdFusion and Gitea flaws within minutes of public analysis as CISA flagged three more vulnerabilities under active exploitation. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Attackers weaponized freshly disclosed CVEs within minutes, hitting Adobe ColdFusion moments after watchTowr's analysis and actively exploiting a Gitea authentication bypass. see: Adobe ColdFusion and Gitea Flaws Exploited in the Wild * [TREND] Enterprise AI cut both ways as Varonis exposed a Google Dialogflow CX cross-tenant flaw while criminals rented RedWing Android bank-fraud kits and abused Gemini for phishing. see: AI Agent Platforms Spring Cross-Tenant Leaks; Rented Bank-Fraud Kits and AI-Powered Phishing * [TREND] China-linked UAT-7810 deployed new LONGLEASH malware to expand its operational relay box network by compromising unpatched Ruckus routers and other internet-facing gear. see: UAT-7810 Builds ORB Network With LONGLEASH * [UPDATE (new)] A small Ohio county paid roughly $1 million to extortionists the same day a major Japanese telecom disclosed a breach exposing 12 million emails. see: Ohio County Extortion and Japanese Telco Breach * [UPDATE (new)] PennDOT prepped drivers for the 25-day Parkway East closure starting Friday while reopening the 62nd Street Bridge after a Sharpsburg hazmat spill. see: PennDOT Details Parkway East Demolition; 62nd Street Bridge Reopens After Hazmat Spill SECURITY ---------------------------------------------------------------- 1. ADOBE COLDFUSION AND GITEA FLAWS EXPLOITED IN THE WILD Vulnerabilities and Exploits · [exploit, patch, zero-day] Latest developments: SecurityWeek and KEVIntel confirmed July 7 that attackers exploit maximum-severity Adobe ColdFusion flaw CVE-2026-48282 in the wild—strikes landed minutes after watchTowr published its analysis—while researchers confirmed active exploitation of Gitea authentication-bypass flaw CVE-2026-20896, and CISA added the JoomShaper SP Page Builder, Langflow, and Joomlack Page Builder flaws to its Known Exploited Vulnerabilities catalog. Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) and Gitea CVE-2026-20896 both hand attackers control of vulnerable servers, and the Langflow authorization bypass CVE-2026-55255 sits in the same AI platform behind recent JadePuffer ransomware. Patch all three now. - SecurityWeek: https://www.securityweek.com/critical-adobe-coldfusion-vulnerability-exploited-in-attacks/ - SecurityWeek: https://www.securityweek.com/critical-gitea-flaw-under-active-exploitation-researchers-warn/ - CISA Advisories: https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog - Help Net Security: https://www.helpnetsecurity.com/2026/07/07/adobe-coldfusion-cve-2026-48282-exploitation-detected/ 2. AI AGENT PLATFORMS SPRING CROSS-TENANT LEAKS AI Security · [ai, vulnerability] Latest developments: Varonis disclosed a critical Google Dialogflow CX flaw that lets an attacker holding edit rights on one Code Block-enabled agent hijack every such agent in the same Google Cloud project to read live conversations, steal shared data, and send attacker-written messages, as Dark Reading branded the GitHub Agentic Workflows private-data leak 'GitLost.' The Dialogflow CX bug and the GitLost flaw show autonomous AI agents leaking private data across tenant and repository boundaries with no stolen credentials. Google patched Dialogflow CX, and GitHub organizations should restrict agent read access. - The Hacker News: https://thehackernews.com/2026/07/rogue-agent-flaw-could-have-let.html - Dark Reading: https://www.darkreading.com/cyber-risk/gitlost-leaks-private-data-github-agentic-workflows - The Hacker News: https://thehackernews.com/2026/07/public-github-issue-could-trick-github.html 3. RENTED BANK-FRAUD KITS AND AI-POWERED PHISHING Ransomware and Cybercrime · [phishing, malware, fraud] Latest developments: Zimperium's zLabs detailed RedWing, an Android bank-fraud service rented on Telegram as a variant of the $300-a-month Oblivion tool that lets low-skill criminals hijack phones and grab one-time codes, as Google sued the Telegram-based Outsider Enterprise for using Gemini to build fake Google and YouTube phishing sites, and ZeroBEC tracked the DEBULL campaign abusing Microsoft's device-code login flow to seize Microsoft 365 accounts. Criminal services keep lowering the skill bar—RedWing packages Android bank fraud, Outsider Enterprise sells Gemini-generated phishing kits, and DEBULL weaponizes Microsoft 365 device-code authentication. Enterprises should block device-code flows and enforce phishing-resistant multifactor authentication. - The Hacker News: https://thehackernews.com/2026/07/redwing-maas-packages-android-bank.html - Schneier on Security: https://www.schneier.com/blog/archives/2026/07/google-is-suing-chinese-scammers-who-are-using-gemini.html - The Hacker News: https://thehackernews.com/2026/07/debull-tooling-abuses-microsoft-device.html 