================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Tuesday, July 14, 2026 - 12:05 PM EDT ================================================================ The U.S. Treasury and European allies opened a coordinated sanctions front against ransomware enablers and Russian state hackers as poisoned npm packages and browser extensions turned the software supply chain into the day's broadest attack surface. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Threat actors keep turning open registries into malware hosting, backdooring a Jscrambler npm package and standing up 148 fake student-proxy modules that conscripted browsers into a DDoS botnet. see: Supply Chain Poisoning Across npm and Browser Extensions * [TREND] Intrusion crews are abusing pre-wired OAuth trust, with ShinyHunters walking into Salesforce and client-ID spoofing validating stolen Entra credentials without tripping sign-in alerts. see: OAuth Abuse Against Cloud Identity * [TREND] Western governments piled on financial pressure as OFAC hit ransomware-enabling First VPN and the UK and EU jointly sanctioned Russian operatives amid Dutch reports of hijacked cameras. see: U.S. Sanctions Ransomware Enablers; Russian Camera Espionage and Western Cyber Sanctions * [UPDATE (new)] Microsoft will make passkeys the default sign-in for Entra ID next September while Google rolls out FIDO2 keys and phone passkeys. see: Passkeys Become the Default in Entra ID * [UPDATE (new)] Jamf Threat Labs flagged CrashStealer, a native C++ macOS infostealer disguised as Apple's crash reporter that uses a notarized dropper to slip past Gatekeeper. see: CrashStealer macOS Infostealer * [UPDATE (new)] Pittsburgh opened cooling centers for a return to the 90s while PennDOT tweaked Parkway East detours and Picklesburgh returns downtown this weekend. see: Cooling Centers Open in Heat Wave; PennDOT Adjusts Parkway East Detours; Picklesburgh Returns This Weekend SECURITY ---------------------------------------------------------------- 1. RUSSIAN CAMERA ESPIONAGE AND WESTERN CYBER SANCTIONS Nation-State Activity · [apt, policy, surveillance] Latest developments: The UK and EU jointly sanctioned Russian individuals and entities for the first time over cyberattacks and disinformation, and Dutch intelligence disclosed that a Russian agency is hijacking internet-connected cameras across Europe to watch NATO military logistics and Ukrainian troops. The moves extend the July 13 CISA-led advisory warning that FSB-linked actors compromise poorly secured routers to build residential proxies inside critical-infrastructure networks; operators should patch and harden edge devices and internet-connected cameras. - The Record: https://therecord.media/russian-intelligence-compromising-cameras-nato-ukraine-netherlands - Dark Reading: https://www.darkreading.com/endpoint-security/weak-security-fuel-russian-cyberattacks - SecurityWeek: https://www.securityweek.com/us-allies-warn-of-russian-cyberattacks-targeting-critical-infrastructure-routers/ - Ars Technica Security: https://arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router/ 2. SUPPLY CHAIN POISONING ACROSS NPM AND BROWSER EXTENSIONS Vulnerabilities and Exploits · [supply-chain, npm, breach] Latest developments: Researchers disclosed a cluster of registry-based attacks: a backdoored Jscrambler npm package downloaded nearly 1,500 times, 148 npm modules posing as student web proxies that turned browsers into a DDoS botnet for two weeks in May, and the removal of ModHeader, a 1.6-million-install browser extension carrying a dormant browsing-history collector. The campaigns exploit trust in the npm registry and browser extension stores; a KU Leuven study separately found 85 popular crypto wallet extensions leak addresses and enable cross-site tracking. Audit dependencies and extension permissions. - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-backdoor-jscrambler-npm-package-with-infostealer-malware/ - The Hacker News: https://thehackernews.com/2026/07/148-npm-packages-disguised-as-student.html - The Hacker News: https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html - The Hacker News: https://thehackernews.com/2026/07/study-of-85-crypto-wallet-extensions.html 3. PASSKEYS BECOME THE DEFAULT IN ENTRA ID Identity and Access Management · [passkeys, mfa, identity] Latest developments: Microsoft will make passkeys the default sign-in for Entra ID in the public cloud on September 1, 2026, and require SMS or voice users to register a passkey by February 1, 2027, while Google began rolling out FIDO2 security keys and phone passkeys for Windows login through GCPW. The shifts push enterprise identity toward phishing-resistant authentication as credential-phishing kits proliferate. Administrators should prepare users for passkey enrollment and enforce FIDO2 second factors. - BleepingComputer: https://www.bleepingcomputer.com/news/microsoft/microsoft-entra-id-gets-passkeys-default-authentication-starting-september/ - Help Net Security: https://www.helpnetsecurity.com/2026/07/14/microsoft-entra-passkey-authentication/ - Help Net Security: https://www.helpnetsecurity.com/2026/07/14/security-key-windows-login-google-workspace/ - Microsoft Security Blog: https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/ 4. U.S. SANCTIONS RANSOMWARE ENABLERS Ransomware and Cybercrime · [ransomware, sanctions, policy] Latest developments: OFAC sanctioned First VPN Service and its 45-year-old Ukrainian administrator along with a Belarusian seller of malware cryptors, the Treasury's first designation of a VPN provider for enabling ransomware. First VPN Service, known as 1VPNS, rented anonymizing infrastructure to ransomware crews attacking U.S. organizations; the sanctions freeze the operators' U.S. assets and bar Americans from transacting with them. - The Hacker News: https://thehackernews.com/2026/07/us-sanctions-first-vpn-service-and.