infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

A publicly released Windows zero-day, a Chinese theft of DigiCert's code-signing trust, and a botnet ransacking exposed AI servers marked a day of attacks aimed at the internet's foundations.


Emerging Trends and Key Updates

Security

1. LegacyHive Windows Zero-Day Exploit Goes Public

Vulnerabilities and Exploits · [zero-day, ics, dos]

Latest developments: A researcher using the "Nightmare Eclipse" handle published a working LegacyHive exploit that escalates local attackers to administrator on fully patched Windows, Palo Alto Networks' Unit 42 disclosed three chained Siemens ROX II OT-switch zero-days that yield persistent root, and the new HollowByte flaw crashes OpenSSL servers with an 11-byte payload.

read more

LegacyHive grants admin rights on current Windows builds, the Siemens ROX II chain compromises industrial switches, and HollowByte lets any unauthenticated sender exhaust an OpenSSL server's memory. Administrators should apply the Siemens and OpenSSL fixes and hunt for LegacyHive privilege escalation.

Sources: BleepingComputer · Unit 42 (Palo Alto) · BleepingComputer · ↑ top

2. Spirals Ransomware and Fairlife Shutdown

Ransomware and Cybercrime · [ransomware]

Latest developments: Symantec's Threat Hunter Team detailed Spirals, a previously unknown Rust ransomware that moved from initial access to data theft and full encryption in under 24 hours against a South Asian IT-services firm, while The Record placed Coca-Cola's Fairlife shutdown at plants in Michigan, New York, and Arizona and Nichirei began restoring the systems it cut off July 13.

read more

Spirals encrypts each file with a separate AES-128 key wrapped by attacker-controlled ECDH, leaving defenders little time to react, and the Fairlife and Nichirei incidents show ransomware still idling major food producers. Keep offline backups and rapid isolation playbooks ready.

Sources: Help Net Security · The Record · SecurityWeek · ↑ top

3. Botnets Hunt Exposed AI Services

AI Security · [ai, botnet, cloud]

Latest developments: A Go botnet called NadMesh surfaced in early July using a Shodan harvester to find exposed ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio instances, and its operator dashboard claims 3,811 stolen AWS keys alongside Kubernetes tokens, as Dark Reading warned that AI models allowed to both interpret and execute commands strip away human oversight.

read more

Teams stand up AI model runners and workflow builders fast and firewall them late, leaving them open to credential theft. Restrict network access to AI services and rotate any cloud keys those services can reach.

Sources: The Hacker News · Dark Reading · ↑ top

4. REvil Suspect Detained, Fraud Launderers Charged

Ransomware and Cybercrime · [arrest, fraud, ransomware]

Latest developments: Armenia has held Russian tourist Aleksandr Ermakov since June 28 on a US extradition request naming a REvil ransomware suspect of the same name, though his wife, Maria Yurova, and his lawyers say officers seized the wrong man, and US prosecutors charged a New York man and woman with laundering $43 million stolen through cyber investment-fraud scams.

read more

The cases mark continued law-enforcement pressure on ransomware suspects and the money mules who cash out online fraud. Border stops and money-laundering charges remain the main tools reaching operators shielded inside Russia.

Sources: The Hacker News · BleepingComputer · ↑ top

5. DigiCert Breach Tied to China's GoldenEyeDog

Data Breaches · [breach, apt]

Latest developments: Expel attributed the April 2026 DigiCert security incident to CylindricalCanine, a subgroup of the Chinese cybercrime group GoldenEyeDog—also tracked as APT-Q-27, Dragon Breath, and Miuuti Group—and linked the intrusion to the theft of code-signing certificates.

read more

GoldenEyeDog, a Chinese crew known for hitting the gambling and gaming sectors, breached certificate authority DigiCert and stole code-signing certificates that let attackers sign malware as trusted software. Defenders should scrutinize recently signed binaries.

Sources: The Hacker News · ↑ top

6. Blockchain-Backed npm Supply Chain Attack

Software Supply Chain · [supply-chain, malware]

Latest developments: Checkmarx uncovered seven malicious npm packages, codenamed ViteVenom, that target the Vite frontend toolchain and expand the ChainVeil campaign with a four-tier blockchain command-and-control network spanning Tron to deliver a remote access trojan.

read more

The packages impersonate Vite tooling and pull attacker instructions from blockchain contracts, which resist takedown. Developers should audit dependencies and pin trusted package versions.

