================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Tuesday, July 14, 2026 - 6:05 AM EDT ================================================================ Western governments escalated financial sanctions against ransomware enablers and Russian state hackers as poisoned software packages kept slipping into enterprises through trusted registries. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Western governments turned sanctions on cyber enablers, with the US Treasury targeting First VPN Service and a Belarusian cryptor seller as the EU and UK jointly named Russia's GRU. see: US Treasury Sanctions First VPN Service and Cryptor Sellers; EU and UK Impose First Joint Russia Cyber Sanctions * [TREND] Attackers keep riding trusted rails, from backdoored Jscrambler npm builds and 148 fake student proxies to ShinyHunters abusing existing Salesforce OAuth connections. see: Software Supply-Chain Attacks Across npm and Browser Stores; ShinyHunters Abuses Salesforce OAuth Trust * [UPDATE (new)] Microsoft will make passkeys the default sign-in for Entra ID starting September 1, auto-enabling them for organizations still relying on phishable SMS or voice codes. see: Passkeys Become the Default in Microsoft Entra ID * [UPDATE (new)] International crude surged nearly 10% toward $87 a barrel, its steepest jump since 2020, as traders bet the Strait of Hormuz stays shut and bond yields climbed. see: Oil Surges Near 10% as Hormuz Battle Deepens * [TREND] Pittsburgh strained under a Parkway East closure now in its fourth day and a fresh heat wave that pushed the city to open cooling centers. see: Parkway East Detours Strain Neighborhoods; Pittsburgh Opens Cooling Centers in Heat * [UPDATE (new)] Jamf Threat Labs flagged CrashStealer, a native C++ macOS infostealer posing as Apple's crash tool with a notarized dropper that slips past Gatekeeper. see: CrashStealer macOS Infostealer SECURITY ---------------------------------------------------------------- 1. SOFTWARE SUPPLY-CHAIN ATTACKS ACROSS NPM AND BROWSER STORES Software Supply Chain · [supply-chain, npm, infostealer] Latest developments: Fresh incidents piled up on July 13 and 14, 2026: a threat actor backdoored several Jscrambler npm packages with a cross-platform credential stealer downloaded almost 1,500 times, JFrog found 148 npm packages disguised as student proxies that turned visitors' browsers into a DDoS botnet for two weeks in May, xAI's Grok Build CLI uploaded entire git repositories with full commit history to a Google Cloud Storage bucket, and Google and Microsoft pulled the ModHeader extension after finding a hidden browsing-history collector across its 1.6 million installs. Attackers keep exploiting the trust developers place in package registries and browser extension stores to smuggle infostealers, botnet code, and data-exfiltration into enterprise environments. Teams should pin dependency versions, audit installed extensions, and monitor for unexpected outbound uploads. - SecurityWeek: https://www.securityweek.com/multiple-jscrambler-packages-impacted-by-supply-chain-attack/ - The Hacker News: https://thehackernews.com/2026/07/148-npm-packages-disguised-as-student.html - The Hacker News: https://thehackernews.com/2026/07/grok-build-uploads-entire-git.html - The Hacker News: https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html 2. US TREASURY SANCTIONS FIRST VPN SERVICE AND CRYPTOR SELLERS Ransomware and Cybercrime · [ransomware, sanctions, policy] Latest developments: On July 13, 2026, the Treasury's Office of Foreign Assets Control designated First VPN Service (1VPNS), its 45-year-old Ukrainian administrator, and a Belarusian man who sold malware cryptors, the first time the United States sanctioned a VPN provider for enabling ransomware. OFAC froze the parties' assets and barred US persons from dealing with them, saying First VPN rented infrastructure to ransomware crews and other criminals attacking Americans while the cryptors helped malware evade detection. Companies must screen the designated names to avoid sanctions violations. - BleepingComputer: https://www.bleepingcomputer.com/news/security/us-sanctions-vpn-malware-providers-linked-to-ransomware-gangs/ - The Hacker News: https://thehackernews.com/2026/07/us-sanctions-first-vpn-service-and.html - The Record: https://therecord.media/first-vpn-administrator-us-sanctions-ransomware-groups 3. SHINYHUNTERS ABUSES SALESFORCE OAUTH TRUST Ransomware and Cybercrime · [oauth, saas, extortion] Latest developments: Microsoft Threat Intelligence and The Hacker News on July 13 and 14, 2026 mapped three specific Salesforce attack paths tied to a year of ShinyHunters activity, showing the group abuses existing OAuth connections between Salesforce and third-party apps to walk into corporate environments and steal data. The data-extortion crew chains voice