================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Thursday, July 16, 2026 - 6:06 AM EDT ================================================================ Microsoft-signed UEFI shims hand attackers a cross-platform Secure Boot bypass, capping a vulnerability-heavy day that also brought a critical Zoom account-takeover fix and a fresh Cisco Talos threat-actor disclosure. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] OpenAI's GPT-Red automated red-teamer beat human testers at prompt injection the same day an unpatched Cursor editor flaw was weaponized, putting AI on both sides of exploit discovery. see: AI Coding Tools and Automated Red-Teaming * [TREND] Sophos and Dark Reading find identity attacks and phishing have overtaken software exploits as ransomware's top entry point, even as multifactor authentication fails to stop credential compromises. see: Ransomware Report: Identity Attacks Overtake Exploits * [TREND] Researchers found nearly a dozen forgotten Microsoft-signed UEFI shim bootloaders still trusted years after revocation, handing attackers a Secure Boot bypass on any operating system. see: Microsoft-Signed UEFI Shims Bypass Secure Boot * [UPDATE (new)] Zoom patched a CVSS 9.8 account-hijack flaw CVE-2026-53412 while F5 fixed multiple NGINX and BIG-IP bugs across its Windows clients. see: Critical Zoom, F5, and Security-Vendor Patches * [UPDATE (new)] Cisco Talos disclosed UAT-11795, a Russian-speaking, financially motivated crew deploying the novel Starland RAT against US and European targets. see: UAT-11795 Deploys Starland RAT * [UPDATE (new)] A cyberattack on Japan's Nichirei Logistics left Kentucky Fried Chicken restaurants short on ingredients and forced restaurant chains to scramble. see: Nichirei Logistics Attack Disrupts KFC SECURITY ---------------------------------------------------------------- 1. CRITICAL ZOOM, F5, AND SECURITY-VENDOR PATCHES Vulnerabilities and Exploits · [patch, vulnerability] Latest developments: Zoom patched CVE-2026-53412, a CVSS 9.8 improper-input-validation flaw that lets an unauthenticated attacker hijack accounts across its Windows Desktop, VDI, and Meeting SDK clients, while F5 fixed multiple NGINX and BIG-IP bugs enabling config changes, memory leaks, and code execution, and Trend Micro, Tanium, ESET, and Tenable each patched critical flaws in their own products. The Zoom fix closes an account-takeover path that needs no login, and the F5 and endpoint-vendor fixes span gear that sits at the network edge and inside security stacks. Organizations should update all four vendors' affected clients and appliances now. - The Hacker News: https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability/ - SecurityWeek: https://www.securityweek.com/f5-patches-multiple-nginx-big-ip-vulnerabilities/ - SecurityWeek: https://www.securityweek.com/trend-micro-tanium-eset-and-tenable-patch-severe-product-vulnerabilities/ 2. AI CODING TOOLS AND AUTOMATED RED-TEAMING AI Security · [ai, prompt-injection, code-execution] Latest developments: OpenAI detailed GPT-Red, an automated red-teamer trained by self-play reinforcement learning that beat human testers at finding prompt-injection weaknesses and now adversarially hardens GPT-5.6 Sol, while researchers showed an unpatched Cursor flaw on Windows that silently runs a git.exe planted in a cloned repository's root, executing as the user with their SSH keys and cloud tokens. GPT-Red turns exploit discovery into an automated loop that outpaces human red teams, and the Cursor bug shows the same automation cuts the other way, turning a hostile repository into instant code execution. Developers should avoid opening untrusted repositories in Cursor until a fix ships. - The Hacker News: https://thehackernews.com/2026/07/openais-gpt-red-automates-prompt.html - Help Net Security: https://www.helpnetsecurity.com/2026/07/16/openai-gpt-red-prompt-injection-test/ - The Hacker News: https://thehackernews.com/2026/07/cursor-flaw-lets-malicious-cloned.html - SecurityWeek: https://www.securityweek.com/unpatched-cursor-vulnerability-exposes-users-to-code-execution/ 3. MICROSOFT-SIGNED UEFI SHIMS BYPASS