daily plain-text briefing: security, markets, business, and pittsburgh
Two Scattered Spider members drew five-and-a-half-year prison terms for the £29 million Transport for London hack as CISA rushed federal agencies to patch actively exploited Oracle, Fortinet, and SharePoint flaws.
Latest developments: Woolwich Crown Court sentenced Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall, to five years and six months each on July 16, 2026 for the 2024 Transport for London intrusion, following guilty pleas entered last month.
The two Scattered Spider members knocked out 148 Transport for London systems and forced all 27,000 employees into offices to reset passwords in person, costing the transit authority about £29 million. The National Crime Agency and Crown Prosecution Service led the case.
Sources: The Hacker News · BleepingComputer · SecurityWeek · The Record · ↑ top
Latest developments: Ars Technica reported July 16, 2026 that the ClickFix copy-paste trick pioneered by financial criminals has reached Russia's most elite state hackers, as researchers documented ClickLock, a new macOS stealer that kills a victim's apps every 210 milliseconds until they type their login password, and the OkoBot framework that fires more than 20 payloads to drain crypto wallets and credentials.
ClickFix lures instruct visitors to paste a command into Terminal or the Windows Run box, which installs malware; ClickLock has already hit at least 100 macOS users. Users should never paste commands supplied by a website.
Sources: Ars Technica Security · The Hacker News · SecurityWeek · BleepingComputer · ↑ top
Latest developments: BleepingComputer disclosed July 16, 2026 a flaw in Anthropic's Claude for Chrome extension that lets a malicious extension simulate user clicks to trigger predefined AI actions and abuse Claude's access to Gmail, Google Docs, Google Calendar, and Salesforce, as The Hacker News detailed a new agent data injection attack that plants false facts in a page or code thread to make an agent misclick or run an attacker's command.
As enterprises hand AI agents access to email, code, and CRM data, attackers corrupt the content those agents read rather than break the underlying models. Microsoft urged least-privilege identity, access, and tool-binding controls to contain autonomous agents.
Sources: BleepingComputer · The Hacker News · Microsoft Security Blog · ↑ top
Latest developments: BleepingComputer profiled July 16, 2026 a new ransomware actor named Spirals that ran a full intrusion—initial access, data theft, and encryption—in under 24 hours, as Dark Reading reported email and identity attacks overtook software exploits as the top ransomware root cause last year, with multifactor authentication present in 97% of credential-based compromises yet failing to stop them.
Ransomware crews increasingly enter through stolen credentials and phishing rather than unpatched software, and they move faster once inside a network. Organizations should harden identity, deploy phishing-resistant MFA, and shorten detection times.
Sources: BleepingComputer · Dark Reading · ↑ top
Latest developments: CISA added three actively exploited flaws to its Known Exploited Vulnerabilities catalog on July 16, 2026—Fortinet FortiSandbox command-injection bugs CVE-2026-25089 and CVE-2026-39808 and Microsoft SharePoint deserialization flaw CVE-2026-58644—and separately ordered federal agencies to patch a critical Oracle E-Business Suite bug by Saturday, July 18.
The Fortinet and SharePoint bugs let attackers run commands and code on unpatched appliances and servers, and the Oracle E-Business Suite flaw threatens enterprise financial applications under ongoing attack. Federal agencies and enterprises should patch immediately.
Sources: CISA Advisories · BleepingComputer · ↑ top
Latest developments: The Hacker News reported July 16, 2026 that the China-linked Daxin kernel rootkit resurfaced after more than four years inside a Taiwanese manufacturing firm, paired with a previously unreported pre-login SYSTEM backdoor named Stupig, as Kaspersky detailed GoSerpent, a two-phase backdoor stealing data from Southeast Asian government entities alongside the Stowaway RAT.
Symantec first documented Daxin (srt64.sys) in March 2022 as a stealthy rootkit built for espionage against hardened networks. Its return, plus the GoSerpent operation against governments, marks renewed China-nexus data theft across Asia; defenders should hunt for kernel drivers and pre-login persistence.
Sources: The Hacker News · Securelist (Kaspersky) · ↑ top
Latest developments: Oil futures settled lower Thursday, July 16, as traders waited to see whether the United States escalates its strikes on Iran or returns to talks, and Chevron disclosed it will explore a pipeline through Syria to route Iraqi crude around the blockaded Strait of Hormuz.