phishing, supply-chain compromise, and misconfigured guest access to seize OAuth trust rather than break any platform flaw, then extorts victims over the stolen records. Organizations should audit connected apps and revoke unused OAuth grants. - Microsoft Security Blog: https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/ - The Hacker News: https://thehackernews.com/2026/07/microsoft-maps-year-long-shinyhunters.html 4. PASSKEYS BECOME THE DEFAULT IN MICROSOFT ENTRA ID Identity and Access Management · [identity, passkeys, mfa] Latest developments: Microsoft said on July 13, 2026 that it will make passkeys the default sign-in experience for Entra ID in the public cloud starting September 1, 2026, automatically enabling passkeys for organizations that still use SMS or voice authentication. The next time users complete multifactor authentication after the rollout, Entra ID prompts them to register a passkey, and from February 1, 2027 anyone relying on SMS or voice codes must enroll one before signing in. Administrators should prepare enrollment guidance now to avoid lockouts. - Help Net Security: https://www.helpnetsecurity.com/2026/07/14/microsoft-entra-passkey-authentication/ - Microsoft Security Blog: https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/ 5. EU AND UK IMPOSE FIRST JOINT RUSSIA CYBER SANCTIONS Nation-State Activity · [nation-state, sanctions, policy] Latest developments: The European Union and United Kingdom issued their first joint cyber sanctions package on July 13, 2026, with the UK naming 24 individuals and entities and the EU nine individuals and four entities, accusing Russia's GRU military intelligence of coordinating hacking and disinformation across Europe. The measures target what Brussels and London call a Russian malicious cyber ecosystem of criminals, self-proclaimed hacktivists, and private firms operating under Moscow's instructions. Sanctioned parties face asset freezes and travel bans. - BleepingComputer: https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/ - Help Net Security: https://www.helpnetsecurity.com/2026/07/13/eu-uk-russia-cyber-activity-sanctions/ - Dark Reading: https://www.darkreading.com/endpoint-security/weak-security-fuel-russian-cyberattacks 6. CRASHSTEALER MACOS INFOSTEALER Ransomware and Cybercrime · [malware, macos, infostealer] Latest developments: Jamf Threat Labs flagged CrashStealer on July 13, 2026, a native C++ macOS information stealer that poses as Apple's crash-reporting tool and uses a notarized dropper to pass Gatekeeper checks. CrashStealer validates the victim's login password locally before harvesting credentials, keychain data, and crypto wallets, breaking from the AppleScript and Objective-C wrappers most Mac stealers rely on. Mac users should distrust unexpected crash-report prompts and verify software signatures. - BleepingComputer: https://www.bleepingcomputer.com/news/security/new-crashstealer-malware-poses-as-apple-crash-reporting-tool/ - The Hacker News: https://thehackernews.com/2026/07/crashstealer-macos-malware-uses.html BUSINESS AND POLITICS ---------------------------------------------------------------- * Oil Surges Near 10% as Hormuz Battle Deepens Latest developments: International crude jumped nearly 10% to about $87 a barrel on July 14, its steepest climb since 2020, dragging global bond yields higher as traders bet the Strait of Hormuz stays shut. A third straight night of U.S. strikes on Iran, President Trump's reimposed naval blockade, and his 20% Hormuz transit fee drove Brent toward $87 and pushed the U.K. ten-year gilt yield back above 5%, its highest since May, reviving inflation fears across stock and bond markets as the strait that carries roughly a fifth of the world's oil chokes. - WSJ Markets: https://www.wsj.com/finance/commodities-futures/oil-surges-most-since-2020-reflecting-bet-that-strait-wont-go-back-to-normal-9aa1639f?mod=rss_markets_main - FT Markets: https://www.ft.com/content/2d899824-5f94-4f0c-81fc-c54a0750e498 - FT Markets: https://www.ft.com/content/107fc895-14db-4003-baa0-d81ed29c477f - WSJ World News: https://www.wsj.com/world/middle-east/u-s-launches-new-iran-strikes-as-trump-weighs-attacking-nuclear-site-156d2109 PITTSBURGH ---------------------------------------------------------------- Weather: Today: Sunny, high 94F. Tonight: Mostly Clear, low 73F. Wednesday: Mostly Sunny, high 97F. Business: * Street Fries Truck Opens South Side Base Latest developments: The Street Fries food truck announced on Instagram the soft launch of a permanent home at 1210 East Carson Street in the South Side. Street Fries Forever, a loaded-fries purveyor, will serve from 1210 East Carson Street in Pittsburgh's South Side, Wednesday through Sunday, with some nights running as late as 2 a.m. - Pittsburgh City Paper: https://www.pghcitypaper.com/food-drink/loaded-fries-beets-and-beats-corny-fun-and-more-pittsburgh-food-news/ * Eat’n Park Debuts Pickle Smiley Cookie Latest developments: Eat'n Park unveiled a pickle-themed version of its Smiley Cookie to mark the Picklesburgh festival. Eat'n Park is selling a Pickle Smiley Cookie, a new take on its signature dessert, at some Pittsburgh-area restaurants and at the Picklesburgh festival itself. - WPXI: https://www.wpxi.com/news/local/eatn-park-celebrates-picklesburgh-with-pickle-smiley-cookie/NP5VOPE62RGAPMS2EPR34PR57A/ Around town: * Parkway East Detours Strain Neighborhoods Latest developments: Public transit ridership rose and Regent Square residents reported gridlock as the Parkway East closure entered its fourth day. The 25-day closure of the Parkway East (I-376) for the Commercial Street Bridge replacement is funneling tens of thousands of drivers through Pittsburgh neighborhoods including Regent Square and Homestead, snarling the evening rush and pushing more commuters onto Pittsburgh Regional Transit. - WPXI: https://www.wpxi.com/news/local/public-transit-sees-boost-riders-people-navigate-parkway-east-closure/GBUSSIQIMRHUXMYOLNW2JNOS2U/ - WPXI: https://www.wpxi.com/news/local/regent-square-residents-say-their-community-was-gridlocked-by-parkway-east-detour/V3QM7DQI7VGQBOFSN237BV5ER4/ - WTAE: https://www.wtae.com/article/drivers-cyclists-adjust-to-busier-parkway-east-detour-routes/71924155 * Pittsburgh Opens Cooling Centers in Heat Latest developments: The city of Pittsburgh opened multiple cooling centers this week as another round of hot, humid weather settled over Western Pennsylvania. Pittsburgh opened several cooling centers as forecasters flagged an Impact Day for hot, humid conditions across Western Pennsylvania. - WPXI: https://www.wpxi.com/news/local/multiple-cooling-centers-open-pittsburgh-this-week/FZCLSU474BFEFFPRJYHHAG4W7U/ - WTAE: https://www.wtae.com/article/impact-day-hot-humid-for-western-pa/71927509 SPORTS ---------------------------------------------------------------- Pirates (50-47) Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM https://plaintextsports.com/mlb/2026-07-17/pit-cle Around the Teams: * Pirates Fill Out 2026 Draft Class Latest developments: The Post-Gazette recapped all 16 players the Pirates added on Day 2 of the MLB Draft, among them Marohn, Fay, Phelps, and Bryson Moore, after taking LSU outfielder Derek Curiel fifth overall. Pittsburgh's 2026 MLB Draft haul, headlined by No. 5 overall pick Derek Curiel of LSU, grew to 16 more selections on Day 2 as the Pirates stocked their farm system ahead of the second half. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/07/12/mlb-draft-pirates-marohn-fay-phelps-bryson-moore/stories/202607120098 Team USA: * Balogun Signs With LeBron James’s Klutch Latest developments: United States forward Folarin Balogun signed with LeBron James's Klutch Sports agency following a breakout 2026 World Cup. Folarin Balogun, the Monaco and U.S. men's national team striker whose World Cup play raised his profile on and off the pitch, joined LeBron James's Klutch Sports agency. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49356529/folarin-balogun-joins-lebron-james-klutch-sports-agency-breakout-world-cup * Revolution Extend Matt Turner Loan Latest developments: The New England Revolution extended the loan of U.S. goalkeeper Matt Turner from Lyon through the end of 2026. The New England Revolution kept United States men's national team goalkeeper Matt Turner on loan from France's Lyon through the end of the 2026 season. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49350801/new-england-revolution-extend-contract-usmnt-gk-matt-turner-loan-lyon READING ---------------------------------------------------------------- * Stratechery -- The OpenAI Super App, ChatGPT = Codex, Whither Chat Argues that OpenAI has refashioned its Codex coding tool into the new ChatGPT, and asks whether the company is walking away from the chat category it pioneered. https://stratechery.com/2026/the-openai-super-app-chatgpt-codex-whither-chat/ * Cal Newport -- Why Reading Matters Responds to Rose Horowitch's Atlantic piece 'The End of Reading is Here,' making the case for why sustained, deep reading still matters. https://calnewport.com/why-reading-matters/ * Ed Zitron -- Premium: The Hater's Guide To The Memory Crisis A skeptical, detailed teardown of the industry narrative around the memory crisis. https://www.wheresyoured.at/premium-the-haters-guide-to-the-memory-crisis/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,524.19 ▲ +0.5% Dow 52,579.32 ▲ +0.1% Nasdaq 26,010.20 = +0.0% WTI crude 73.12 ▲ +5.6% EUR/USD 1.1421 ▲ +0.1% GBP/USD 1.3389 ▲ +0.7% USD/JPY 162.25 ▲ +0.2% ================================================================ Generated 2026-07-14 06:05 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================