================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Thursday, July 16, 2026 - 4:06 PM EDT ================================================================ Two Scattered Spider members drew five-and-a-half-year prison terms for the £29 million Transport for London hack as CISA rushed federal agencies to patch actively exploited Oracle, Fortinet, and SharePoint flaws. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] A flaw in Anthropic's Claude for Chrome extension lets malicious extensions simulate clicks to hijack the AI agent's access to Gmail and Salesforce. see: Attackers Weaponize AI Agents Through Browsers and Data * [TREND] Intrusions now finish in a day as the Spirals crew encrypted in under 24 hours, while two Scattered Spider members were jailed for the Transport for London hack. see: Spirals Ransomware and Identity-Driven Intrusions; Scattered Spider Members Jailed for Transport for London Hack * [TREND] The ClickFix copy-paste trick has climbed from ordinary crooks to Russia's elite state hackers, spawning a new macOS ClickLock stealer. see: ClickFix Spreads as ClickLock and OkoBot Stealers Emerge * [UPDATE (new)] CISA flagged three actively exploited flaws—Fortinet FortiSandbox, Microsoft SharePoint, and Oracle bugs—in its Known Exploited Vulnerabilities catalog. see: CISA Flags Fortinet, SharePoint, and Oracle Flaws Under Attack * [UPDATE (new)] The China-linked Daxin kernel rootkit resurfaced inside a Taiwanese manufacturer after four years, paired with a pre-login SYSTEM backdoor. see: China-Linked Daxin and GoSerpent Espionage Backdoors * [UPDATE (new)] Wildfire smoke dropped Pittsburgh under a Code Red air quality alert as a cyclospora outbreak hospitalized one and crews imploded the Commercial Street Bridge. see: Code Red Air Quality Blankets Pittsburgh; Cyclospora Outbreak Sends One to the Hospital; Commercial Street Bridge Imploded on the Parkway East SECURITY ---------------------------------------------------------------- 1. SCATTERED SPIDER MEMBERS JAILED FOR TRANSPORT FOR LONDON HACK Ransomware and Cybercrime · [cybercrime, arrest] Latest developments: Woolwich Crown Court sentenced Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall, to five years and six months each on July 16, 2026 for the 2024 Transport for London intrusion, following guilty pleas entered last month. The two Scattered Spider members knocked out 148 Transport for London systems and forced all 27,000 employees into offices to reset passwords in person, costing the transit authority about £29 million. The National Crime Agency and Crown Prosecution Service led the case. - The Hacker News: https://thehackernews.com/2026/07/two-scattered-spider-hackers-get-55.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/scattered-spider-members-behind-transport-for-london-hack-get-five-years-in-prison/ - SecurityWeek: https://www.securityweek.com/two-scattered-spider-hackers-sentenced-to-jail-in-uk/ - The Record: https://therecord.media/scattered-spider-hackers-tfl-sentenced 2. CLICKFIX SPREADS AS CLICKLOCK AND OKOBOT STEALERS EMERGE Ransomware and Cybercrime · [malware, social-engineering, macos] Latest developments: Ars Technica reported July 16, 2026 that the ClickFix copy-paste trick pioneered by financial criminals has reached Russia's most elite state hackers, as researchers documented ClickLock, a new macOS stealer that kills a victim's apps every 210 milliseconds until they type their login password, and the OkoBot framework that fires more than 20 payloads to drain crypto wallets and credentials. ClickFix lures instruct visitors to paste a command into Terminal or the Windows Run box, which installs malware; ClickLock has already hit at least 100 macOS users. Users should never paste commands supplied by a website. - Ars Technica Security: https://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices/ - The Hacker News: https://thehackernews.com/2026/07/new-clicklock-macos-stealer-kills-apps.html - SecurityWeek: https://www.securityweek.com/clicklock-stealer-bypasses-macos-security-with-social-engineering-process-killing/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/new-okobot-framework-deploys-20-payloads-to-steal-data-crypto/ 3. ATTACKERS WEAPONIZE AI AGENTS THROUGH BROWSERS AND DATA AI Security · [ai, prompt-injection] Latest developments: BleepingComputer disclosed July 16, 2026 a flaw in Anthropic's Claude for Chrome extension that lets a malicious extension simulate user clicks to trigger predefined AI actions and abuse Claude's access to Gmail, Google Docs, Google Calendar, and Salesforce, as The Hacker News detailed a new agent data injection attack that plants false facts in a page or code thread to make an agent misclick or run an attacker's command. As enterprises hand AI agents access to email, code, and CRM data, attackers corrupt the content those agents read rather than break the underlying models. Microsoft urged least-privilege identity, access, and tool-binding controls to contain autonomous agents. - BleepingComputer: https://www.bleepingcomputer.com/news/security/claude-chrome-extension-flaw-lets-malicious-extensions-trigger-ai-actions/ - The Hacker News: https://thehackernews.com/2026/07/new-agent-data-injection-attack-can.html - Microsoft Security Blog: https://www.microsoft.com/en-us/security/blog/2026/07/16/least-privilege-for-ai-agents-identity-access-and-tool-binding/ 4. SPIRALS RANSOMWARE AND IDENTITY-DRIVEN INTRUSIONS Ransomware and Cybercrime · [ransomware, breach] Latest developments: BleepingComputer profiled July 16, 2026 a new ransomware actor named Spirals that ran a full intrusion—initial access, data theft, and encryption—in under 24 hours, as Dark Reading reported email and identity attacks overtook software exploits as the top ransomware root cause last year, with multifactor authentication present in 97% of credential-based compromises yet failing to stop them. Ransomware crews increasingly enter through stolen credentials and phishing rather than unpatched software, and they move faster once inside a network. Organizations should harden identity, deploy phishing-resistant MFA, and shorten detection times. - BleepingComputer: https://www.bleepingcomputer.com/news/security/new-spirals-ransomware-encrypts-victim-network-in-under-24-hours/ - Dark Reading: https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause 5. CISA FLAGS FORTINET, SHAREPOINT, AND ORACLE FLAWS UNDER ATTACK Vulnerabilities and Exploits · [patch, exploit, zero-day] Latest developments: CISA added three actively exploited flaws to its Known Exploited Vulnerabilities catalog on July 16, 2026—Fortinet FortiSandbox command-injection bugs CVE-2026-25089 and CVE-2026-39808 and Microsoft SharePoint deserialization flaw CVE-2026-58644—and separately ordered federal agencies to patch a critical Oracle E-Business Suite bug by Saturday, July 18. The Fortinet and SharePoint bugs let attackers run commands and code on unpatched appliances and servers, and the Oracle E-Business Suite flaw threatens enterprise financial applications under ongoing attack. Federal agencies and enterprises should patch immediately. - CISA Advisories: https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog - BleepingComputer: https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-flaw-by-saturday/ 6. CHINA-LINKED DAXIN AND GOSERPENT ESPIONAGE BACKDOORS Nation-State Activity · [apt, espionage, malware] Latest developments: The Hacker News reported July 16, 2026 that the China-linked Daxin kernel rootkit resurfaced after more than four years inside a Taiwanese manufacturing firm, paired with a previously unreported pre-login SYSTEM backdoor named Stupig, as Kaspersky detailed GoSerpent, a two-phase backdoor stealing data from Southeast Asian government entities alongside the Stowaway RAT. Symantec first documented Daxin (srt64.sys) in March 2022 as a stealthy rootkit built for espionage against hardened networks. Its return, plus the GoSerpent operation against governments, marks renewed China-nexus data theft across Asia; defenders should