daily plain-text briefing: security, markets, business, and pittsburgh
Microsoft-signed UEFI shims hand attackers a cross-platform Secure Boot bypass, capping a vulnerability-heavy day that also brought a critical Zoom account-takeover fix and a fresh Cisco Talos threat-actor disclosure.
Latest developments: Zoom patched CVE-2026-53412, a CVSS 9.8 improper-input-validation flaw that lets an unauthenticated attacker hijack accounts across its Windows Desktop, VDI, and Meeting SDK clients, while F5 fixed multiple NGINX and BIG-IP bugs enabling config changes, memory leaks, and code execution, and Trend Micro, Tanium, ESET, and Tenable each patched critical flaws in their own products.
The Zoom fix closes an account-takeover path that needs no login, and the F5 and endpoint-vendor fixes span gear that sits at the network edge and inside security stacks. Organizations should update all four vendors' affected clients and appliances now.
Sources: The Hacker News · BleepingComputer · SecurityWeek · SecurityWeek · ↑ top
Latest developments: OpenAI detailed GPT-Red, an automated red-teamer trained by self-play reinforcement learning that beat human testers at finding prompt-injection weaknesses and now adversarially hardens GPT-5.6 Sol, while researchers showed an unpatched Cursor flaw on Windows that silently runs a git.exe planted in a cloned repository's root, executing as the user with their SSH keys and cloud tokens.
GPT-Red turns exploit discovery into an automated loop that outpaces human red teams, and the Cursor bug shows the same automation cuts the other way, turning a hostile repository into instant code execution. Developers should avoid opening untrusted repositories in Cursor until a fix ships.
Sources: The Hacker News · Help Net Security · The Hacker News · SecurityWeek · ↑ top
Latest developments: Researchers disclosed nearly a dozen old, Microsoft-signed UEFI shim bootloaders that stayed trusted for years after revocation, letting an attacker load unsigned code and bypass Secure Boot on any machine regardless of operating system.
A shim is a small Microsoft-signed bootloader that Linux distributions use to chain Secure Boot trust; because these outdated shims remain trusted until firmware revocation lists catch up, they open a path to run malicious code before the OS starts. Administrators should apply the latest UEFI dbx revocation updates.
Sources: SecurityWeek · Dark Reading · ↑ top
Latest developments: Sophos' State of Ransomware 2026, a survey of 2,158 IT and security leaders, found ransom demands falling while malicious email and phishing now cause half of all incidents, and Dark Reading reported identity attacks have overtaken vulnerability exploits as the top ransomware root cause, with multifactor authentication present in 97 percent of credential-based compromises yet failing to prevent them.
The data marks a shift from software exploitation toward stolen and phished credentials as the opening move in ransomware cases. Companies should harden email defenses, phishing-resistant authentication, and identity monitoring rather than lean on MFA alone.
Sources: Help Net Security · Dark Reading · ↑ top
Latest developments: Cisco Talos disclosed UAT-11795, a Russian-speaking, financially motivated adversary that since at least June 2025 has targeted users in the United States and Europe with a novel Starland remote access trojan and a bespoke WLDR command-and-control implant.
UAT-11795 pairs the custom Starland RAT with the WLDR implant to seize remote control of victim machines across the United States and Europe. Defenders should hunt for the indicators of compromise Talos published with the report.
Sources: Cisco Talos · ↑ top
Latest developments: A cyberattack on Nichirei Logistics Group, Japan's largest cold-chain operator, left Kentucky Fried Chicken restaurants short on ingredients and forced major restaurant chains to scramble to keep deliveries moving.
Nichirei runs the refrigerated warehousing and transport that feeds Japanese restaurant supply chains, so the intrusion cascaded straight into food deliveries. The company has not yet detailed the attack's cause or attacker.
Sources: The Record · ↑ top
Latest developments: Iran freed a U.S. citizen it had held more than a year as what Trump called a good-will gesture, and crude steadied after three straight days of gains even as diplomacy over the strait stayed gridlocked.
The United States and Iran remain locked in armed conflict over the Strait of Hormuz, the chokepoint for roughly a fifth of the world's seaborne oil, where a U.S. naval blockade and repeated strikes have driven an energy-price rally that is padding second-quarter results at majors like TotalEnergies.
Sources: WSJ Markets · WSJ World News · ↑ top
Latest developments: The Trump administration set a 25% tariff on certain Brazilian goods, closing a yearlong U.S. trade investigation into practices it deemed unfair.
Washington's levy on the world's tenth-largest economy deepens a diplomatic rift with Brasília ahead of a South American presidential election, hitting exporters of a country that runs a large agricultural and industrial trade with the United States.
