================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Sunday, July 12, 2026 - 2:17 AM EDT ================================================================ A poisoned jscrambler npm release ran a Rust infostealer on developers' machines, the sharpest of a day's attacks reaching from software supply chains down to device bootloaders. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Nation-state espionage converged as suspected China- and India-aligned actors both breached Pakistan's Balochistan Police while China-linked Silver Fox fielded a new Rust MODBEACON trojan. see: China and India Spy on Balochistan Police; Silver Fox's MODBEACON RAT * [TREND] Attackers kept poisoning the developer supply chain as the jscrambler npm release smuggled a native Rust infostealer onto Windows, macOS, and Linux machines during install. see: Poisoned jscrambler npm Release and GitHub Recon * [TREND] Vulnerabilities moved deeper into the stack with six fresh U-Boot bootloader flaws and an unpatched XRING crash in Alibaba's XQUIC HTTP/3 library. see: Six New U-Boot Bootloader Flaws; Unpatched XRING Flaw in Alibaba's XQUIC * [UPDATE (new)] SecurityWeek detailed GigaWiper, a new backdoor bundling a standalone wiper, ransomware-style encryption, and a multi-pass wiping command built for system-level sabotage. see: GigaWiper Destructive Malware * [UPDATE (new)] U.S. Central Command struck again overnight after Iran's Revolutionary Guard fired on a containership and once more declared the Strait of Hormuz closed. see: Hormuz Fighting Escalates Again * [UPDATE (new)] Union Pacific's Big Boy No. 4014 drew thousands to Homestead, compounding gridlock from the Parkway East closure and stranding drivers for hours. see: Big Boy Crowds Compound Parkway East Detour SECURITY ---------------------------------------------------------------- 1. CHINA AND INDIA SPY ON BALOCHISTAN POLICE Nation-State Activity · [apt, espionage, breach] Latest developments: SentinelOne disclosed that suspected China- and India-aligned threat actors ran separate espionage campaigns against Pakistan's Balochistan Police between February 2024 and April 2026, in some cases breaching the exact same servers that host web applications managing criminal and citizen records for the force policing the country's insurgency-hit southwestern province. Two rival states independently compromised the same Pakistani law-enforcement systems, a rare case of adversaries and near-allies colliding on one target tied to the long-running Balochistan separatist conflict. The intrusions exposed police and citizen data across the province. - The Record: https://therecord.media/china-india-ran-separate-spy-campaigns-against-same-police-force - SecurityWeek: https://www.securityweek.com/china-india-linked-hackers-both-targeted-same-pakistani-police-force/ - The Hacker News: https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html 2. POISONED JSCRAMBLER NPM RELEASE AND GITHUB RECON Ransomware and Cybercrime · [supply-chain, malware, breach] Latest developments: The jscrambler package's 8.14.0 release, published July 11, 2026, carried a preinstall hook that dropped and ran a native Rust infostealer—separate Windows, macOS, and Linux builds—on any machine that installed it, and Socket flagged the release six minutes after publication, while SecurityWeek reported ghost accounts abusing the GitHub API to map organizations' repositories and members in a mass reconnaissance campaign. Two developer-ecosystem threats surfaced together: a compromised jscrambler npm build that steals credentials at install time, and throwaway GitHub accounts quietly cataloging corporate repos and staff for later attacks. Pin dependency versions, audit recent installs, and lock down GitHub organization visibility. - The Hacker News: https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html - SecurityWeek: https://www.securityweek.com/ghost-accounts-abuse-github-api-in-mass-recon-campaign/ 3. SIX NEW U-BOOT BOOTLOADER FLAWS Vulnerabilities and Exploits · [firmware, patch, vulnerability] Latest developments: Firmware security firm Binarly disclosed six new flaws in U-Boot, the bootloader that starts home routers, smart cameras, and data-center management chips, four of which crash a device and two of which let an attacker who slips a malicious image in front of the bootloader run code before the device raises its defenses. U-Boot runs on an enormous range of hardware, so the code-execution bugs open a path to stealthy, persistent firmware implants that survive reinstalls and defeat later protections. Device makers should ship the patched builds; operators should track firmware updates from affected vendors. - BleepingComputer: https://www.bleepingcomputer.com/news/security/new-u-boot-flaws-could-enable-stealthy-firmware-attacks/ - The Hacker News: https://thehackernews.com/2026/07/six-new-u-boot-flaws-could-let.html 4. GIGAWIPER DESTRUCTIVE MALWARE Ransomware and Cybercrime · [wiper, ransomware, malware] Latest