infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

Britain sentenced two Scattered Spider members to five and a half years for the Transport for London breach as CISA rushed federal agencies to patch an actively exploited Oracle flaw and China-linked espionage backdoors resurfaced across Asia.


Emerging Trends and Key Updates

Security

1. AI Agents Weaponized and Data-Injection Attacks

AI Security · [ai, prompt-injection, zero-day]

Latest developments: Researchers demonstrated a data-injection attack that corrupts the facts an AI agent trusts—one planted product review makes a shopping agent click Buy Now, one fake GitHub comment makes a coding assistant run a stranger's command—while Intruder unveiled a vulnerability vending machine that pairs code slicing with large language models and found an unknown WordPress plugin zero-day.

read more

Offensive AI is maturing on both sides: attackers hide malicious instructions in data an agent reads, and defenders automate zero-day discovery, though researchers stress a finding still has to be proven before it counts. Organizations deploying AI agents should treat all agent-read content as untrusted input.

Sources: The Hacker News · BleepingComputer · The Hacker News · ↑ top

2. Scattered Spider Members Sentenced for TfL Hack

Ransomware and Cybercrime · [cybercrime, arrest]

Latest developments: A British court sentenced two leading members of the Scattered Spider cybercrime collective to five years and six months each for the 2024 attack on Transport for London that cost the agency £29 million.

read more

Scattered Spider, a loose collective known for social-engineering help desks, breached Transport for London in 2024, forcing service and refund system outages. The prison terms mark one of the first major convictions of the group's members.

Sources: BleepingComputer · The Record · ↑ top

3. Crypto-Theft Malware Targets macOS and Hardware Wallets

Ransomware and Cybercrime · [malware, cryptocurrency]

Latest developments: SecurityWeek detailed ClickLock Stealer, a new macOS malware that uses social engineering and process killing to steal passwords and cryptocurrency from at least 100 users, while The Hacker News exposed OkoBot, a Windows framework running since April 2025 that injects seed-phrase phishing prompts into the legitimate Ledger and Trezor desktop apps.

read more

Both families chase cryptocurrency: ClickLock bypasses macOS protections to grab credentials and wallets, and OkoBot waits for victims to open real hardware-wallet software before demanding their recovery phrase. Users should ignore any in-app request to re-enter a seed phrase.

Sources: SecurityWeek · The Hacker News · ↑ top

4. China-Linked Backdoors Resurface Across Asia

Nation-State Activity · [apt, espionage, backdoor]

Latest developments: The Daxin kernel-mode rootkit reappeared after more than four years inside a Taiwan manufacturing firm alongside a new pre-login SYSTEM backdoor named Stupig, while Kaspersky detailed GoSerpent, an evolving backdoor stealing data from Southeast Asian government entities using the Stowaway RAT and a ThumbcacheService tool.

read more

Symantec first documented Daxin in March 2022 as a stealthy rootkit tied to Chinese espionage; its return signals renewed targeting of Taiwanese industry and Southeast Asian governments. Both campaigns run two-phase intrusions built for long-term data theft.

Sources: The Hacker News · Securelist (Kaspersky) · ↑ top

5. Spirals Ransomware Encrypts in Under 24 Hours

Ransomware and Cybercrime · [ransomware, breach]

Latest developments: A new ransomware actor called Spirals ran an entire corporate intrusion—from initial access through data theft to encryption—in less than 24 hours.

read more

Spirals compresses the ransomware kill chain into a single day, leaving defenders almost no window to detect and respond. Fast dwell-to-encryption times raise the premium on early identity and endpoint detection.

Sources: BleepingComputer · ↑ top

6. Active Exploitation of Oracle E-Business Suite

Vulnerabilities and Exploits · [patch, zero-day, cve]

Latest developments: CISA ordered federal agencies to patch the critical Oracle E-Business Suite financial-application flaw CVE-2026-46817 by Saturday, July 18, 2026, citing ongoing attacks.

read more

CVE-2026-46817 is a privilege-management flaw in Oracle's E-Business Suite that attackers are exploiting in the wild. Agencies and enterprises running the financial application should apply Oracle's fix immediately.

