================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Friday, July 10, 2026 - 9:05 AM EDT ================================================================ Okta uncovers a voice-phishing crew enrolling rogue Microsoft Entra passkeys to hijack Microsoft 365 accounts, as an unpatched flaw in Alibaba's XQUIC and a mass WordPress backdoor widen the day's attack surface. CONTENTS: Emerging Trends and Key Updates | Security | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Both a criminal crew mapping 1.4 million sites in WP-SHELLSTORM and EU lawmakers reviving Chat Control push mass scanning of WordPress hosts and private messages. see: WP-SHELLSTORM Backdoors WordPress at Scale; EU Revives Chat Control as NIS2 Lags * [UPDATE (new)] Okta traced O-UNC-066, a vishing crew phoning Microsoft 365 users to enroll attacker-controlled Entra passkeys through fake Entra ID login pages. see: Okta Traces Vishing Crew Enrolling Rogue Entra Passkeys * [TREND] Fresh single-line network-library bugs keep landing, led by FoxIO's unpatched XRING crash in Alibaba's XQUIC alongside new Zimbra and Palo Alto PAN-OS patches. see: New Flaws Hit XQUIC, Zimbra, and Palo Alto * [UPDATE (new)] SentinelOne found both China-linked and India-linked hackers separately breaching Pakistan's Balochistan Police force for more than two years. see: China and India Both Hack Balochistan Police * [UPDATE (new)] Coinspect disclosed Ill Bloom, a weak-randomness flaw letting attackers reconstruct wallet seed phrases and drain the crypto they hold. see: Ill Bloom Flaw Drains Crypto Wallets * [TREND] This run's Reading turns skeptical on AI, with Zitron urging the build-out to collapse, Newport warning of productivity paradoxes, and Ben Thompson on verifiable data. see: Let AI Burn; Beware of Productivity Paradoxes; Muse Image, Grok 4.5, Alex Karp on CNBC SECURITY ---------------------------------------------------------------- 1. NEW FLAWS HIT XQUIC, ZIMBRA, AND PALO ALTO Vulnerabilities and Exploits · [vulnerability, patch, zero-day] Latest developments: FoxIO researcher Sébastien Féry disclosed XRING on July 8, an unpatched flaw in Alibaba's XQUIC library that lets any remote client crash an HTTP/3 server with roughly 260 bytes of legal QPACK traffic, while Zimbra urged customers to patch a critical Classic Web Client cross-site-scripting bug, Palo Alto Networks fixed 13 PAN-OS flaws, and Cisco Talos disclosed vulnerabilities in WolfSSL, GeoVision, and VTK-DICOM. XRING needs no login and no malformed packets, and no patch exists yet. Apply the Zimbra, Palo Alto, and Talos-tracked vendor fixes and monitor XQUIC-backed HTTP/3 servers for denial-of-service probes. - The Hacker News: https://thehackernews.com/2026/07/unpatched-xring-flaw-in-xquic-lets.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/zimbra-urges-customers-to-patch-critical-web-client-xss-flaw/ - SecurityWeek: https://www.securityweek.com/palo-alto-networks-patches-13-vulnerabilities/ - Cisco Talos: https://blog.talosintelligence.com/wolfssl-vulnerabilities/ 2. OKTA TRACES VISHING CREW ENROLLING ROGUE ENTRA PASSKEYS Ransomware and Cybercrime · [phishing, extortion, breach] Latest developments: Okta warned July 10 of a threat actor it tracks as O-UNC-066 that phones Microsoft 365 users with fake security requests, steers them to phishing sites mirroring Microsoft Entra ID login pages, and enrolls attacker-controlled Entra passkeys to seize accounts for data extortion. The crew runs a panel-controlled phishing kit built to hijack the passkey enrollment process across multiple sectors. Train staff to reject unsolicited voice requests to enroll new authenticators and lock down Entra passkey registration. - SecurityWeek: https://www.securityweek.com/okta-warns-of-vishing-attacks-targeting-microsoft-365-customers/ - The Hacker News: https://thehackernews.com/2026/07/hackers-use-fake-microsoft-entra.html 3. WP-SHELLSTORM BACKDOORS WORDPRESS AT SCALE Ransomware and Cybercrime · [malware, backdoor, web] Latest developments: The Hacker News reported July 10 that a cybercrime crew left its own server exposed on the internet for three weeks, revealing WP-SHELLSTORM, a mass site-hacking operation whose target list names more than 1.4 million WordPress websites alongside its hacking tools and activity logs. The exposed files showed researchers how a mass WordPress compromise runs from the inside, though far fewer than the 1.4 million listed sites were actually broken into. Patch WordPress core and plugins and audit sites for injected backdoors. - The Hacker News: https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html 4. ILL BLOOM FLAW DRAINS CRYPTO WALLETS Ransomware and Cybercrime · [cryptocurrency, vulnerability] Latest developments: Security firm Coinspect disclosed Ill Bloom on July 10, a flaw in how some wallet software generated its recovery phrase with weak randomness that lets an attacker reconstruct the seed words and take everything they control, and confirmed one coordinated sweep in May that drained $3.1 million. The recovery phrase is the set of words that control the money, so weak generation hands attackers full control of the wallet. Holders on affected software should migrate funds to wallets whose seed generation uses strong randomness. - The Hacker News: https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html 5. CHINA AND INDIA BOTH HACK BALOCHISTAN POLICE Nation-State Activity · [apt, nation-state] Latest developments: SentinelOne revealed July 10 that both China-linked and India-linked hackers have separately targeted Pakistan's Balochistan Police force for at least two years, putting rival and allied intelligence services on the same victim. The overlapping intrusions show a single regional law-enforcement body drawing sustained attention from multiple state-aligned groups. Organizations in contested