daily plain-text briefing: security, markets, business, and pittsburgh
A publicly released Windows zero-day, a Chinese theft of DigiCert's code-signing trust, and a botnet ransacking exposed AI servers marked a day of attacks aimed at the internet's foundations.
Latest developments: A researcher using the "Nightmare Eclipse" handle published a working LegacyHive exploit that escalates local attackers to administrator on fully patched Windows, Palo Alto Networks' Unit 42 disclosed three chained Siemens ROX II OT-switch zero-days that yield persistent root, and the new HollowByte flaw crashes OpenSSL servers with an 11-byte payload.
LegacyHive grants admin rights on current Windows builds, the Siemens ROX II chain compromises industrial switches, and HollowByte lets any unauthenticated sender exhaust an OpenSSL server's memory. Administrators should apply the Siemens and OpenSSL fixes and hunt for LegacyHive privilege escalation.
Sources: BleepingComputer · Unit 42 (Palo Alto) · BleepingComputer · ↑ top
Latest developments: Symantec's Threat Hunter Team detailed Spirals, a previously unknown Rust ransomware that moved from initial access to data theft and full encryption in under 24 hours against a South Asian IT-services firm, while The Record placed Coca-Cola's Fairlife shutdown at plants in Michigan, New York, and Arizona and Nichirei began restoring the systems it cut off July 13.
Spirals encrypts each file with a separate AES-128 key wrapped by attacker-controlled ECDH, leaving defenders little time to react, and the Fairlife and Nichirei incidents show ransomware still idling major food producers. Keep offline backups and rapid isolation playbooks ready.
Sources: Help Net Security · The Record · SecurityWeek · ↑ top
Latest developments: A Go botnet called NadMesh surfaced in early July using a Shodan harvester to find exposed ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio instances, and its operator dashboard claims 3,811 stolen AWS keys alongside Kubernetes tokens, as Dark Reading warned that AI models allowed to both interpret and execute commands strip away human oversight.
Teams stand up AI model runners and workflow builders fast and firewall them late, leaving them open to credential theft. Restrict network access to AI services and rotate any cloud keys those services can reach.
Sources: The Hacker News · Dark Reading · ↑ top
Latest developments: Armenia has held Russian tourist Aleksandr Ermakov since June 28 on a US extradition request naming a REvil ransomware suspect of the same name, though his wife, Maria Yurova, and his lawyers say officers seized the wrong man, and US prosecutors charged a New York man and woman with laundering $43 million stolen through cyber investment-fraud scams.
The cases mark continued law-enforcement pressure on ransomware suspects and the money mules who cash out online fraud. Border stops and money-laundering charges remain the main tools reaching operators shielded inside Russia.
Sources: The Hacker News · BleepingComputer · ↑ top
Latest developments: Expel attributed the April 2026 DigiCert security incident to CylindricalCanine, a subgroup of the Chinese cybercrime group GoldenEyeDog—also tracked as APT-Q-27, Dragon Breath, and Miuuti Group—and linked the intrusion to the theft of code-signing certificates.
GoldenEyeDog, a Chinese crew known for hitting the gambling and gaming sectors, breached certificate authority DigiCert and stole code-signing certificates that let attackers sign malware as trusted software. Defenders should scrutinize recently signed binaries.
Sources: The Hacker News · ↑ top
Latest developments: Checkmarx uncovered seven malicious npm packages, codenamed ViteVenom, that target the Vite frontend toolchain and expand the ChainVeil campaign with a four-tier blockchain command-and-control network spanning Tron to deliver a remote access trojan.
The packages impersonate Vite tooling and pull attacker instructions from blockchain contracts, which resist takedown. Developers should audit dependencies and pin trusted package versions.
Sources: The Hacker News · ↑ top
Latest developments: House Republicans pushed ahead Friday, July 17, on a package to fund the Iran war—much smaller than President Trump wants and uncertain to pass amid party divisions—as crude oil posted double-digit weekly gains.
American strikes on increasingly sensitive Persian Gulf targets risk spiraling into a wider war as Iran hits back at neighboring Gulf states, and oil futures climbed all week on fears of supply disruption near the Strait of Hormuz.
Sources: WSJ World News · WSJ Markets · WSJ Politics · ↑ top
This Afternoon: Smoke, high 88F.
Tonight: Smoke, low 71F.
Saturday: Areas Of Smoke then Patchy Smoke, high 86F.
Latest developments: Two former bank executives and a Pittsburgh lawyer filed a national-charter application July 14, launching the region's first new bank in almost 20 years, WPXI reported.
A core group of six—led by former BNY and Huntington executives and a law-firm partner—applied to federal regulators to charter a startup bank in Pittsburgh, the first new bank in the region in nearly two decades.
Latest developments: U.S. Steel showcased job openings and its multibillion-dollar Edgar Thomson investment Friday, July 17, projecting the new Braddock hot strip mill will finish by 2029 and add $1.7 billion to Pennsylvania's economy, WTAE reported.
U.S. Steel is building a new hot strip mill at its Edgar Thomson plant in Braddock, with completion projected in 2029 and $1.7 billion in economic impact for the commonwealth.
Latest developments: Meteorologists said Friday, July 17, that strong to severe storms arriving late Saturday will wash out the wildfire smoke, ending the Code Purple alert that shut Kennywood, Sandcastle, and Idlewild and canceled Allegheny County events.
Thick smoke from Canadian and Minnesota wildfires held Pennsylvania under a statewide Code Purple "very unhealthy" alert Friday, closing the Kennywood, Sandcastle, and Idlewild amusement parks and prompting County Executive Sara Innamorato to urge residents to stay indoors.
Latest developments: The Allegheny County Department of Public Works released a schedule Friday, July 17, to fully close northbound I-279 for five overnight stretches next week.
Crews will fully close a portion of northbound Interstate 279 for five nights next week to demolish Jacks Run Bridge No. 3, which carries Jacks Run Road over the highway.
Latest developments: The Pennsylvania Turnpike and state police said their first joint toll-enforcement initiative recovered more than $2 million in unpaid tolls, KDKA reported July 17.
A one-month enforcement push by the Pennsylvania Turnpike and Pennsylvania State Police collected more than $2 million in unpaid tolls, stopping aggressive drivers and those with suspended registrations tied to unpaid bills.
Pirates (50-47)
Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM
Latest developments: ESPN reported July 17 that U.S. women's national team midfielder Lindsey Heaps, after stints with Paris Saint-Germain and abroad, joined NWSL expansion side Denver Summit FC, a return to her native Colorado.
United States women's national team midfielder Lindsey Heaps, a veteran of Paris Saint-Germain and Olympique Lyonnais, signed with new NWSL club Denver Summit FC, bringing her career back to the Colorado region where she grew up.
Sources: ESPN Soccer · ↑ top
S&P 500 7,548.10 ▲ +0.5% Dow 52,571.11 ▼ -0.3% Nasdaq 26,082.60 ▲ +0.4% WTI crude 77.49 ▲ +9.7% EUR/USD 1.1423 = -0.0% GBP/USD 1.3418 ▲ +0.4% USD/JPY 162.19 ▲ +0.1%