developments: SecurityWeek detailed GigaWiper, a backdoor that bundles a standalone wiper, ransomware-style encryption, and a multi-pass wiping command into one tool built for system-level sabotage. GigaWiper blurs the line between ransomware and pure destruction, giving operators the choice to extort or simply erase a compromised system beyond recovery. Organizations should treat it as a data-destruction threat and verify that backups sit beyond the reach of a compromised host. - SecurityWeek: https://www.securityweek.com/gigawiper-combines-multiple-malware-for-system-level-sabotage/ 5. UNPATCHED XRING FLAW IN ALIBABA'S XQUIC Vulnerabilities and Exploits · [dos, vulnerability, zero-day] Latest developments: FoxIO researcher Sébastien Féry disclosed XRING on July 8, a single wrong variable in Alibaba's XQUIC QUIC and HTTP/3 library that lets any remote client crash the server with roughly 260 bytes of legal QPACK traffic, no login and no malformed packets required, and there is no patch. XRING turns ordinary HTTP/3 requests into a reliable denial-of-service against anyone running XQUIC, a widely embedded library. With no fix available, operators should restrict exposure of XQUIC-backed services and monitor for repeated QPACK-triggered crashes. - The Hacker News: https://thehackernews.com/2026/07/unpatched-xring-flaw-in-xquic-lets.html 6. SILVER FOX'S MODBEACON RAT Nation-State Activity · [apt, malware, rat] Latest developments: Chinese security firm QiAnXin attributed a new Rust-based remote access trojan called MODBEACON to the China-linked group Silver Fox, which uses gRPC streaming to encrypt its command-and-control traffic and spreads through counterfeit installers pushed by SEO poisoning. MODBEACON reveals a more organized operation behind what looked like a high-volume, low-sophistication malware crew, with encrypted gRPC channels that blend into normal traffic. Defenders should watch for counterfeit software installers and unusual gRPC connections. - The Hacker News: https://thehackernews.com/2026/07/new-modbeacon-rat-uses-grpc-streaming.html BUSINESS AND POLITICS ---------------------------------------------------------------- * Hormuz Fighting Escalates Again Latest developments: U.S. Central Command launched fresh strikes overnight into July 12 after Iran's Revolutionary Guard fired on a containership transiting the strait, left a crew member missing, again declared the waterway closed, and turned its threats on the Gulf Arab states. Iran and the United States traded new attacks over the Strait of Hormuz, the chokepoint carrying roughly a fifth of the world's seaborne oil, as the Trump administration warned Tehran to reopen the passage and grew pessimistic about any nuclear deal. The Wall Street Journal reports Iran now treats control of the strait as cementing its regional power, keeping tanker traffic and oil prices at risk. - WSJ: https://www.wsj.com/world/middle-east/u-s-launches-new-strikes-on-iran-after-hormuz-tensions-escalate-d6903c7f?mod=pls_whats_news_us_business_f - FT: https://www.ft.com/content/6b6c23e9-f24e-4c3e-bb1a-e5cb6860008d - WSJ: https://www.wsj.com/world/middle-east/https-www-wsj-com-world-middle-east-iran-deal-strait-of-hormuz-b027c30f-580ee99f PITTSBURGH ---------------------------------------------------------------- Weather: Overnight: Mostly Cloudy, low 67F. Sunday: Mostly Sunny, high 87F. Sunday Night: Mostly Clear, low 67F. Business: * West Overton Revives Cherry Bounce Latest developments: West Overton Village's distillery in Scottdale, Westmoreland County, launched a historic cherry bounce, a colonial cherry-steeped whiskey liqueur, to mark the United States' semiquincentennial. West Overton Village, the restored 19th-century industrial hamlet near Scottdale where Henry Clay Frick was born, runs a working distillery; its America 250 cherry bounce ties the region's whiskey heritage to the July 4 anniversary of independence. - TribLive: https://triblive.com/local/westmoreland/west-overton-village-distillery-launches-historic-cherry-bounce-for-america-250/ * Jeannette Hires Three Officers to Curb Overtime Latest developments: Jeannette hired three police officers this week, which city officials said should ease the department's ballooning overtime costs. Jeannette, a Westmoreland County city that has leaned on costly overtime to staff a short-handed police force, added three officers to bring those payroll costs down. - TribLive: https://triblive.com/local/westmoreland/jeannette-hires-3-police-officers-to-help-rein-in-ballooning-overtime-costs/ Around town: * Big Boy Crowds Compound Parkway East Detour Latest developments: Thousands lined the rails in Homestead on Saturday, July 11, to watch Union Pacific's Big Boy No. 4014 steam locomotive, jamming a borough already absorbing detour traffic from the Parkway East closure and leaving drivers in hours of gridlock. PennDOT closed the Parkway East (I-376) and the Squirrel Hill Tunnel on July 10 for a 25-day