4. OHIO COUNTY EXTORTION AND JAPANESE TELCO BREACH Data Breaches · [breach, extortion] Latest developments: SecurityWeek reported July 7 that a small Ohio county government paid roughly $1 million to a cyber-extortion group to stop the release of stolen data, the same day a major Japanese telecom disclosed a breach that exposed 12 million emails from a system serving customer accounts and webmail for five Japanese internet service providers. Two data-theft incidents surfaced: a small Ohio county paid $1 million to prevent publication of stolen files, and a Japanese carrier lost 12 million customer emails from its webmail and storage systems. Both underscore that extortion crews profit from stolen data alone. - SecurityWeek: https://www.securityweek.com/county-government-reportedly-paid-1-million-to-cyber-extortion-group/ - The Record: https://therecord.media/major-japanese-telco-cyberattack-12-million-emails 5. UAT-7810 BUILDS ORB NETWORK WITH LONGLEASH Nation-State Activity · [apt, malware, china] Latest developments: Cisco Talos and BleepingComputer reported July 7 that China-linked actor UAT-7810 built new malware called LONGLEASH to expand its operational relay box network, compromising internet-facing networking gear, chiefly unpatched Ruckus routers. UAT-7810, a China-aligned group, keeps evolving custom malware to conscript edge devices into an ORB relay network that masks the origin of espionage traffic. Organizations should patch Ruckus and other internet-facing routers. - BleepingComputer: https://www.bleepingcomputer.com/news/security/chinese-hackers-develop-longleash-malware-to-expand-orb-network/ - Cisco Talos: https://blog.talosintelligence.com/uat-7810/ BUSINESS AND POLITICS ---------------------------------------------------------------- * U.S. Revokes Iran Oil License After Tanker Strikes Latest developments: The U.S. Treasury canceled the waiver that let Iran sell its oil, retaliating for Tuesday's strikes on three commercial tankers near the Strait of Hormuz and driving crude futures sharply higher. Iran's forces struck three tankers crossing the Strait of Hormuz, the chokepoint for Persian Gulf oil exports, and the U.S. Treasury answered by revoking the authorization that permitted Tehran to sell its crude, jolting global energy markets as producers already race idle wells back online. - WSJ US Business: https://www.wsj.com/world/middle-east/u-s-revokes-waiver-allowing-sale-of-iranian-oil-b6eb5620?mod=pls_whats_news_us_business_f - WSJ US Business: https://www.wsj.com/finance/commodities-futures/oil-rises-on-possible-position-adjustments-before-expected-resumption-of-u-s-iran-talks-ead21cdc?mod=pls_whats_news_us_business_f PITTSBURGH ---------------------------------------------------------------- Weather: This Afternoon: Chance Showers And Thunderstorms, high 86F. Tonight: Chance Showers And Thunderstorms then Areas Of Fog, low 68F. Wednesday: Areas Of Fog then Slight Chance Showers And Thunderstorms, high 89F. Business: * Mixburgh Courts Cocktail Tourism Latest developments: Space Bar owners Dale Vaughn and Elizabeth Menzel are steering the Mixburgh Foundation's coordinated cocktail weekend and conference with VisitPittsburgh to pull drink tourists into the city. The Mixburgh Foundation, run by Space Bar owners Dale Vaughn and Elizabeth Menzel in partnership with VisitPittsburgh, unites local bars, restaurants, and distilleries to market Pittsburgh's spirits and cocktail scene and draw visitors to the region. - Pittsburgh Magazine: https://www.pittsburghmagazine.com/mixburgh-cocktail-weekend-and-conference/ * PIT Donates Lost Items, Readies Auction Latest developments: Pittsburgh International Airport donated 60 pieces of left-behind medical equipment to the nonprofit Global Links and is preparing its recurring auction of unclaimed lost-and-found items. Pittsburgh International Airport gave 60 pieces of abandoned medical equipment held past its standard period to Global Links, a Pittsburgh nonprofit that distributes health supplies to people in need, and is readying its popular sale of items travelers never reclaimed. - Pittsburgh Magazine: https://www.pittsburghmagazine.com/pit-donates-lost-items-to-charity-and-preps-for-popular-auction/ Around town: * Hartwood Acres Joins Old-Growth Forest Network Latest developments: Local leaders announced Tuesday that Allegheny County's Hartwood Acres became the county's first site in the national Old-Growth Forest Network. Hartwood Acres, the 692-acre Allegheny County park anchored by a 1929 Tudor mansion and stands of 200-year-old trees, joined the Old-Growth Forest Network of more than 340 protected, publicly accessible forests; three-quarters of the property stays forested. - KDKA: https://www.cbsnews.com/pittsburgh/news/hartwood-acres-old-growth-forest-network/ * PennDOT Details Parkway East Demolition Latest developments: PennDOT laid out plans to