infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

Western governments escalated financial sanctions against ransomware enablers and Russian state hackers as poisoned software packages kept slipping into enterprises through trusted registries.


Emerging Trends and Key Updates

Security

1. Software Supply-Chain Attacks Across npm and Browser Stores

Software Supply Chain · [supply-chain, npm, infostealer]

Latest developments: Fresh incidents piled up on July 13 and 14, 2026: a threat actor backdoored several Jscrambler npm packages with a cross-platform credential stealer downloaded almost 1,500 times, JFrog found 148 npm packages disguised as student proxies that turned visitors' browsers into a DDoS botnet for two weeks in May, xAI's Grok Build CLI uploaded entire git repositories with full commit history to a Google Cloud Storage bucket, and Google and Microsoft pulled the ModHeader extension after finding a hidden browsing-history collector across its 1.6 million installs.

read more

Attackers keep exploiting the trust developers place in package registries and browser extension stores to smuggle infostealers, botnet code, and data-exfiltration into enterprise environments. Teams should pin dependency versions, audit installed extensions, and monitor for unexpected outbound uploads.

Sources: SecurityWeek · The Hacker News · The Hacker News · The Hacker News · ↑ top

2. US Treasury Sanctions First VPN Service and Cryptor Sellers

Ransomware and Cybercrime · [ransomware, sanctions, policy]

Latest developments: On July 13, 2026, the Treasury's Office of Foreign Assets Control designated First VPN Service (1VPNS), its 45-year-old Ukrainian administrator, and a Belarusian man who sold malware cryptors, the first time the United States sanctioned a VPN provider for enabling ransomware.

read more

OFAC froze the parties' assets and barred US persons from dealing with them, saying First VPN rented infrastructure to ransomware crews and other criminals attacking Americans while the cryptors helped malware evade detection. Companies must screen the designated names to avoid sanctions violations.

Sources: BleepingComputer · The Hacker News · The Record · ↑ top

3. ShinyHunters Abuses Salesforce OAuth Trust

Ransomware and Cybercrime · [oauth, saas, extortion]

Latest developments: Microsoft Threat Intelligence and The Hacker News on July 13 and 14, 2026 mapped three specific Salesforce attack paths tied to a year of ShinyHunters activity, showing the group abuses existing OAuth connections between Salesforce and third-party apps to walk into corporate environments and steal data.

read more

The data-extortion crew chains voice phishing, supply-chain compromise, and misconfigured guest access to seize OAuth trust rather than break any platform flaw, then extorts victims over the stolen records. Organizations should audit connected apps and revoke unused OAuth grants.

Sources: Microsoft Security Blog · The Hacker News · ↑ top

4. Passkeys Become the Default in Microsoft Entra ID

Identity and Access Management · [identity, passkeys, mfa]

Latest developments: Microsoft said on July 13, 2026 that it will make passkeys the default sign-in experience for Entra ID in the public cloud starting September 1, 2026, automatically enabling passkeys for organizations that still use SMS or voice authentication.

read more

The next time users complete multifactor authentication after the rollout, Entra ID prompts them to register a passkey, and from February 1, 2027 anyone relying on SMS or voice codes must enroll one before signing in. Administrators should prepare enrollment guidance now to avoid lockouts.

Sources: Help Net Security · Microsoft Security Blog · ↑ top

5. EU and UK Impose First Joint Russia Cyber Sanctions

Nation-State Activity · [nation-state, sanctions, policy]

Latest developments: The European Union and United Kingdom issued their first joint cyber sanctions package on July 13, 2026, with the UK naming 24 individuals and entities and the EU nine individuals and four entities, accusing Russia's GRU military intelligence of coordinating hacking and disinformation across Europe.

read more

The measures target what Brussels and London call a Russian malicious cyber ecosystem of criminals, self-proclaimed hacktivists, and private firms operating under Moscow's instructions. Sanctioned parties face asset freezes and travel bans.

Sources: BleepingComputer · Help Net Security · Dark Reading · ↑ top

6. CrashStealer macOS Infostealer

Ransomware and Cybercrime · [malware, macos, infostealer]

Latest developments: Jamf Threat Labs flagged CrashStealer on July 13, 2026, a native C++ macOS information stealer that poses as Apple's crash-reporting tool and uses a notarized dropper to pass Gatekeeper checks.

read more

CrashStealer validates the victim's login password locally before harvesting credentials, keychain data, and crypto wallets, breaking from the AppleScript and Objective-C wrappers most Mac stealers rely on. Mac users should distrust unexpected crash-report prompts and verify software signatures.