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/us-sanctions-vpn-malware-providers-linked-to-ransomware-gangs/ - The Record: https://therecord.media/first-vpn-administrator-us-sanctions-ransomware-groups 5. CRASHSTEALER MACOS INFOSTEALER Ransomware and Cybercrime · [malware, macos, infostealer] Latest developments: Jamf Threat Labs identified CrashStealer, a native C++ macOS infostealer that disguises itself as Apple's crash-reporting tool and uses a notarized dropper to pass Gatekeeper, moving from development in May to in-the-wild use by early July. CrashStealer validates the victim's login password locally, then harvests passwords, Keychain data, and cryptocurrency wallets. Mac users should distrust unexpected crash-report prompts and verify app notarization. - Help Net Security: https://www.helpnetsecurity.com/2026/07/14/crashstealer-macos-infostealer-password-theft/ - The Hacker News: https://thehackernews.com/2026/07/crashstealer-macos-malware-uses.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/new-crashstealer-malware-poses-as-apple-crash-reporting-tool/ 6. OAUTH ABUSE AGAINST CLOUD IDENTITY Identity and Access Management · [oauth, saas, breach] Latest developments: Microsoft mapped three Salesforce attack paths from a year of ShinyHunters OAuth abuse, and researchers disclosed OAuth client ID spoofing, a technique two threat actors use to validate stolen Microsoft Entra credentials without generating a sign-in event. Attackers exploit the OAuth connections tying SaaS platforms to third-party apps, sidestepping platform flaws entirely; separate RabbitMQ access-control bugs can leak the broker's OAuth client secrets and cross tenant boundaries. Review OAuth grants and guest access. - Microsoft Security Blog: https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/ - The Hacker News: https://thehackernews.com/2026/07/oauth-client-id-spoofing-lets-attackers.html - The Hacker News: https://thehackernews.com/2026/07/rabbitmq-flaws-could-leak-oauth-secrets.html BUSINESS AND POLITICS ---------------------------------------------------------------- * Trump Reverses Hormuz Shipping Fee as Oil Nears $87 Latest developments: One day after floating a 20% toll on cargo crossing the Strait of Hormuz, Trump abandoned the plan Tuesday, saying he will replace it with trade and investment deals from Gulf states, and Brent crude touched $87 after fresh U.S. strikes answered Iranian attacks on tankers. The United States and Iran are fighting through their most dangerous stretch since an April truce collapsed; Washington launched a new round of strikes after Iranian forces hit commercial tankers in the Strait of Hormuz, the chokepoint for roughly a fifth of the world's oil, driving Brent above $85 and lifting Treasury yields and gold. - FT World: https://www.ft.com/content/359bc137-c375-4812-87a9-07fbba8e347f - WSJ World News: https://www.wsj.com/world/middle-east/trump-iran-strait-of-hormuz-us-toll-6d40a276 - FT World: https://www.ft.com/content/2d899824-5f94-4f0c-81fc-c54a0750e498 PITTSBURGH ---------------------------------------------------------------- Weather: Today: Sunny, high 94F. Tonight: Mostly Clear, low 73F. Wednesday: Mostly Sunny, high 97F. Business: * Two Tech Firms Lease at Bakery Square Latest developments: Two technology companies signed leases at Bakery Square in East Liberty, where owner Walnut Capital and the AI Strike Team policy group are branding the development and the surrounding Penn Avenue corridor as "AI Avenue." Bakery Square, built on the old Nabisco plant in East Liberty, has become a magnet for Pittsburgh tech startups, and Walnut Capital's push recasts the stretch of Penn Avenue as a hub for artificial-intelligence firms. - WPXI: https://www.wpxi.com/news/local/two-tech-companies-take-space-bakery-square/PBS5OOBLGFBQBHBGO7LIGEI5GM/ * Pennsylvania Rises to 13th in Business Ranking Latest developments: CNBC's annual "America's Top States for Business" study ranked Pennsylvania 13th, up from 17th in 2025, the state's best showing in 15 years and the highest among Northeastern states. The CNBC ranking grades states on economy, workforce, infrastructure, and cost, and Pennsylvania's climb marks a rebound for a state that has trailed its neighbors. - WPXI: https://www.wpxi.com/news/local/pennsylvania-climbs-13th-national-business-ranking-highest-15-years/JCXQB5KJGRATJPDNQDA54FHGNQ/ * Convention Center Posts Strong May Latest developments: The David L. Lawrence Convention Center Downtown netted more