Sources: WSJ World News · FT World · ↑ top
Latest developments: The Bank of Korea, under new governor Shin Hyun-song, raised rates for the first time in three years, and Korean shares slumped as SK Hynix and Samsung Electronics cratered, briefly halting trading on the Korea Exchange.
A sharp reversal in memory-chip shares, the epicenter of the global AI-infrastructure trade, is rippling from Seoul into U.S. futures and reviving fears that the AI equity boom has run ahead of itself.
Sources: FT World · WSJ Markets · ↑ top
Today: Mostly Sunny then Smoke, high 93F.
Tonight: Smoke, low 67F.
Friday: Smoke, high 92F.
Latest developments: West Virginia University won $160 million in new government funding to anchor an industrial-energy innovation hub with the University of Pittsburgh and Carnegie Mellon University.
The National Science Foundation is funding the RETI Engine, which pairs WVU, Pitt, and CMU to develop industrial-energy technology across the Appalachian region.
Sources: Pittsburgh Post-Gazette · ↑ top
Latest developments: PJM Interconnection's latest capacity auction cleared at the price cap once more, and chief executive David Mills said electricity demand keeps outrunning supply.
The result signals another round of higher electricity bills across PJM's multistate grid, which includes Pennsylvania, as data-center load and slow generation buildout strain the system.
Sources: PublicSource · ↑ top
Latest developments: A report out Thursday, July 16, from county treasurer Erica Rocchi Brusselars pegs Allegheny County's pension shortfall at $1.4 billion and warns the county must add $100 million a year for 20 years to close it.
Years of deferral left the county pension fund badly underfunded, and the fix demands large annual cash infusions that will squeeze the budget under County Executive Sara Innamorato.
Sources: KDKA · Pittsburgh Post-Gazette · ↑ top
Latest developments: A serious water main break Wednesday evening closed part of South Braddock Avenue, one of the main detour routes around the shut Parkway East.
With I-376 closed 25 days for the Commercial Street Bridge replacement, roughly 100,000 daily drivers lean on detours such as South Braddock Avenue, and losing part of it tightens the squeeze through the East End.
Latest developments: The Jewish Federation of Greater Pittsburgh approved a $150,000 increase in security funding for the coming year.
The money buys guards, cameras, secure doors, and training for area houses of worship; Shawn Brokos directs the federation's community security program.
Latest developments: An Agave americana at Phipps Conservatory has shot a bloom stalk clear through the glass ceiling, a once-in-a-lifetime flowering now on view.
The century plant, which blooms only once before it dies, is spiking above the roofline at Phipps Conservatory and Botanical Gardens in Oakland's Schenley Park, a rare sight visitors can catch during regular hours.
Sources: Pittsburgh Post-Gazette · ↑ top
Latest developments: The Pittsburgh Collage Collective hosts a free drop-in Collage Cafe on Thursday, July 16.
Collage Cafe runs Thursday, July 16, from 5 to 7 p.m. at Creative Chem Co., 4618 Friendship Avenue in Bloomfield; admission is free and open to ages 16 and up.
Sources: Pittsburgh City Paper · ↑ top
Pirates (50-47)
Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM
Latest developments: The Post-Gazette's July 16 training-camp countdown argues cornerback Jalen Ramsey must become defensive coordinator Patrick Graham's most versatile weapon as camp opens in Latrobe.
The piece lays out how Graham plans to move Ramsey around the formation, playing him at outside corner, in the slot, and near the box to disguise coverages for the Steelers defense.
Sources: Post-Gazette Steelers · ↑ top
Latest developments: Post-Gazette Pirates writer Noah Hiles calls the escalating salary-cap fight between MLB and the players' union already exhausting.
Hiles' column casts the standoff between commissioner Rob Manfred and MLBPA lead negotiator Bruce Meyer as a drawn-out slog that hangs over small-market clubs like the Pirates as the sides inch toward the next labor deal.
Sources: Post-Gazette Pirates · ↑ top
Latest developments: ESPN detailed how rapper Flavor Flav became the driving force behind the inaugural SHE Weekend in Las Vegas, his biggest show of support yet for women's sports.
Flavor Flav, who has grown into an unlikely champion of American women's sports, built SHE Weekend around the Team USA women's ice hockey program, extending his patronage of the national team.
Sources: ESPN Olympics · ↑ top
S&P 500 7,550.07 ▲ +0.7% Dow 52,557.99 ▼ -0.3% Nasdaq 26,147.58 ▲ +0.8% WTI crude 76.11 ▲ +8.8% EUR/USD 1.1414 = -0.0% GBP/USD 1.3389 ▲ +0.3% USD/JPY 162.28 ▲ +0.2%