Sources: BleepingComputer · The Hacker News · ↑ top

Business and Politics

Oil Surges Near 10% as Hormuz Battle Deepens

Latest developments: International crude jumped nearly 10% to about $87 a barrel on July 14, its steepest climb since 2020, dragging global bond yields higher as traders bet the Strait of Hormuz stays shut.

read more

A third straight night of U.S. strikes on Iran, President Trump's reimposed naval blockade, and his 20% Hormuz transit fee drove Brent toward $87 and pushed the U.K. ten-year gilt yield back above 5%, its highest since May, reviving inflation fears across stock and bond markets as the strait that carries roughly a fifth of the world's oil chokes.

Sources: WSJ Markets · FT Markets · FT Markets · WSJ World News · ↑ top

Pittsburgh

Weather

Today: Sunny, high 94F.

Tonight: Mostly Clear, low 73F.

Wednesday: Mostly Sunny, high 97F.

Business

Street Fries Truck Opens South Side Base

Latest developments: The Street Fries food truck announced on Instagram the soft launch of a permanent home at 1210 East Carson Street in the South Side.

read more

Street Fries Forever, a loaded-fries purveyor, will serve from 1210 East Carson Street in Pittsburgh's South Side, Wednesday through Sunday, with some nights running as late as 2 a.m.

Sources: Pittsburgh City Paper · ↑ top

Eat’n Park Debuts Pickle Smiley Cookie

Latest developments: Eat'n Park unveiled a pickle-themed version of its Smiley Cookie to mark the Picklesburgh festival.

read more

Eat'n Park is selling a Pickle Smiley Cookie, a new take on its signature dessert, at some Pittsburgh-area restaurants and at the Picklesburgh festival itself.

Sources: WPXI · ↑ top

Around Town

Parkway East Detours Strain Neighborhoods

Latest developments: Public transit ridership rose and Regent Square residents reported gridlock as the Parkway East closure entered its fourth day.

read more

The 25-day closure of the Parkway East (I-376) for the Commercial Street Bridge replacement is funneling tens of thousands of drivers through Pittsburgh neighborhoods including Regent Square and Homestead, snarling the evening rush and pushing more commuters onto Pittsburgh Regional Transit.

Sources: WPXI · WPXI · WTAE · ↑ top

Pittsburgh Opens Cooling Centers in Heat

Latest developments: The city of Pittsburgh opened multiple cooling centers this week as another round of hot, humid weather settled over Western Pennsylvania.

read more

Pittsburgh opened several cooling centers as forecasters flagged an Impact Day for hot, humid conditions across Western Pennsylvania.

Sources: WPXI · WTAE · ↑ top

Sports

Pirates (50-47)

Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM

Around the Teams

Pirates Fill Out 2026 Draft Class

Latest developments: The Post-Gazette recapped all 16 players the Pirates added on Day 2 of the MLB Draft, among them Marohn, Fay, Phelps, and Bryson Moore, after taking LSU outfielder Derek Curiel fifth overall.

read more

Pittsburgh's 2026 MLB Draft haul, headlined by No. 5 overall pick Derek Curiel of LSU, grew to 16 more selections on Day 2 as the Pirates stocked their farm system ahead of the second half.

Sources: Post-Gazette Pirates · ↑ top

Team USA

Balogun Signs With LeBron James’s Klutch

Latest developments: United States forward Folarin Balogun signed with LeBron James's Klutch Sports agency following a breakout 2026 World Cup.

read more

Folarin Balogun, the Monaco and U.S. men's national team striker whose World Cup play raised his profile on and off the pitch, joined LeBron James's Klutch Sports agency.

Sources: ESPN Soccer · ↑ top

Revolution Extend Matt Turner Loan

Latest developments: The New England Revolution extended the loan of U.S. goalkeeper Matt Turner from Lyon through the end of 2026.

read more

The New England Revolution kept United States men's national team goalkeeper Matt Turner on loan from France's Lyon through the end of the 2026 season.

Sources: ESPN Soccer · ↑ top

Reading

Markets

weekly average, change vs prior week

S&P 500     7,524.19  ▲ +0.5%
Dow        52,579.32  ▲ +0.1%
Nasdaq     26,010.20  = +0.0%
WTI crude      73.12  ▲ +5.6%
EUR/USD       1.1421  ▲ +0.1%
GBP/USD       1.3389  ▲ +0.7%
USD/JPY       162.25  ▲ +0.2%