than $600,000 in May, lifted by steel-industry gatherings and volleyball tournaments. The Downtown Pittsburgh convention center's May surplus points to a busy events calendar drawing trade shows and tournaments back to the riverfront hall. - WPXI: https://www.wpxi.com/news/local/pittsburgh-convention-center-has-strong-may-driven-by-steel-volleyball-events/VQ4RLODIZZGGTKAHBKQ3ZZKOYU/ Around town: * PennDOT Adjusts Parkway East Detours Latest developments: Four days into the 25-day Parkway East closure, PennDOT says it has flagged several traffic pinch points and is adjusting signals around the clock from its command center as drivers hunt for routes around Homestead and Swissvale. PennDOT closed the Parkway East (I-376) on July 10 to slide a new Commercial Street Bridge into place, diverting roughly 100,000 daily drivers onto surface streets and Route 28 through August 3. - WTAE: https://www.wtae.com/article/parkway-east-detours-376-bridge-closure-penndot/71930354 * Cooling Centers Open in Heat Wave Latest developments: Pittsburgh opened cooling centers Tuesday as highs return to the 90s from July 14 through Friday, all First Alert Weather Days, under a Code Orange air-quality alert and a Code Red heat advisory across parts of southwestern Pennsylvania. A heat dome parked over the region pushes heat-index values toward 100, prompting the city to open cooling stations while the Pennsylvania DEP warns of unhealthy ozone. - TribLive: https://triblive.com/local/morning-roundup-air-quality-alert-issued-for-western-pa-pittsburgh-opens-cooling-centers-amid-heat-wave/ * ScareHouse Plans North Shore Halloween Venue Latest developments: ScareHouse, the nationally known Pittsburgh haunted attraction, is partnering with The Plaza at North Shore to launch a Halloween destination called the "Halloween Hangout." The collaboration gives ScareHouse a new seasonal home on the North Shore, adding a fall draw to the retail and entertainment complex near the stadiums. - WPXI: https://www.wpxi.com/news/local/scarehouse-partners-with-plaza-north-shore-create-new-halloween-destination/6CBUYRDLOZCFJBEK6J2LSSLDMU/ Events: * Picklesburgh Returns This Weekend Latest developments: Picklesburgh, the pickle-themed festival that USA Today readers have voted the country's No. 1 specialty food festival four times, runs Thursday, July 16, through Sunday, July 19, at multiple Pittsburgh locations. Picklesburgh serves handcrafted food and artisan drinks built around pickled ingredients from local chefs and restaurants, drawing crowds across several Downtown and neighborhood sites. - Pittsburgh Magazine: https://www.pittsburghmagazine.com/things-to-do-this-weekend-in-pittsburgh/ SPORTS ---------------------------------------------------------------- Pirates (50-47) Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM https://plaintextsports.com/mlb/2026-07-17/pit-cle Team USA: * Suni Lee Aims for Third Olympics Latest developments: American gymnastics star Suni Lee announced on Instagram Tuesday she is returning to the sport to chase a third Olympics at the 2028 Los Angeles Games, roughly two years out. Lee, the Olympic all-around champion, steps back toward elite competition as the U.S. gymnastics program builds toward a home Games in Los Angeles. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49358550/suni-lee-returning-gymnastics-two-years-la-olympics * Balogun Signs With LeBron's Klutch Sports Latest developments: U.S. striker Folarin Balogun signed with LeBron James's agency Klutch Sports after a breakout 2026 World Cup that raised his profile on and off the field. Balogun, the Monaco forward whose red-card suspension Trump lobbied FIFA to overturn, emerged as a standout of the American run before the round-of-16 exit to Belgium. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49356529/folarin-balogun-joins-lebron-james-klutch-sports-agency-breakout-world-cup READING ---------------------------------------------------------------- * Stratechery -- The OpenAI Super App, ChatGPT = Codex, Whither Chat Ben Thompson argues OpenAI has refashioned Codex into the new ChatGPT and asks whether the company is quietly walking away from the chat category it pioneered. https://stratechery.com/2026/the-openai-super-app-chatgpt-codex-whither-chat/ * Cal Newport -- Why Reading Matters Newport responds to Rose Horowitch's Atlantic piece "The End of Reading Is Here," making the case that sustained, deep reading remains essential even as attention spans fray. https://calnewport.com/why-reading-matters/ * Ed Zitron -- Premium: The Hater's Guide To The Memory Crisis Zitron delivers a skeptic's breakdown of the memory-chip crunch, tracing how surging demand and pricing tied to the AI buildout are squeezing the broader tech industry. https://www.wheresyoured.at/premium-the-haters-guide-to-the-memory-crisis/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,524.19 ▲ +0.5% Dow 52,579.32 ▲ +0.1% Nasdaq 26,010.20 = +0.0% WTI crude 73.12 ▲ +5.6% EUR/USD 1.1421 ▲ +0.1% GBP/USD 1.3389 ▲ +0.7% USD/JPY 162.25 ▲ +0.2% ================================================================ Generated 2026-07-14 12:05 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================