infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

A wave of critical patches from Zoom, Splunk, and F5 lands alongside a Secure Boot bypass hiding in forgotten bootloaders, while Russian-speaking crews trojanize video apps to steal credentials and crypto.


Emerging Trends and Key Updates

Security

1. Critical Zoom, Splunk, and F5 Flaws Patched

Vulnerabilities and Exploits · [patch, account-takeover, vulnerability]

Latest developments: Zoom shipped fixes for CVE-2026-53412, a 9.8-severity improper-input-validation flaw that lets an unauthenticated attacker take over Windows accounts, a day after warning of it, while Splunk and F5 patched critical bugs of their own across their platforms and the NGINX and BIG-IP lines.

read more

CVE-2026-53412 affects the Zoom Desktop, VDI, and Meeting SDK clients for Windows; Splunk's flaws expose credentials and enable privilege escalation, and F5's NGINX and BIG-IP bugs allow configuration changes, memory leaks, and code execution. Apply every vendor update now.

Sources: The Hacker News · SecurityWeek · SecurityWeek · BleepingComputer · ↑ top

2. Breaches Hit 23andMe, Nichirei Logistics, and Romania's Land Registry

Data Breaches · [breach, settlement, disruption]

Latest developments: 23andMe agreed to pay $18 million to settle claims from 43 state attorneys general over its failure to protect genetic data, as fresh attacks knocked out Japan's largest cold-chain operator Nichirei Logistics Group—short-supplying KFC restaurants and supermarkets—and Romania's national cadastre agency ANCPI, whose e-Terra land registry went dark with data now allegedly for sale.

read more

The 23andMe settlement resolves fallout from its earlier customer-data breach, while the Nichirei and ANCPI incidents show cyberattacks halting food logistics and government land records in real time. Expect regulatory and operational pressure on data custodians.

Sources: BleepingComputer · The Record · Help Net Security · ↑ top

3. Forgotten UEFI Shims Bypass Secure Boot

Vulnerabilities and Exploits · [vulnerability, secure-boot]

Latest developments: Researchers found nearly a dozen old UEFI shim bootloaders, each carrying a valid Microsoft signature and only recently revoked, that stayed trusted for years and let an attacker bypass Secure Boot on any machine regardless of its operating system.

read more

Shims chain-load an OS bootloader after Secure Boot verifies them, and because the vulnerable versions kept valid Microsoft signatures, an attacker who plants one can load unsigned code before the operating system starts. Update the shim revocation list and firmware.

Sources: SecurityWeek · Dark Reading · ↑ top

4. UAT-11795 Starland RAT via Trojanized Video Apps

Ransomware and Cybercrime · [malware, rat, cybercrime]

Latest developments: Cisco Talos and BleepingComputer detailed UAT-11795, a Russian-speaking, financially motivated actor active since at least June 2025 that trojanizes WebEx and Zoom installers to drop the novel Starland RAT and a bespoke WLDR command-and-control implant.

read more

The campaign steals credentials and cryptocurrency from targets across the United States and Europe. Download conferencing software only from vendor sites and verify installer signatures.

Sources: BleepingComputer · Cisco Talos · ↑ top

5. Sandworm Fake-CAPTCHA PowerShell Attacks

Nation-State Activity · [apt, clickfix, malware]

Latest developments: Ukraine's responders caught Sandworm, Russia's GRU-linked group, replacing a website CAPTCHA with instructions telling Ukrainian visitors to paste a PowerShell command into Windows, the same copy-paste ClickFix trick that criminal operators use to spread the new modular TELEPUZ malware documented by Elastic Security Labs.

read more

ClickFix lures dress malware execution as a routine human-verification step, sidestepping downloads and many defenses. Train users never to paste commands from a web page into a terminal.

Sources: The Record · The Hacker News · ↑ top

6. OpenAI Debuts GPT-Red Automated Red-Teamer

AI Security · [ai, red-teaming, prompt-injection]

Latest developments: OpenAI disclosed GPT-Red, an internal automated red-teaming model it uses to discover prompt-injection weaknesses at scale and adversarially train its GPT-5.6 Sol release, landing as researchers argue AI can surface bugs quickly but a human still has to prove each one real.

read more

GPT-Red generates prompt-injection attacks against OpenAI's own models to fix flaws before wide deployment. The push reflects a broader shift toward automated offense balanced by human verification of findings.