SECURE BOOT Vulnerabilities and Exploits · [vulnerability, secure-boot] Latest developments: Researchers disclosed nearly a dozen old, Microsoft-signed UEFI shim bootloaders that stayed trusted for years after revocation, letting an attacker load unsigned code and bypass Secure Boot on any machine regardless of operating system. A shim is a small Microsoft-signed bootloader that Linux distributions use to chain Secure Boot trust; because these outdated shims remain trusted until firmware revocation lists catch up, they open a path to run malicious code before the OS starts. Administrators should apply the latest UEFI dbx revocation updates. - SecurityWeek: https://www.securityweek.com/old-uefi-shims-expose-systems-to-secure-boot-bypass/ - Dark Reading: https://www.darkreading.com/cyber-risk/forgotten-bootloaders-expose-secure-boot-blind-spot 4. RANSOMWARE REPORT: IDENTITY ATTACKS OVERTAKE EXPLOITS Ransomware and Cybercrime · [ransomware, phishing] Latest developments: Sophos' State of Ransomware 2026, a survey of 2,158 IT and security leaders, found ransom demands falling while malicious email and phishing now cause half of all incidents, and Dark Reading reported identity attacks have overtaken vulnerability exploits as the top ransomware root cause, with multifactor authentication present in 97 percent of credential-based compromises yet failing to prevent them. The data marks a shift from software exploitation toward stolen and phished credentials as the opening move in ransomware cases. Companies should harden email defenses, phishing-resistant authentication, and identity monitoring rather than lean on MFA alone. - Help Net Security: https://www.helpnetsecurity.com/2026/07/16/sophos-state-of-ransomware-2026/ - Dark Reading: https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause 5. UAT-11795 DEPLOYS STARLAND RAT Ransomware and Cybercrime · [malware, rat] Latest developments: Cisco Talos disclosed UAT-11795, a Russian-speaking, financially motivated adversary that since at least June 2025 has targeted users in the United States and Europe with a novel Starland remote access trojan and a bespoke WLDR command-and-control implant. UAT-11795 pairs the custom Starland RAT with the WLDR implant to seize remote control of victim machines across the United States and Europe. Defenders should hunt for the indicators of compromise Talos published with the report. - Cisco Talos: https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/ 6. NICHIREI LOGISTICS ATTACK DISRUPTS KFC Critical Infrastructure Security · [cyberattack, supply-chain] Latest developments: A cyberattack on Nichirei Logistics Group, Japan's largest cold-chain operator, left Kentucky Fried Chicken restaurants short on ingredients and forced major restaurant chains to scramble to keep deliveries moving. Nichirei runs the refrigerated warehousing and transport that feeds Japanese restaurant supply chains, so the intrusion cascaded straight into food deliveries. The company has not yet detailed the attack's cause or attacker. - The Record: https://therecord.media/cyberattack-japan-nichirei-logistics-impacts-kfc BUSINESS AND POLITICS ---------------------------------------------------------------- * U.S.-Iran Standoff Over Hormuz Latest developments: Iran freed a U.S. citizen it had held more than a year as what Trump called a good-will gesture, and crude steadied after three straight days of gains even as diplomacy over the strait stayed gridlocked. The United States and Iran remain locked in armed conflict over the Strait of Hormuz, the chokepoint for roughly a fifth of the world's seaborne oil, where a U.S. naval blockade and repeated strikes have driven an energy-price rally that is padding second-quarter results at majors like TotalEnergies. - WSJ Markets: https://www.wsj.com/finance/commodities-futures/oil-rises-amid-prospects-of-escalating-mideast-conflict-7f8ab657?mod=rss_markets_main - WSJ World News: https://www.wsj.com/world/middle-east/iran-allows-u-s-citizen-it-held-for-more-than-a-year-to-leave-035b44e0 * U.S. Imposes 25% Tariff on Brazil Latest developments: The Trump administration set a 25% tariff on