================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Thursday, July 16, 2026 - 9:06 AM EDT ================================================================ Britain sentenced two Scattered Spider members to five and a half years for the Transport for London breach as CISA rushed federal agencies to patch an actively exploited Oracle flaw and China-linked espionage backdoors resurfaced across Asia. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Researchers demonstrated a data-injection attack that makes a coding assistant run a stranger's command from a single fake GitHub comment, weaponizing AI agents against their own users. see: AI Agents Weaponized and Data-Injection Attacks * [UPDATE (new)] CISA ordered federal agencies to patch actively exploited Oracle E-Business Suite flaw CVE-2026-46817 by Saturday, citing ongoing attacks on the financial application. see: Active Exploitation of Oracle E-Business Suite * [TREND] China-linked espionage crews resurfaced across Asia, dropping the Daxin rootkit inside a Taiwan manufacturer and a fresh GoSerpent backdoor into Southeast Asian government networks. see: China-Linked Backdoors Resurface Across Asia * [UPDATE (new)] A British court sentenced two Scattered Spider members to five and a half years each for the 2024 Transport for London breach that cost the agency £29 million. see: Scattered Spider Members Sentenced for TfL Hack * [TREND] New criminal tooling proliferated as ClickLock Stealer drained crypto from macOS users while the Spirals crew ran a full intrusion through encryption in under 24 hours. see: Crypto-Theft Malware Targets macOS and Hardware Wallets; Spirals Ransomware Encrypts in Under 24 Hours * [UPDATE (new)] Locally, crews imploded the Commercial Street Bridge over the Parkway East, a Code Red air-quality alert holds through Friday, and Picklesburgh opens downtown. see: Commercial Street Bridge Comes Down on Parkway East; Code Red Air Quality Lingers Into Friday; Picklesburgh Opens Downtown SECURITY ---------------------------------------------------------------- 1. AI AGENTS WEAPONIZED AND DATA-INJECTION ATTACKS AI Security · [ai, prompt-injection, zero-day] Latest developments: Researchers demonstrated a data-injection attack that corrupts the facts an AI agent trusts—one planted product review makes a shopping agent click Buy Now, one fake GitHub comment makes a coding assistant run a stranger's command—while Intruder unveiled a vulnerability vending machine that pairs code slicing with large language models and found an unknown WordPress plugin zero-day. Offensive AI is maturing on both sides: attackers hide malicious instructions in data an agent reads, and defenders automate zero-day discovery, though researchers stress a finding still has to be proven before it counts. Organizations deploying AI agents should treat all agent-read content as untrusted input. - The Hacker News: https://thehackernews.com/2026/07/new-agent-data-injection-attack-can.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/we-built-a-vulnerability-vending-machine-ai-tokens-in-zero-days-out/ - The Hacker News: https://thehackernews.com/2026/07/ai-can-find-bugs-but-human-knowledge.html 2. SCATTERED SPIDER MEMBERS SENTENCED FOR TFL HACK Ransomware and Cybercrime · [cybercrime, arrest] Latest developments: A British court sentenced two leading members of the Scattered Spider cybercrime collective to five years and six months each for the 2024 attack on Transport for London that cost the agency £29 million. Scattered Spider, a loose collective known for social-engineering help desks, breached Transport for London in 2024, forcing service and refund system outages. The prison terms mark one of the first major convictions of the group's members. - BleepingComputer: https://www.bleepingcomputer.com/news/security/scattered-spider-members-behind-transport-for-london-hack-get-five-years-in-prison/ - The Record: https://therecord.media/scattered-spider-hackers-tfl-sentenced 3. CRYPTO-THEFT MALWARE TARGETS MACOS AND HARDWARE WALLETS Ransomware and Cybercrime · [malware, cryptocurrency] Latest developments: SecurityWeek detailed ClickLock Stealer, a new macOS malware that uses social engineering and process killing to steal passwords and cryptocurrency from at least 100 users, while The Hacker News exposed OkoBot, a Windows framework running since April 2025 that injects seed-phrase phishing prompts into the legitimate Ledger and Trezor desktop apps. Both families chase