The United States and Iran remain at war over the Strait of Hormuz, the chokepoint that carries roughly a fifth of the world's oil, and Washington's naval blockade of Iran's ports has kept energy markets unsettled for weeks; a Chevron-led consortium that includes a Syrian-Qatari group and a Los Angeles venture firm tied to Trump ally Tom Barrack now weighs investing in Iraqi oil fields and a pipeline to move that crude past the strait.
Sources: WSJ Markets · WSJ World News · FT Markets · ↑ top
This Afternoon: Areas Of Smoke, high 91F.
Tonight: Smoke, low 66F.
Friday: Smoke, high 89F.
Latest developments: Gecko Robotics, the Pittsburgh robotics and defense firm, will open a manufacturing facility in Aleppo Township near Sewickley, TribLive reported July 16.
Gecko Robotics, founded in Pittsburgh and known for wall-climbing inspection robots and defense work, will add a manufacturing plant in the Sewickley area, expanding the company's local production footprint.
Latest developments: Helltown Brewing will close its Strip District taproom as new development reshapes Penn Avenue, the Post-Gazette reported July 16.
Helltown Brewing, the Westmoreland County brewer with a taproom on Penn Avenue in Pittsburgh's Strip District, will shut that location as a wave of construction remakes the corridor.
Sources: Pittsburgh Post-Gazette · ↑ top
Latest developments: JDoggs, a new hot dog truck, opened July 13 at 420 Perry Highway in West View, Pittsburgh Magazine reported.
JDoggs, a hot dog truck parked at 420 Perry Highway in West View, runs 10:30 a.m. to 2:30 p.m. Monday through Friday, at least through the end of summer.
Sources: Pittsburgh Magazine · ↑ top
Latest developments: Crews detonated explosives around 8 a.m. Thursday, July 16, bringing down the Commercial Street Bridge on the Parkway East, and PennDOT said the demolition went according to plan with no damage to the new span.
PennDOT closed the Parkway East (I-376) between the Squirrel Hill Tunnel and the Edgewood/Swissvale exit to replace the Commercial Street Bridge in a 25-day project; the agency postponed Wednesday's planned implosion when crews ran out of daylight, then demolished the old bridge Thursday morning.
Latest developments: The Allegheny County cyclospora outbreak has sent at least one person to the hospital, and a University of Pittsburgh professor and PublicSource laid out precautions as cases climb, with officials urging safeguards without panic.
The Allegheny County Health Department is tracking a cyclosporiasis outbreak—cases of the diarrhea-causing parasite—amid a multistate CDC investigation, and Pittsburgh physicians recommend washing produce and other safeguards.
Sources: Pittsburgh Post-Gazette · PublicSource · ↑ top
Latest developments: Wildfire smoke from Canada and Minnesota pushed into the Pittsburgh region Thursday, July 16, dropping the city under a Code Red air quality alert, with the worst conditions expected overnight into Friday afternoon.
The Pennsylvania Department of Environmental Protection declared a Code Red alert—air unhealthy for everyone—across the region as wildfire smoke combined with heat, and KDKA meteorologists flagged Thursday and Friday as First Alert Weather days.
Sources: Pittsburgh Post-Gazette · KDKA · ↑ top
Latest developments: Picklesburgh opened Thursday, July 16, and runs through Sunday, July 19, in Downtown Pittsburgh.
Picklesburgh, the pickle-themed food festival, runs Thursday through Sunday, July 16-19, in Downtown Pittsburgh, with hours of noon to 10 p.m. and noon to 6 p.m. across the four days.
Sources: NEXTpittsburgh Arts & Entertainment · ↑ top
Pirates (50-47)
Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM
Latest developments: The Post-Gazette laid out five storylines for the Pirates' second half July 16 as the team comes out of the All-Star break vying for a National League wild-card spot, with ace Paul Skenes anchoring the rotation.
The Pittsburgh Pirates return from the All-Star break clinging to wild-card hopes in the National League, leaning on a revamped offense and right-hander Paul Skenes atop the rotation.
Sources: Post-Gazette Pirates · ↑ top
S&P 500 7,550.07 ▲ +0.7% Dow 52,557.99 ▼ -0.3% Nasdaq 26,147.58 ▲ +0.8% WTI crude 76.11 ▲ +8.8% EUR/USD 1.1423 = -0.0% GBP/USD 1.3418 ▲ +0.4% USD/JPY 162.19 ▲ +0.1%