Commercial Street Bridge replacement, rerouting roughly 100,000 daily drivers through Homestead and the Waterfront; Union Pacific's Big Boy No. 4014, the world's largest operating steam locomotive, drew thousands to Homestead's rail lines on its Western Pennsylvania tour before stopping in Leetsdale on its way home. Homestead-area officials warned that weekday rush hour could worsen the congestion. - KDKA: https://www.cbsnews.com/pittsburgh/news/parkway-east-closure-big-boy-traffic-homestead/ - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/transportation/2026/07/11/commercial-bridge-closure-day-1/stories/202607110044 - WPXI: https://www.wpxi.com/news/local/big-boy-locomotive-draws-massive-crowds-across-western-pennsylvania/QHGET5EUUJHWXFHOOY54RSRXBI/ Events: * Danny Elfman Heads to Pittsburgh Latest developments: Film composer Danny Elfman, in a Post-Gazette Q&A, discussed the shrinking audience for classical music ahead of an upcoming Pittsburgh appearance. Danny Elfman, who scored Tim Burton's films, the 1989 'Batman,' and the theme to 'The Simpsons,' spoke with the Post-Gazette about the decline of classical music's audience before a coming performance in Pittsburgh. - Pittsburgh Post-Gazette: https://www.post-gazette.com/ae/music/2026/07/09/danny-elfman-classical-music-decline-film-pittsburgh/stories/202607090002 SPORTS ---------------------------------------------------------------- Pirates (49-47) Sat Jul 11 · Brewers 6 · Pirates 7 · Final Esmerlyn Valdez's grand slam, two homers lead Pirates past Brewers 7-6 in first game of doubleheader https://plaintextsports.com/mlb/2026-07-11/mil-pit Sat Jul 11 · Brewers 2 · Pirates 3 · Final Esmerlyn Valdez homers again as Pirates edge Brewers, 3-2, sweep twinbill from NL Central leaders https://plaintextsports.com/mlb/2026-07-11/mil-pit Up Next · Brewers @ Pirates · Sun Jul 12, 12:15 PM https://plaintextsports.com/mlb/2026-07-12/mil-pit Around the Teams: * Pirates' Bats Blow Past Last Year's Homers Latest developments: The Post-Gazette's 'Off The Bat' charted how the Pirates have already surpassed their entire 2025 home run total, crediting Bryan Reynolds, Brandon Lowe, and Ryan O'Hearn. The Pittsburgh Pirates, long among baseball's weakest power-hitting teams, have found sustained pop in 2026 from Bryan Reynolds, Brandon Lowe, and Ryan O'Hearn, topping their full 2025 home run count with months of the season left. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/07/11/pirates-mlb-home-run-reynolds-lowe-o-hearn/stories/202607100074 * Hiles: Pirates Are Misusing Mlodzinski Latest developments: Post-Gazette columnist Noah Hiles argued the Pirates must make better use of right-handed reliever Carmen Mlodzinski, faulting how the club deploys him. Noah Hiles wrote that the Pittsburgh Pirates are wasting Carmen Mlodzinski by keeping him out of higher-leverage bullpen work, a critique aimed at how general manager Ben Cherington's staff manages its relief corps. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/07/11/hiles-column-mlodzinski-bullpen-mlb-kelly-cherington/stories/202607110014 * Greg Hawthorne, 1979 First-Round Pick, Dies at 69 Latest developments: Greg Hawthorne, the back the Pittsburgh Steelers took in the first round of the 1979 NFL Draft, has died at 69, the Post-Gazette reported. The Pittsburgh Steelers made Greg Hawthorne their first-round draft pick in 1979, during the closing years of the franchise's Steel Curtain dynasty; he has died at 69. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/10/hawthorne-dies-obituary-nfl-player/stories/202607100049 READING ---------------------------------------------------------------- * Ed Zitron -- Premium: The Hater's Guide To The Memory Crisis Zitron dissects the surging prices and shortages gripping the computer-memory market, tying the squeeze to the AI data-center build-out and casting a skeptical eye on whether the boom can hold. https://www.wheresyoured.at/premium-the-haters-guide-to-the-memory-crisis/ * Stratechery -- Muse Image, Grok 4.5, Alex Karp on CNBC Ben Thompson argues the battle for verifiable data increasingly defines the AI race, threading Meta's Muse Image, xAI's Grok 4.5, and Palantir chief Alex Karp's CNBC remarks into one thesis. https://stratechery.com/2026/muse-image-grok-4-5-alex-karp-on-cnbc/ * Cal Newport -- Beware of Productivity Paradoxes Newport warns that new tools, like the personal computer before them, often fail to deliver the productivity gains they promise, cautioning readers against assuming technology automatically makes work more efficient. https://calnewport.com/beware-of-productivity-paradoxes/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,528.60 ▲ +1.0% Dow 52,690.77 ▲ +0.7% Nasdaq 26,059.80 ▲ +0.8% WTI crude 71.20 ▲ +2.7% EUR/USD 1.1424 ▲ +0.1% GBP/USD 1.3382 ▲ +0.9% USD/JPY 162.21 ▲ +0.1% ================================================================ Generated 2026-07-12 02:17 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================