cryptocurrency: ClickLock bypasses macOS protections to grab credentials and wallets, and OkoBot waits for victims to open real hardware-wallet software before demanding their recovery phrase. Users should ignore any in-app request to re-enter a seed phrase. - SecurityWeek: https://www.securityweek.com/clicklock-stealer-bypasses-macos-security-with-social-engineering-process-killing/ - The Hacker News: https://thehackernews.com/2026/07/okobot-malware-framework-injects-seed.html 4. CHINA-LINKED BACKDOORS RESURFACE ACROSS ASIA Nation-State Activity · [apt, espionage, backdoor] Latest developments: The Daxin kernel-mode rootkit reappeared after more than four years inside a Taiwan manufacturing firm alongside a new pre-login SYSTEM backdoor named Stupig, while Kaspersky detailed GoSerpent, an evolving backdoor stealing data from Southeast Asian government entities using the Stowaway RAT and a ThumbcacheService tool. Symantec first documented Daxin in March 2022 as a stealthy rootkit tied to Chinese espionage; its return signals renewed targeting of Taiwanese industry and Southeast Asian governments. Both campaigns run two-phase intrusions built for long-term data theft. - The Hacker News: https://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.html - Securelist (Kaspersky): https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/ 5. SPIRALS RANSOMWARE ENCRYPTS IN UNDER 24 HOURS Ransomware and Cybercrime · [ransomware, breach] Latest developments: A new ransomware actor called Spirals ran an entire corporate intrusion—from initial access through data theft to encryption—in less than 24 hours. Spirals compresses the ransomware kill chain into a single day, leaving defenders almost no window to detect and respond. Fast dwell-to-encryption times raise the premium on early identity and endpoint detection. - BleepingComputer: https://www.bleepingcomputer.com/news/security/new-spirals-ransomware-encrypts-victim-network-in-under-24-hours/ 6. ACTIVE EXPLOITATION OF ORACLE E-BUSINESS SUITE Vulnerabilities and Exploits · [patch, zero-day, cve] Latest developments: CISA ordered federal agencies to patch the critical Oracle E-Business Suite financial-application flaw CVE-2026-46817 by Saturday, July 18, 2026, citing ongoing attacks. CVE-2026-46817 is a privilege-management flaw in Oracle's E-Business Suite that attackers are exploiting in the wild. Agencies and enterprises running the financial application should apply Oracle's fix immediately. - BleepingComputer: https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-flaw-by-saturday/ BUSINESS AND POLITICS ---------------------------------------------------------------- * U.S.-Iran War Widens as Hormuz Stays Shut Latest developments: The Financial Times warns the renewed Strait of Hormuz closure now threatens a fresh oil-supply crunch as the commercial stockpiles that cushioned the war's early shocks run low, even as crude steadied after three straight days of gains with U.S.-Iran diplomacy gridlocked. The United States and Iran stay locked in open conflict around the Strait of Hormuz, through which roughly a fifth of the world's oil passes; Washington has blockaded Iran's ports and kept striking Iranian targets, holding global energy markets on edge. - Financial Times: https://www.ft.com/content/fb373886-413a-4fd5-84ff-b43acdc2ecbd - WSJ Markets: https://www.wsj.com/finance/commodities-futures/oil-rises-amid-prospects-of-escalating-mideast-conflict-7f8ab657?mod=rss_markets_main PITTSBURGH ---------------------------------------------------------------- Weather: Today: Mostly Sunny then Smoke, high 93F. Tonight: Smoke, low 67F. Friday: Smoke, high 92F. Business: * Can Manufacturing Re-Emerge at Hazelwood Green? Latest developments: A Post-Gazette feature asks whether Pittsburgh, and reclaimed industrial sites like Hazelwood Green, can anchor a manufacturing revival across Appalachia. The ReImagine Appalachia effort argues southwestern Pennsylvania's industrial legacy positions Pittsburgh—led by mill-site redevelopments such as Hazelwood Green along the Monongahela River—to recapture advanced manufacturing jobs. - Pittsburgh Post-Gazette: https://www.post-gazette.com/business/career-workplace/2026/07/16/reimagine-appalachia-jobs-pittsburgh-hazelwood-green/stories/202607090048 Around town: * Commercial Street Bridge Comes Down on Parkway East Latest developments: After PennDOT scrubbed Wednesday night's attempt for lack of daylight, crews imploded the Commercial Street Bridge over the Parkway East around 8 a.m. Thursday, July 16, dropping it in seconds. PennDOT closed the Parkway East (I-376) on July 10 for a 25-day project to replace the Commercial Street Bridge in Pittsburgh; District 11 executive Jason Zang said safeguards shielded the adjacent new span, and roughly 100,000 daily drivers stay on detours until the highway reopens. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/transportation/2026/07/16/commercial-street-bridge-parkway-east/stories/202607160039 - KDKA: https://www.cbsnews.com/pittsburgh/news/how-to-watch-penndot-commercial-street-bridge-explosive-demolition-today/ * Code Red Air Quality Lingers Into Friday Latest developments: The Pennsylvania DEP's Code Red alert holds through Thursday, July 16, with the smoke expected to be worst overnight into Friday afternoon. Wildfire smoke from Canada and Minnesota pushed unhealthy pollution across Western Pennsylvania; the Pennsylvania Department of Environmental Protection warns the air is unhealthy for everyone and urges limited time outdoors while highs reach the 90s. - KDKA: https://www.cbsnews.com/pittsburgh/news/wildfire-smoke-and-poor-air-quality-expected-on-thursday-in-pittsburgh-first-alert-weather/ Events: * Picklesburgh Opens Downtown Latest developments: Picklesburgh opens today, Thursday, July 16, and runs through Sunday, July 19, after drawing more than 200,000 people last year. Picklesburgh, the free pickle-themed food festival the Pittsburgh Downtown Partnership launched in 2015, fills Downtown Pittsburgh and the North Shore with vendors, live music, and pickle antics from noon to 10 p.m. Thursday through Saturday and noon to 6 p.m. Sunday; details at picklesburgh.com. - KDKA: https://www.cbsnews.com/pittsburgh/news/picklesburgh-2026-dates-schedule-map/ - NEXTpittsburgh Events: https://nextpittsburgh.com/events/14-things-to-do-this-weekend-from-picklesburgh-to-the-pittsburgh-vintage-grand-prix/ SPORTS ---------------------------------------------------------------- Pirates (50-47) Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM https://plaintextsports.com/mlb/2026-07-17/pit-cle Around the Teams: * Pirates' Second-Half Playoff Push Latest developments: The Post-Gazette laid out five storylines as the Pirates open the second half in Cleveland chasing a wild-card berth, centered on ace Paul Skenes. Pittsburgh's Pirates reached the All-Star break within range of a National League wild card; Post-Gazette writers flag Paul Skenes, a revamped offense, and coming roster decisions as the keys to whether the club stays in the race. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/07/16/storylines-analysis-mlb-second-half-skenes/stories/202607150032 Team USA: * USMNT's Home World Cup, In Pictures Latest developments: With Spain and Argentina set for Sunday's final, ESPN published a photo retrospective of the U.S. men's national team's home World Cup, which ended in the round of 16. The 2026 World Cup, co-hosted by the United States, Canada, and Mexico, held American attention for a month before the U.S. men lost 4-1 to Belgium in the round of 16; ESPN collected the images that defined the run. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49352246/2026-world-cup-capsule-images-usmnt-remember-forever READING ---------------------------------------------------------------- * Ed Zitron -- The OpenAI Bubble Zitron argues OpenAI sits at the center of an unsustainable AI financial bubble, dissecting the company's economics and spending to show why he thinks the numbers do not add up. https://www.wheresyoured.at/the-openai-bubble/ * Stratechery -- IBM Misses, IBM's Mainframe Moat, IBM's Many AI Problems Thompson unpacks IBM's disappointing preliminary results, arguing its mainframe franchise stays a durable moat even as the company confronts multiple problems in the AI era. https://stratechery.com/2026/ibm-misses-ibms-mainframe-moat-ibms-many-ai-problems/ * Cal Newport -- Why Reading Matters Responding to Rose Horowitch's Atlantic piece on collapsing reading habits, Newport defends the cognitive value of sustained deep reading. https://calnewport.com/why-reading-matters/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,550.07 ▲ +0.7% Dow 52,557.99 ▼ -0.3% Nasdaq 26,147.58 ▲ +0.8% WTI crude 76.11 ▲ +8.8% EUR/USD 1.1414 = -0.0% GBP/USD 1.3389 ▲ +0.3% USD/JPY 162.28 ▲ +0.2% ================================================================ Generated 2026-07-16 09:06 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================