certain Brazilian goods, closing a yearlong U.S. trade investigation into practices it deemed unfair. Washington's levy on the world's tenth-largest economy deepens a diplomatic rift with Brasília ahead of a South American presidential election, hitting exporters of a country that runs a large agricultural and industrial trade with the United States. - WSJ World News: https://www.wsj.com/economy/trade/u-s-to-impose-25-tariff-on-certain-goods-from-brazil-2f1bd33a - FT World: https://www.ft.com/content/97050622-ca1e-45d9-9541-b87aeb15fd24 * Bank of Korea Hikes as Chip Stocks Crater Latest developments: The Bank of Korea, under new governor Shin Hyun-song, raised rates for the first time in three years, and Korean shares slumped as SK Hynix and Samsung Electronics cratered, briefly halting trading on the Korea Exchange. A sharp reversal in memory-chip shares, the epicenter of the global AI-infrastructure trade, is rippling from Seoul into U.S. futures and reviving fears that the AI equity boom has run ahead of itself. - FT World: https://www.ft.com/content/bb1a1582-c522-4c5d-a769-45ba9f5a3054 - WSJ Markets: https://www.wsj.com/finance/stocks/u-s-stock-futures-fall-on-fresh-ai-wobble-a7d12092?mod=rss_markets_main PITTSBURGH ---------------------------------------------------------------- Weather: Today: Mostly Sunny then Smoke, high 93F. Tonight: Smoke, low 67F. Friday: Smoke, high 92F. Business: * WVU, Pitt, CMU Land $160M Energy Hub Latest developments: West Virginia University won $160 million in new government funding to anchor an industrial-energy innovation hub with the University of Pittsburgh and Carnegie Mellon University. The National Science Foundation is funding the RETI Engine, which pairs WVU, Pitt, and CMU to develop industrial-energy technology across the Appalachian region. - Pittsburgh Post-Gazette: https://www.post-gazette.com/business/tech-news/2026/07/16/national-science-foundation-reti-engine-wvu-pitt-cmu/stories/202607150065 * PJM Capacity Price Hits Cap Again Latest developments: PJM Interconnection's latest capacity auction cleared at the price cap once more, and chief executive David Mills said electricity demand keeps outrunning supply. The result signals another round of higher electricity bills across PJM's multistate grid, which includes Pennsylvania, as data-center load and slow generation buildout strain the system. - PublicSource: https://www.publicsource.org/pjm-electricity-energy-pennsylvania-utilities-rates/ Around town: * Allegheny County Pension Shortfall Hits $1.4 Billion Latest developments: A report out Thursday, July 16, from county treasurer Erica Rocchi Brusselars pegs Allegheny County's pension shortfall at $1.4 billion and warns the county must add $100 million a year for 20 years to close it. Years of deferral left the county pension fund badly underfunded, and the fix demands large annual cash infusions that will squeeze the budget under County Executive Sara Innamorato. - KDKA: https://www.cbsnews.com/pittsburgh/news/allegheny-county-pension-fund-report/ - Pittsburgh Post-Gazette: https://www.post-gazette.com/local/city/2026/07/16/allegheny-county-pension-crisis-funding-ratio-peduto-innamorato/stories/202607160002 * Water Main Break Closes Parkway East Detour Latest developments: A serious water main break Wednesday evening closed part of South Braddock Avenue, one of the main detour routes around the shut Parkway East. With I-376 closed 25 days for the Commercial Street Bridge replacement, roughly 100,000 daily drivers lean on detours such as South Braddock Avenue, and losing part of it tightens the squeeze through the East End. - WTAE: https://www.wtae.com/article/south-braddock-avenue-parkway-east-detour-closed-water-main-break/72047697 * Jewish Federation Boosts Security Funding Latest developments: The Jewish Federation of Greater Pittsburgh approved a $150,000 increase in security funding for the coming year. The money buys guards, cameras, secure doors, and training for area houses of worship; Shawn Brokos directs the federation's community security program. - KDKA: https://www.cbsnews.com/pittsburgh/news/jewish-federation-of-greater-pittsburgh-security-funding/ Events: * Century Plant Blooms at Phipps Latest developments: An Agave americana at Phipps Conservatory has shot a bloom stalk clear through the glass ceiling, a once-in-a-lifetime flowering now on view. The century plant, which blooms only once before it dies, is spiking above the roofline at Phipps Conservatory and Botanical Gardens in Oakland's Schenley Park, a rare sight visitors can catch during regular hours. - Pittsburgh Post-Gazette: https://www.post-gazette.com/life/garden/2026/07/16/adios-agave-americana-century-plant-phipps-conservatory-pittsburgh/stories/202607160015 * Collage Cafe in Bloomfield Latest developments: The Pittsburgh Collage Collective hosts a free drop-in Collage Cafe on Thursday, July 16. Collage Cafe runs Thursday, July 16, from 5 to 7 p.m. at Creative Chem Co., 4618 Friendship Avenue in Bloomfield; admission is free and open to ages 16 and up. - Pittsburgh City Paper: https://www.pghcitypaper.com/listings/this-weeks-top-events/pittsburghs-top-events-thu-july-16-wed-july-22/ SPORTS ---------------------------------------------------------------- Pirates (50-47) Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM https://plaintextsports.com/mlb/2026-07-17/pit-cle Around the Teams: * Ramsey as Graham's Chess Piece Latest developments: The Post-Gazette's July 16 training-camp countdown argues cornerback Jalen Ramsey must become defensive coordinator Patrick Graham's most versatile weapon as camp opens in Latrobe. The piece lays out how Graham plans to move Ramsey around the formation, playing him at outside corner, in the slot, and near the box to disguise coverages for the Steelers defense. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/16/trainingcamp-jalen-ramsey-latrobe-graham/stories/202607160004 * MLB Salary-Cap Fight Wears On Latest developments: Post-Gazette Pirates writer Noah Hiles calls the escalating salary-cap fight between MLB and the players' union already exhausting. Hiles' column casts the standoff between commissioner Rob Manfred and MLBPA lead negotiator Bruce Meyer as a drawn-out slog that hangs over small-market clubs like the Pirates as the sides inch toward the next labor deal. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/07/15/hiles-column-salarycap-mlbpa-cba-bargaining/stories/202607150035 Team USA: * Flavor Flav Backs Team USA Women's Hockey Latest developments: ESPN detailed how rapper Flavor Flav became the driving force behind the inaugural SHE Weekend in Las Vegas, his biggest show of support yet for women's sports. Flavor Flav, who has grown into an unlikely champion of American women's sports, built SHE Weekend around the Team USA women's ice hockey program, extending his patronage of the national team. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49368037/she-weekend-las-vegas-flavor-flav-team-usa-womens-ice-hockey READING ---------------------------------------------------------------- * Ed Zitron -- The OpenAI Bubble Zitron argues OpenAI sits at the heart of an inflating AI financial bubble, dissecting the company's spending, revenue claims, and dependence on ever-larger capital raises. https://www.wheresyoured.at/the-openai-bubble/ * Stratechery -- IBM Misses, IBM's Mainframe Moat, IBM's Many AI Problems Ben Thompson reads IBM's weak preliminary results as a company-specific story, arguing its durable mainframe franchise still anchors the business while AI exposes deeper strategic weaknesses. https://stratechery.com/2026/ibm-misses-ibms-mainframe-moat-ibms-many-ai-problems/ * Cal Newport -- Why Reading Matters Responding to Rose Horowitch's Atlantic piece on declining literacy, Newport defends deep reading as essential cognitive training rather than a nostalgic pastime. https://calnewport.com/why-reading-matters/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,550.07 ▲ +0.7% Dow 52,557.99 ▼ -0.3% Nasdaq 26,147.58 ▲ +0.8% WTI crude 76.11 ▲ +8.8% EUR/USD 1.1414 = -0.0% GBP/USD 1.3389 ▲ +0.3% USD/JPY 162.28 ▲ +0.2% ================================================================ Generated 2026-07-16 06:06 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================