Sources: BleepingComputer · ↑ top

Business and Politics

U.S.-Iran War Widens as Hormuz Stays Shut

Latest developments: The Financial Times warns the renewed Strait of Hormuz closure now threatens a fresh oil-supply crunch as the commercial stockpiles that cushioned the war's early shocks run low, even as crude steadied after three straight days of gains with U.S.-Iran diplomacy gridlocked.

read more

The United States and Iran stay locked in open conflict around the Strait of Hormuz, through which roughly a fifth of the world's oil passes; Washington has blockaded Iran's ports and kept striking Iranian targets, holding global energy markets on edge.

Sources: Financial Times · WSJ Markets · ↑ top

Pittsburgh

Weather

Today: Mostly Sunny then Smoke, high 93F.

Tonight: Smoke, low 67F.

Friday: Smoke, high 92F.

Business

Can Manufacturing Re-Emerge at Hazelwood Green?

Latest developments: A Post-Gazette feature asks whether Pittsburgh, and reclaimed industrial sites like Hazelwood Green, can anchor a manufacturing revival across Appalachia.

read more

The ReImagine Appalachia effort argues southwestern Pennsylvania's industrial legacy positions Pittsburgh—led by mill-site redevelopments such as Hazelwood Green along the Monongahela River—to recapture advanced manufacturing jobs.

Sources: Pittsburgh Post-Gazette · ↑ top

Around Town

Commercial Street Bridge Comes Down on Parkway East

Latest developments: After PennDOT scrubbed Wednesday night's attempt for lack of daylight, crews imploded the Commercial Street Bridge over the Parkway East around 8 a.m. Thursday, July 16, dropping it in seconds.

read more

PennDOT closed the Parkway East (I-376) on July 10 for a 25-day project to replace the Commercial Street Bridge in Pittsburgh; District 11 executive Jason Zang said safeguards shielded the adjacent new span, and roughly 100,000 daily drivers stay on detours until the highway reopens.

Sources: Pittsburgh Post-Gazette · KDKA · ↑ top

Code Red Air Quality Lingers Into Friday

Latest developments: The Pennsylvania DEP's Code Red alert holds through Thursday, July 16, with the smoke expected to be worst overnight into Friday afternoon.

read more

Wildfire smoke from Canada and Minnesota pushed unhealthy pollution across Western Pennsylvania; the Pennsylvania Department of Environmental Protection warns the air is unhealthy for everyone and urges limited time outdoors while highs reach the 90s.

Sources: KDKA · ↑ top

Events

Picklesburgh Opens Downtown

Latest developments: Picklesburgh opens today, Thursday, July 16, and runs through Sunday, July 19, after drawing more than 200,000 people last year.

read more

Picklesburgh, the free pickle-themed food festival the Pittsburgh Downtown Partnership launched in 2015, fills Downtown Pittsburgh and the North Shore with vendors, live music, and pickle antics from noon to 10 p.m. Thursday through Saturday and noon to 6 p.m. Sunday; details at picklesburgh.com.

Sources: KDKA · NEXTpittsburgh Events · ↑ top

Sports

Pirates (50-47)

Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM

Around the Teams

Pirates' Second-Half Playoff Push

Latest developments: The Post-Gazette laid out five storylines as the Pirates open the second half in Cleveland chasing a wild-card berth, centered on ace Paul Skenes.

read more

Pittsburgh's Pirates reached the All-Star break within range of a National League wild card; Post-Gazette writers flag Paul Skenes, a revamped offense, and coming roster decisions as the keys to whether the club stays in the race.

Sources: Post-Gazette Pirates · ↑ top

Team USA

USMNT's Home World Cup, In Pictures

Latest developments: With Spain and Argentina set for Sunday's final, ESPN published a photo retrospective of the U.S. men's national team's home World Cup, which ended in the round of 16.

read more

The 2026 World Cup, co-hosted by the United States, Canada, and Mexico, held American attention for a month before the U.S. men lost 4-1 to Belgium in the round of 16; ESPN collected the images that defined the run.

Sources: ESPN Soccer · ↑ top

Reading

Markets

weekly average, change vs prior week

S&P 500     7,550.07  ▲ +0.7%
Dow        52,557.99  ▼ -0.3%
Nasdaq     26,147.58  ▲ +0.8%
WTI crude      76.11  ▲ +8.8%
EUR/USD       1.1414  = -0.0%
GBP/USD       1.3389  ▲ +0.3%
USD/JPY       162.28  ▲ +0.2%