regions should assume interest from several actors at once and harden internet-facing systems accordingly. - SecurityWeek: https://www.securityweek.com/china-india-linked-hackers-both-targeted-same-pakistani-police-force/ 6. EU REVIVES CHAT CONTROL AS NIS2 LAGS Policy and Regulation · [policy, privacy, regulation] Latest developments: Wired reported July 9 that the EU's Chat Control bill will again let companies scan citizens' private texts, emails, and social media messages for child-abuse material even though a majority of European lawmakers voted against it, the same day The Record reported the European Commission took Ireland, Spain, France, and the Netherlands to court for missing the NIS2 critical-infrastructure transposition deadline by more than 20 months. Chat Control reopens bulk scanning of private communications across the bloc, while four member states remain out of compliance with NIS2, the EU's baseline law for securing critical infrastructure. Compliance teams in the named countries face pending enforcement and should track final NIS2 transposition. - Wired Security: https://www.wired.com/story/a-majority-of-european-lawmakers-voted-against-letting-big-tech-read-our-messages-theyre-going-to-anyway/ - The Record: https://therecord.media/eu-cyber-filing-ireland-spain-france-netherlands-nis2 PITTSBURGH ---------------------------------------------------------------- Weather: Today: Chance Showers And Thunderstorms, high 82F. Tonight: Chance Showers And Thunderstorms then Areas Of Fog, low 67F. Saturday: Areas Of Fog then Scattered Showers And Thunderstorms, high 84F. Business: * Bloomfield's Liberty Avenue in Transition Latest developments: PublicSource published a feature today tracing how Bloomfield's main commercial strip is changing. PublicSource examined how shifting demographics, stalled development, and a wave of new storefronts are reshaping Liberty Avenue, the historically Italian commercial spine of Pittsburgh's Bloomfield neighborhood. - PublicSource: https://www.publicsource.org/liberty-bloomfield-pittsburgh-changing-from-italian-roots/ * Harrison Property Appeals Cost Highlands Schools Latest developments: TribLive reported the two successful appeals will cut revenue for both bodies this year. Harrison Township and the Highlands School District face a revenue hit after the owners of two large Harrison properties won Allegheny County tax-assessment appeals cutting roughly $1.2 million in taxable value. - TribLive: https://triblive.com/local/valley-news-dispatch/highlands-harrison-lose-revenue-after-1-2-million-in-reassessment-appeals/ Around town: * Parkway East Closes Tonight for 25 Days Latest developments: The closure begins tonight at 9 p.m., and WTAE launched a tool that maps detours and estimates travel times. PennDOT closes the Parkway East, Interstate 376, between the Squirrel Hill Tunnel and the Edgewood/Swissvale exit for 25 days starting at 9 p.m. Friday, July 10, to demolish the old Commercial Street Bridge and slide a replacement into place, rerouting a corridor that carries roughly 100,000 vehicles a day. - WTAE: https://www.wtae.com/article/parkway-east-bridge-closure-travel-times/71895669 * Flood Watch Grips the Region Again Latest developments: Forecasters placed the Pittsburgh area under a flood watch for today, with rain returning this afternoon. The National Weather Service put the Pittsburgh region under a flood watch for Friday, July 10, warning of rainfall rates up to two inches an hour, days after storms swamped parts of Allegheny and Westmoreland counties over the July 4 weekend. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/weather-news/2026/07/10/pittsburgh-weather-flood-watch-rain/stories/202607100041 * New Kensington Stuck on Abandoned Hospital Latest developments: TribLive reported the city has few legal levers to force the owners to act. New Kensington officials say they have limited options in a standoff with the owners of a long-abandoned hospital, a predicament the Westmoreland County city shares with Hornell, New York. - TribLive: https://triblive.com/local/valley-news-dispatch/new-kensington-left-with-limited-options-in-standoff-with-abandoned-hospital-owners/ SPORTS ---------------------------------------------------------------- Pirates (47-47) Thu Jul 9 · Braves 10 · Pirates 5 · Final Mike Yastrzemski hits grand slam in Braves' 10-5 win over Pirates https://plaintextsports.com/mlb/2026-07-09/atl-pit Up Next · Brewers @ Pirates · Fri Jul 10, 6:40 PM https://plaintextsports.com/mlb/2026-07-10/mil-pit READING ---------------------------------------------------------------- * Stratechery -- Muse Image, Grok 4.5, Alex Karp on CNBC Ben Thompson argues the contest to secure verifiable data increasingly defines the AI race, threading through Meta's Muse image model, xAI's Grok 4.5, and Palantir chief Alex Karp's CNBC appearance. https://stratechery.com/2026/muse-image-grok-4-5-alex-karp-on-cnbc/ * Ed Zitron -- Let AI Burn Zitron contends the AI build-out is financially unsustainable and should be allowed to collapse rather than be propped up, extending his case that the industry's economics do not add up. https://www.wheresyoured.at/let-ai-burn/ * Cal Newport -- Beware of Productivity Paradoxes Newport warns that technologies which look like productivity slam dunks, from the personal computer to today's AI tools, often fail to deliver the output gains people assume they will. https://calnewport.com/beware-of-productivity-paradoxes/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,510.17 ▲ +1.1% Dow 52,743.39 ▲ +1.2% Nasdaq 25,970.01 ▲ +0.9% WTI crude 70.66 ▲ +0.9% EUR/USD 1.1426 ▲ +0.3% GBP/USD 1.3367 ▲ +1.0% USD/JPY 161.98 ▼ -0.1% ================================================================ Generated 2026-07-10 09:05 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================