hunt for kernel drivers and pre-login persistence. - The Hacker News: https://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.html - Securelist (Kaspersky): https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/ BUSINESS AND POLITICS ---------------------------------------------------------------- * Iran War Keeps Oil on Edge as Chevron Eyes a Hormuz Bypass Latest developments: Oil futures settled lower Thursday, July 16, as traders waited to see whether the United States escalates its strikes on Iran or returns to talks, and Chevron disclosed it will explore a pipeline through Syria to route Iraqi crude around the blockaded Strait of Hormuz. The United States and Iran remain at war over the Strait of Hormuz, the chokepoint that carries roughly a fifth of the world's oil, and Washington's naval blockade of Iran's ports has kept energy markets unsettled for weeks; a Chevron-led consortium that includes a Syrian-Qatari group and a Los Angeles venture firm tied to Trump ally Tom Barrack now weighs investing in Iraqi oil fields and a pipeline to move that crude past the strait. - WSJ Markets: https://www.wsj.com/finance/commodities-futures/oil-rises-amid-prospects-of-escalating-mideast-conflict-7f8ab657?mod=rss_markets_main - WSJ World News: https://www.wsj.com/world/middle-east/chevron-will-explore-creating-strait-of-hormuz-alternative-for-iraqi-oil-36308abf - FT Markets: https://www.ft.com/content/eb6e0b25-6682-46bc-a879-136a38d1d7d6?syn-25a6b1a6=1 PITTSBURGH ---------------------------------------------------------------- Weather: This Afternoon: Areas Of Smoke, high 91F. Tonight: Smoke, low 66F. Friday: Smoke, high 89F. Business: * Gecko Robotics to Open Aleppo Township Plant Latest developments: Gecko Robotics, the Pittsburgh robotics and defense firm, will open a manufacturing facility in Aleppo Township near Sewickley, TribLive reported July 16. Gecko Robotics, founded in Pittsburgh and known for wall-climbing inspection robots and defense work, will add a manufacturing plant in the Sewickley area, expanding the company's local production footprint. - TribLive: https://triblive.com/local/sewickley/pittsburghs-gecko-robotics-opening-manufacturing-facility-in-sewickley/ * Helltown Brewing to Close Strip District Taproom Latest developments: Helltown Brewing will close its Strip District taproom as new development reshapes Penn Avenue, the Post-Gazette reported July 16. Helltown Brewing, the Westmoreland County brewer with a taproom on Penn Avenue in Pittsburgh's Strip District, will shut that location as a wave of construction remakes the corridor. - Pittsburgh Post-Gazette: https://www.post-gazette.com/life/drinks/2026/07/16/helltown-brewing-strip-district-taproom/stories/202607160044 * JDoggs Hot Dog Truck Opens in West View Latest developments: JDoggs, a new hot dog truck, opened July 13 at 420 Perry Highway in West View, Pittsburgh Magazine reported. JDoggs, a hot dog truck parked at 420 Perry Highway in West View, runs 10:30 a.m. to 2:30 p.m. Monday through Friday, at least through the end of summer. - Pittsburgh Magazine: https://www.pittsburghmagazine.com/dig-in-with-graver-fireside-pizza-co/ Around town: * Commercial Street Bridge Imploded on the Parkway East Latest developments: Crews detonated explosives around 8 a.m. Thursday, July 16, bringing down the Commercial Street Bridge on the Parkway East, and PennDOT said the demolition went according to plan with no damage to the new span. PennDOT closed the Parkway East (I-376) between the Squirrel Hill Tunnel and the Edgewood/Swissvale exit to replace the Commercial Street Bridge in a 25-day project; the agency postponed Wednesday's planned implosion when crews ran out of daylight, then demolished the old bridge Thursday morning. - KDKA: https://www.cbsnews.com/pittsburgh/news/how-to-watch-penndot-commercial-street-bridge-explosive-demolition-today/ * Cyclospora Outbreak Sends One to the Hospital Latest developments: The Allegheny County cyclospora outbreak has sent at least one person to the hospital, and a University of Pittsburgh professor and PublicSource laid out precautions as cases climb, with officials urging safeguards without panic. The Allegheny County Health Department is tracking a cyclosporiasis outbreak—cases of the diarrhea-causing parasite—amid a multistate CDC investigation, and Pittsburgh physicians recommend washing produce and other safeguards. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/health/2026/07/16/cyclospora-parasite-outbreak-1/stories/202607160046 - PublicSource: https://www.publicsource.org/cyclospora-diarrhea-precautions-pittsburgh-allegheny-county/ * Code Red Air Quality Blankets Pittsburgh Latest developments: Wildfire smoke from Canada and Minnesota pushed into the Pittsburgh region Thursday, July 16, dropping the city under a Code Red air quality alert, with the worst conditions expected overnight into Friday afternoon. The Pennsylvania Department of Environmental Protection declared a Code Red alert—air unhealthy for everyone—across the region as wildfire smoke combined with heat, and KDKA meteorologists flagged Thursday and Friday as First Alert Weather days. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/weather-news/2026/07/16/pittsburgh-weather-wildfire-smoke-1/stories/202607160061 - KDKA: https://www.cbsnews.com/pittsburgh/news/wildfire-smoke-and-poor-air-quality-expected-on-thursday-in-pittsburgh-first-alert-weather/ Events: * Picklesburgh Underway Downtown Latest developments: Picklesburgh opened Thursday, July 16, and runs through Sunday, July 19, in Downtown Pittsburgh. Picklesburgh, the pickle-themed food festival, runs Thursday through Sunday, July 16-19, in Downtown Pittsburgh, with hours of noon to 10 p.m. and noon to 6 p.m. across the four days. - NEXTpittsburgh Arts & Entertainment: https://nextpittsburgh.com/events/14-things-to-do-this-weekend-from-picklesburgh-to-the-pittsburgh-vintage-grand-prix/ SPORTS ---------------------------------------------------------------- Pirates (50-47) Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM https://plaintextsports.com/mlb/2026-07-17/pit-cle Around the Teams: * Pirates Eye a Second-Half Playoff Push Latest developments: The Post-Gazette laid out five storylines for the Pirates' second half July 16 as the team comes out of the All-Star break vying for a National League wild-card spot, with ace Paul Skenes anchoring the rotation. The Pittsburgh Pirates return from the All-Star break clinging to wild-card hopes in the National League, leaning on a revamped offense and right-hander Paul Skenes atop the rotation. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/07/16/storylines-analysis-mlb-second-half-skenes/stories/202607150032 READING ---------------------------------------------------------------- * Ed Zitron -- The OpenAI Bubble Ed Zitron argues OpenAI is a financial bubble, contending that the company's soaring valuation and enormous cash burn rest on revenue and adoption that cannot justify the money pouring in. https://www.wheresyoured.at/the-openai-bubble/ * Stratechery -- IBM Misses, IBM's Mainframe Moat, IBM's Many AI Problems Ben Thompson dissects IBM's disappointing preliminary results that spooked the software market, arguing the mainframe franchise remains a durable moat even as IBM faces structural problems competing in AI. https://stratechery.com/2026/ibm-misses-ibms-mainframe-moat-ibms-many-ai-problems/ * Cal Newport -- Why Reading Matters Cal Newport responds to an Atlantic article declaring the end of reading, making the case that sustained deep reading remains essential to thinking and that its decline is a real cultural loss worth resisting. https://calnewport.com/why-reading-matters/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,550.07 ▲ +0.7% Dow 52,557.99 ▼ -0.3% Nasdaq 26,147.58 ▲ +0.8% WTI crude 76.11 ▲ +8.8% EUR/USD 1.1423 = -0.0% GBP/USD 1.3418 ▲ +0.4% USD/JPY 162.19 ▲ +0.1% ================================================================ Generated 2026-07-16 16:06 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================