drop the aging Commercial Street bridge with hundreds of button-triggered explosive charges and again urged employers to let workers stay home when the 25-day Parkway East closure starts Friday, July 10. PennDOT will shut the Parkway East between the Squirrel Hill Tunnel and the Edgewood/Swissvale exit for 25 days beginning Friday, July 10, to replace the Commercial Street bridge; the agency plans to demolish the span with hundreds of explosive charges and is pressing commuters on the 100,000-vehicle-a-day route to work from home. - TribLive: https://triblive.com/local/how-penndot-plans-to-demolish-a-parkway-east-bridge/ - WTAE: https://www.wtae.com/article/penndot-encouraging-businesses-let-employees-work-home-closure/71850997 * 62nd Street Bridge Reopens After Hazmat Spill Latest developments: PennDOT reopened the 62nd Street Bridge in both directions shortly before 1:30 p.m. Tuesday, ending a 12-hour cleanup after an overturned tractor-trailer spilled hazardous materials in Sharpsburg late Monday. An overturned tractor-trailer dumped hazardous materials on the 62nd Street Bridge in Sharpsburg late Monday, closing the span and forcing morning rush-hour detours to other bridges; the Cherry City Volunteer Fire Company and Allegheny County crews cleared the scene before PennDOT reopened both directions early Tuesday afternoon. - WTAE: https://www.wtae.com/article/crews-cleaning-up-hazardous-materials-from-overturned-tractor-trailer-in-sharpsburg/71847902 - KDKA: https://www.cbsnews.com/pittsburgh/news/overturned-truck-62nd-street-bridge-hazardous-materials-spill/ SPORTS ---------------------------------------------------------------- Pirates (46-45) Up Next · Braves @ Pirates · Tue Jul 7, 6:40 PM https://plaintextsports.com/mlb/2026-07-07/atl-pit Around the Teams: * Torn Tendon Sidelines Pirates' Griffin Latest developments: The Pirates put rookie shortstop Konnor Griffin back on the injured list Tuesday with a torn tendon in his finger, which the Post-Gazette reported will cost him eight to 10 weeks. Pirates rookie phenom Konnor Griffin tore a tendon in his finger and faces eight to 10 weeks out, another setback for the young shortstop; the Post-Gazette noted the club leans on Jack Brannigan and Jared Triolo to fill the gap. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/07/07/mlb-news-konnor-griffin-injury-jack-brannigan-jared-triolo/stories/202607070035 Team USA: * U.S.-Belgium Loss Sets Viewership Record Latest developments: Fox said Tuesday that preliminary ratings make the United States' 4-1 round-of-16 loss to Belgium the most-watched soccer telecast in American history. The U.S. men's national team's World Cup elimination by Belgium in Seattle drew the largest television audience for any soccer broadcast in United States history, Fox announced, a record set even as the tournament hosts crashed out in the round of 16. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49298623/usa-belgium-most-watched-soccer-game-american-history * ESPN Ties U.S. Exit to Pay-to-Play Youth Soccer Latest developments: In the wake of the round-of-16 exit, ESPN argued the United States keeps falling short because its youth pipeline prizes families' ability to pay for travel matches above developing young players. ESPN's post-mortem on the U.S. men's World Cup elimination pinned the recurring failures on America's pay-to-play youth system, where the cost of travel soccer gatekeeps talent and starves long-term player development. - ESPN Soccer: https://www.espn.com/soccer/worldcup/story/_/id/49297263/usmnt-world-cup-loss-youth-travel-soccer-system READING ---------------------------------------------------------------- * Ed Zitron -- Let AI Burn Zitron argues the AI industry is hemorrhaging money with no credible path to profitability and makes the case for letting the overbuilt sector collapse under its own losses rather than sustaining it. https://www.wheresyoured.at/let-ai-burn/ * Stratechery -- A Script for Mark Zuckerberg Ben Thompson writes the earnings-call remarks he thinks Mark Zuckerberg should deliver, laying out how Meta ought to frame its AI strategy and spending for investors. https://stratechery.com/2026/a-script-for-mark-zuckerberg/ * Cal Newport -- Beware of Productivity Paradoxes Newport warns that tools promising obvious productivity gains, like the personal computer, often deliver far less than expected, and urges skepticism toward assuming new technology automatically speeds knowledge work. https://calnewport.com/beware-of-productivity-paradoxes/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,488.74 ▲ +1.5% Dow 52,552.63 ▲ +1.4% Nasdaq 26,005.54 ▲ +1.7% WTI crude 69.21 ▼ -3.7% EUR/USD 1.1419 ▲ +0.3% GBP/USD 1.3324 ▲ +0.9% USD/JPY 162.03 ▲ +0.2% ================================================================ Generated 2026-07-07 16:05 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================