infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

The European Union and United Kingdom impose their first joint cyber sanctions on Russian GRU officers as Zimbra and RabbitMQ rush critical patches and attackers weaponize AI to map corporate networks.


Emerging Trends and Key Updates

Security

1. EU and UK Sanction Russian GRU Officers

Nation-State Activity · [apt, policy, sanctions]

Latest developments: The European Union and United Kingdom on July 13, 2026 imposed their first joint cyber sanctions package, targeting dozens of Russian GRU intelligence officers and entities accused of running a yearslong spying and sabotage network against European governments and critical infrastructure.

read more

The measures freeze assets and bar travel for individuals the EU ties to attacks and sabotage across Europe, arriving days after a US-led advisory warned of Russian state hackers breaching critical-infrastructure routers. Operators should apply the joint router-hardening guidance.

Sources: BleepingComputer · SecurityWeek · ↑ top

2. RabbitMQ Broker Takeover Flaw

Vulnerabilities and Exploits · [vulnerability, patch]

Latest developments: SecurityWeek reported July 13, 2026 that a newly disclosed RabbitMQ vulnerability lets unauthenticated attackers retrieve the message broker's confidential OAuth client secret and seize full control of the broker.

read more

RabbitMQ is a widely deployed open-source message broker that underpins enterprise application queues, and the flaw exposes its OAuth client secret to anonymous requests. Administrators should apply the fixed release and rotate the exposed secret.

Sources: SecurityWeek · ↑ top

3. Zimbra Patches Critical Code Execution Flaw

Vulnerabilities and Exploits · [vulnerability, patch, xss]

Latest developments: Zimbra shipped a fix on July 13, 2026 for the critical stored cross-site-scripting flaw in its Classic Web Client that runs attacker code when a victim opens a crafted email, closing a hole disclosed July 10 that still carries no CVE identifier.

read more

Zimbra Collaboration's Classic Web Client executes malicious scripts embedded in crafted emails the moment a recipient opens them, exposing user sessions. Administrators should install the patched version immediately.

Sources: SecurityWeek · ↑ top

4. Spoofed OAuth Client IDs Evade Entra ID Logs

Vulnerabilities and Exploits · [identity, evasion]

Latest developments: Help Net Security reported July 13, 2026 that attackers running account enumeration against Microsoft cloud tenants now spoof the OAuth client_id so Microsoft Entra ID records an unfamiliar application ID, keeping their probing out of sign-in telemetry.

read more

The technique exploits how Entra ID logs unrecognized application identifiers, letting operators confirm valid accounts without tripping the usual monitoring. Defenders should treat unfamiliar application IDs in sign-in logs as suspect.

Sources: Help Net Security · ↑ top

5. AI-Generated PowerShell Maps Active Directory

AI Security · [ai, powershell]

Latest developments: The Hacker News reported July 13, 2026 that an unknown threat actor used a vibe-coded, suspected AI-generated PowerShell script to locate the domain controller and enumerate users, computers, and domains, then exported an AD_Report.html to gauge its own success.

read more

The script performed full Active Directory reconnaissance and wrote its results to disk, showing attackers leaning on large language models to assemble tooling on the fly. Defenders should watch for anomalous PowerShell enumeration and unexpected report artifacts.

Sources: The Hacker News · ↑ top

6. Meta Patent for All-Day Emotion-Tracking AI

Surveillance and Privacy · [privacy, surveillance, ai]

Latest developments: The Hacker News reported July 13, 2026 that Meta filed a patent application for an AI that listens to a user's voice all day, infers emotion from how they sound, and keeps a timestamped log tied to location, activity, and phone use.

read more

The filing describes always-on audio capture that pins each emotional read to the moment, place, and context, raising fresh biometric-surveillance concerns. It remains a patent application rather than a shipped product.

Sources: The Hacker News · ↑ top

Business and Politics

U.S. Vows to Seize Strait of Hormuz

Latest developments: The United States struck fresh Iranian targets after Tehran rejected the demand to reopen the strait, President Trump said Washington will take over the waterway and bill Iran for the service, and OPEC further cut its 2026 oil-demand growth forecast.

read more

The United States and Iran each claim control of the Strait of Hormuz—the channel carrying roughly a fifth of the world's oil—after a weekend of strikes across the Middle East, and Brent crude climbed while gold fell more than 1% Monday, July 13, on revived inflation fears.

Sources: WSJ World News · FT World · WSJ US Business · ↑ top

Pittsburgh

Weather

Today: Sunny, high 89F.

Tonight: Mostly Clear, low 68F.

Tuesday: Sunny, high 94F.

Business

Kroger's Giant Eagle Purchase Draws Fire

Latest developments: A Post-Gazette letter to the editor warned that Kroger's proposed purchase of Giant Eagle could deepen food deserts across the Pittsburgh region.

read more

Kroger, the Cincinnati supermarket chain, has moved to buy Pittsburgh-based Giant Eagle, and a Post-Gazette reader argued the combination could worsen food deserts in low-income neighborhoods that lean on the two chains' stores.

Sources: Pittsburgh Post-Gazette · ↑ top

Jeannette to Sell 20 Vacant Lots

Latest developments: Jeannette approved a new vetting process and will offer roughly 20 city-owned vacant lots for sale, requiring would-be buyers to submit background and other information.

read more

The Westmoreland County city of Jeannette will sell about 20 vacant lots it owns, screening applicants under a newly approved process meant to keep the land out of the hands of problem buyers.

Sources: TribLive · ↑ top

Around Town

Funding Gap Threatens Alle-Kiski Shuttle

Latest developments: A funding shortfall threatens the free community shuttle serving Harrison, Tarentum, and Brackenridge that residents use for groceries, the library, and the post office.

read more

Riders like Natrona resident Cindy Brashears depend on the free shuttle linking Harrison, Tarentum, and Brackenridge in the Alle-Kiski Valley, and its operators say lost funding could end the service.

Sources: TribLive · ↑ top

Allegheny County Jail Seeks New Warden

Latest developments: Allegheny County opened a search for a new warden to lead its jail, and county leaders and activists said they are watching the process warily.

read more

The Allegheny County Jail begins a search for its next warden, tied to Trevor Wingard, and reform advocates want a voice in choosing the person who will run the downtown facility.

Sources: Pittsburgh Post-Gazette · ↑ top

Sports

Pirates (50-47)

Sun Jul 12 · Brewers 5 · Pirates 14 · Final

Skenes wins 2nd straight start after 9-game winless slide, Pirates rout Brewers 14-5 with 10-run 4th

Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM

Reading

Markets

weekly average, change vs prior week

S&P 500     7,528.60  ▲ +1.0%
Dow        52,690.77  ▲ +0.7%
Nasdaq     26,059.80  ▲ +0.8%
WTI crude      71.20  ▲ +2.7%
EUR/USD       1.1428  ▲ +0.2%
GBP/USD       1.3382  ▲ +0.9%
USD/JPY       162.16  ▲ +0.1%