Sources: The Hacker News · ↑ top

Business and Politics

U.S.-Iran War Widens as House Weighs War Funding

Latest developments: House Republicans pushed ahead Friday, July 17, on a package to fund the Iran war—much smaller than President Trump wants and uncertain to pass amid party divisions—as crude oil posted double-digit weekly gains.

read more

American strikes on increasingly sensitive Persian Gulf targets risk spiraling into a wider war as Iran hits back at neighboring Gulf states, and oil futures climbed all week on fears of supply disruption near the Strait of Hormuz.

Sources: WSJ World News · WSJ Markets · WSJ Politics · ↑ top

Pittsburgh

Weather

This Afternoon: Smoke, high 88F.

Tonight: Smoke, low 71F.

Saturday: Areas Of Smoke then Patchy Smoke, high 86F.

Business

Startup Bank Files for Pittsburgh Charter

Latest developments: Two former bank executives and a Pittsburgh lawyer filed a national-charter application July 14, launching the region's first new bank in almost 20 years, WPXI reported.

read more

A core group of six—led by former BNY and Huntington executives and a law-firm partner—applied to federal regulators to charter a startup bank in Pittsburgh, the first new bank in the region in nearly two decades.

Sources: WPXI · ↑ top

U.S. Steel Showcases Braddock Mill Investment

Latest developments: U.S. Steel showcased job openings and its multibillion-dollar Edgar Thomson investment Friday, July 17, projecting the new Braddock hot strip mill will finish by 2029 and add $1.7 billion to Pennsylvania's economy, WTAE reported.

read more

U.S. Steel is building a new hot strip mill at its Edgar Thomson plant in Braddock, with completion projected in 2029 and $1.7 billion in economic impact for the commonwealth.

Sources: WTAE · ↑ top

Around Town

Wildfire Smoke to Clear With Saturday Storms

Latest developments: Meteorologists said Friday, July 17, that strong to severe storms arriving late Saturday will wash out the wildfire smoke, ending the Code Purple alert that shut Kennywood, Sandcastle, and Idlewild and canceled Allegheny County events.

read more

Thick smoke from Canadian and Minnesota wildfires held Pennsylvania under a statewide Code Purple "very unhealthy" alert Friday, closing the Kennywood, Sandcastle, and Idlewild amusement parks and prompting County Executive Sara Innamorato to urge residents to stay indoors.

Sources: WTAE · WTAE · ↑ top

I-279 North to Close Five Nights Next Week

Latest developments: The Allegheny County Department of Public Works released a schedule Friday, July 17, to fully close northbound I-279 for five overnight stretches next week.

read more

Crews will fully close a portion of northbound Interstate 279 for five nights next week to demolish Jacks Run Bridge No. 3, which carries Jacks Run Road over the highway.

Sources: WPXI · ↑ top

State Police, Turnpike Collect $2 Million in Tolls

Latest developments: The Pennsylvania Turnpike and state police said their first joint toll-enforcement initiative recovered more than $2 million in unpaid tolls, KDKA reported July 17.

read more

A one-month enforcement push by the Pennsylvania Turnpike and Pennsylvania State Police collected more than $2 million in unpaid tolls, stopping aggressive drivers and those with suspended registrations tied to unpaid bills.

Sources: KDKA · ↑ top

Sports

Pirates (50-47)

Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM

Team USA

Lindsey Heaps Returns Home With Denver Summit

Latest developments: ESPN reported July 17 that U.S. women's national team midfielder Lindsey Heaps, after stints with Paris Saint-Germain and abroad, joined NWSL expansion side Denver Summit FC, a return to her native Colorado.

read more

United States women's national team midfielder Lindsey Heaps, a veteran of Paris Saint-Germain and Olympique Lyonnais, signed with new NWSL club Denver Summit FC, bringing her career back to the Colorado region where she grew up.

Sources: ESPN Soccer · ↑ top

Reading

Markets

weekly average, change vs prior week

S&P 500     7,548.10  ▲ +0.5%
Dow        52,571.11  ▼ -0.3%
Nasdaq     26,082.60  ▲ +0.4%
WTI crude      77.49  ▲ +9.7%
EUR/USD       1.1423  = -0.0%
GBP/USD       1.3418  ▲ +0.4%
USD/JPY       162.19  ▲ +0.1%