Sources: The Hacker News · The Hacker News · ↑ top

Business and Politics

U.S.-Iran War Grinds On as Hormuz Stays Choked

Latest developments: The U.S. military expanded its strikes into northern Iran and disabled a ship trying to run the blockade, Iran released American woman Dena Karari after more than a year in detention as what Trump called a goodwill gesture, and oil rose for a fourth straight session as Strait of Hormuz transit thinned to a trickle.

read more

The renewed U.S. campaign against Iran keeps the Strait of Hormuz effectively closed, squeezing the world's main oil artery; crude climbed a fourth day and gold briefly slipped below $4,000 as traders weighed Tehran's threat to halt energy exports against Washington's threat to strike Iranian civilian infrastructure.

Sources: WSJ Markets · WSJ World News · ↑ top

Pittsburgh

Weather

This Afternoon: Smoke, high 93F.

Tonight: Smoke, low 67F.

Friday: Smoke, high 92F.

Business

Schwebel's Buyer Talks Collapse

Latest developments: Talks with a potential buyer for Schwebel Baking Company have come to a close, the Post-Gazette reported July 16, dimming the prospects for the bread maker.

read more

Schwebel Baking Company, a longtime regional bread and roll maker, ended negotiations with a would-be purchaser, leaving the company's future and its workforce in doubt.

Sources: Pittsburgh Post-Gazette · ↑ top

PJM Auction Hits Price Cap Again

Latest developments: PJM Interconnection's latest capacity auction cleared at the price cap for a second straight year, and CEO David Mills said demand keeps growing faster than supply, pointing to higher electricity bills across Pennsylvania.

read more

PJM Interconnection, the grid operator serving Pennsylvania and 12 other states, again saw its capacity auction hit the maximum allowed price, a result consumer advocates warn will push electricity rates up for households across the region.

Sources: PublicSource · ↑ top

WVU, Pitt, CMU Land Energy Hub

Latest developments: West Virginia University won $160 million in new federal money from the National Science Foundation's RETI Engine and will partner with the University of Pittsburgh and Carnegie Mellon University to build an industrial energy innovation hub.

read more

The National Science Foundation grant ties WVU, Pitt, and Carnegie Mellon together to develop industrial energy technology, one of the larger research awards flowing to the Pittsburgh region's universities.

Sources: Pittsburgh Post-Gazette · ↑ top

Around Town

Allegheny County Pension Shortfall Hits $1.4 Billion

Latest developments: A new report from Allegheny County Treasurer Erica Rocchi Brussalars, out July 16, pegs the county's pension shortfall at $1.4 billion and says the county must find an extra $100 million a year for 20 years to fix it.

read more

Allegheny County's underfunded pension system, long left to fester, has come due, and closing the gap will demand roughly $100 million in new money annually for two decades under Executive Sara Innamorato, a strain the county has yet to fund.

Sources: KDKA · Pittsburgh Post-Gazette · ↑ top

Events

LÚNASA Celtic Festival Coming to Arts Landing

Latest developments: The Irish Partnership of Pittsburgh and Anam Arts announced LÚNASA: A Celtic Festival Cultivating the Light of Belonging, a new event coming to Arts Landing in Downtown Pittsburgh later this summer.

read more

LÚNASA is a new Celtic-heritage festival from the Irish Partnership of Pittsburgh, which also runs the annual Pittsburgh Irish Festival, staged at Arts Landing Downtown as a first-year cultural tradition.

Sources: Pittsburgh Magazine · ↑ top

Sports

Pirates (50-47)

Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM

Around the Teams

Ramsey as Graham's Chess Piece

Latest developments: A Post-Gazette training-camp countdown argues cornerback Jalen Ramsey must be defensive coordinator Patrick Graham's ultimate movable chess piece as the Steelers open camp at Saint Vincent College in Latrobe.

read more

The Post-Gazette frames Ramsey, the veteran cornerback the Steelers acquired for their secondary, as the versatile defender Graham can line up all over the field, a linchpin of Pittsburgh's 2026 defense.

Sources: Post-Gazette Steelers · ↑ top

Team USA

Flavor Flav Backs Team USA Women's Hockey

Latest developments: ESPN detailed July 15 how rapper Flavor Flav became the driving force behind the inaugural SHE Weekend in Las Vegas, his biggest show of support yet for the U.S. women's national ice hockey team.

read more

Flavor Flav, an unexpected champion of women's sports, is bankrolling and headlining SHE Weekend, an event built around Team USA women's ice hockey players as they push their sport toward a bigger stage.

Sources: ESPN Olympics · ↑ top

Reading

Markets

weekly average, change vs prior week

S&P 500     7,550.07  ▲ +0.7%
Dow        52,557.99  ▼ -0.3%
Nasdaq     26,147.58  ▲ +0.8%
WTI crude      76.11  ▲ +8.8%
EUR/USD       1.1414  = -0.0%
GBP/USD       1.3389  ▲ +0.3%
USD/JPY       162.28  ▲ +0.2%