================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Friday, July 17, 2026 - 4:05 PM EDT ================================================================ A publicly released Windows zero-day, a Chinese theft of DigiCert's code-signing trust, and a botnet ransacking exposed AI servers marked a day of attacks aimed at the internet's foundations. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Attackers are industrializing infrastructure abuse, as the NadMesh botnet harvests cloud keys from exposed AI tooling while ViteVenom smuggles blockchain-backed malware into the npm registry. see: Botnets Hunt Exposed AI Services; Blockchain-Backed npm Supply Chain Attack * [UPDATE (new)] A publicly released LegacyHive exploit hands local attackers administrator rights on fully patched Windows, extending a week of privilege-escalation pressure on defenders. see: LegacyHive Windows Zero-Day Exploit Goes Public * [UPDATE (new)] Symantec's Threat Hunter Team detailed Spirals, a new Rust ransomware that went from initial access to full encryption in under 24 hours. see: Spirals Ransomware and Fairlife Shutdown * [TREND] Attribution and arrests advanced as Expel tied the DigiCert breach to China's GoldenEyeDog while Armenia detained a disputed REvil ransomware suspect. see: DigiCert Breach Tied to China's GoldenEyeDog; REvil Suspect Detained, Fraud Launderers Charged * [TREND] Commentators soured on AI economics, with Zitron branding OpenAI an unsustainable bubble and Ben Thompson doubting IBM's mainframe-bound positioning for the AI era. see: The OpenAI Bubble; IBM Misses, IBM’s Mainframe Moat, IBM’s Many AI Problems * [UPDATE (new)] Saturday storms will wash out wildfire smoke and end the Code Purple alert that shut Kennywood, Sandcastle, and Idlewild across Allegheny County. see: Wildfire Smoke to Clear With Saturday Storms SECURITY ---------------------------------------------------------------- 1. LEGACYHIVE WINDOWS ZERO-DAY EXPLOIT GOES PUBLIC Vulnerabilities and Exploits · [zero-day, ics, dos] Latest developments: A researcher using the "Nightmare Eclipse" handle published a working LegacyHive exploit that escalates local attackers to administrator on fully patched Windows, Palo Alto Networks' Unit 42 disclosed three chained Siemens ROX II OT-switch zero-days that yield persistent root, and the new HollowByte flaw crashes OpenSSL servers with an 11-byte payload. LegacyHive grants admin rights on current Windows builds, the Siemens ROX II chain compromises industrial switches, and HollowByte lets any unauthenticated sender exhaust an OpenSSL server's memory. Administrators should apply the Siemens and OpenSSL fixes and hunt for LegacyHive privilege escalation. - BleepingComputer: https://www.bleepingcomputer.com/news/security/new-windows-legacyhive-zero-day-exploit-grants-hackers-admin-access/ - Unit 42 (Palo Alto): https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/ 2. SPIRALS RANSOMWARE AND FAIRLIFE SHUTDOWN Ransomware and Cybercrime · [ransomware] Latest developments: Symantec's Threat Hunter Team detailed Spirals, a previously unknown Rust ransomware that moved from initial access to data theft and full encryption in under 24 hours against a South Asian IT-services firm, while The Record placed Coca-Cola's Fairlife shutdown at plants in Michigan, New York, and Arizona and Nichirei began restoring the systems it cut off July 13. Spirals encrypts each file with a separate AES-128 key wrapped by attacker-controlled ECDH, leaving defenders little time to react, and the Fairlife and Nichirei incidents show ransomware still idling major food producers. Keep offline backups and rapid isolation playbooks ready. - Help Net Security: https://www.helpnetsecurity.com/2026/07/17/spirals-ransomware-south-asia/ - The Record: https://therecord.media/dairy-company-fairlife-suspends-production-us-cyber-incident - SecurityWeek: https://www.securityweek.com/cyberattack-disrupts-operations-of-japanese-frozen-food-giant-nichirei/ 3. BOTNETS HUNT EXPOSED AI SERVICES AI Security · [ai, botnet, cloud] Latest developments: A Go botnet called NadMesh surfaced in early July using a Shodan harvester to find exposed ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio instances, and its operator dashboard claims 3,811 stolen AWS keys alongside Kubernetes tokens, as Dark Reading warned that AI models allowed to both interpret and execute commands strip away human oversight. Teams stand up AI model runners and workflow builders fast and firewall them late, leaving them open to credential theft. Restrict network access to AI services and rotate any cloud keys those services can reach. - The Hacker News: https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html - Dark Reading: https://www.darkreading.com/application-security/real-ai-threat-blind-trust 4. REVIL SUSPECT DETAINED, FRAUD LAUNDERERS CHARGED Ransomware and Cybercrime · [arrest, fraud, ransomware] Latest developments: Armenia has held Russian tourist Aleksandr Ermakov since June 28 on a US extradition request naming a REvil ransomware suspect of the same name, though his wife, Maria Yurova, and his lawyers say officers seized the wrong man, and US prosecutors charged a New York man and woman with laundering $43 million stolen through cyber investment-fraud scams. The cases mark continued law-enforcement pressure on ransomware suspects and the money mules who cash out online fraud. Border stops and money-laundering charges remain the main tools reaching operators shielded inside Russia. - The Hacker News: https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/us-charges-two-over-laundering-43-million-from-investment-fraud/ 5. DIGICERT BREACH TIED TO CHINA'S GOLDENEYEDOG Data Breaches · [breach, apt] Latest developments: Expel attributed the April 2026 DigiCert security incident to CylindricalCanine, a subgroup of the Chinese cybercrime group GoldenEyeDog—also tracked as APT-Q-27, Dragon Breath, and Miuuti Group—and linked the intrusion to the theft of code-signing certificates. GoldenEyeDog, a Chinese crew known for hitting the gambling and gaming sectors, breached certificate authority DigiCert and stole code-signing certificates that let attackers sign malware as trusted software. Defenders should scrutinize recently signed binaries. - The Hacker News: https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html 6. BLOCKCHAIN-BACKED NPM SUPPLY CHAIN ATTACK Software Supply Chain · [supply-chain, malware] Latest developments: Checkmarx uncovered seven malicious npm packages, codenamed ViteVenom, that target the Vite frontend toolchain and expand the ChainVeil campaign with a four-tier blockchain command-and-control network spanning Tron to deliver a remote access trojan. The packages impersonate Vite tooling and pull attacker instructions from blockchain contracts, which resist takedown. Developers should audit dependencies and pin trusted package versions. - The Hacker News: https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html BUSINESS AND POLITICS ---------------------------------------------------------------- * U.S.-Iran War Widens as House Weighs War Funding Latest developments: House Republicans pushed ahead Friday, July 17, on a package to fund the Iran war—much smaller than President Trump wants and uncertain to pass amid party divisions—as crude oil posted double-digit weekly gains. American strikes on increasingly sensitive Persian Gulf targets risk spiraling into a wider war as Iran hits back at neighboring Gulf states, and oil futures climbed all week on fears of supply disruption near the Strait of Hormuz. - WSJ World News: https://www.wsj.com/world/middle-east/the-u-s-and-iran-creep-toward-a-wider-war-with-escalating-attacks-7323c060 - WSJ Markets: https://www.wsj.com/finance/commodities-futures/oil-rises-amid-escalating-supply-disruption-concerns-c3dcf86d?mod=rss_markets_main - WSJ Politics: https://www.wsj.com/politics/policy/gop-package-to-fund-iran-war-runs-into-republican-doubts-5502da4e PITTSBURGH ---------------------------------------------------------------- Weather: This Afternoon: Smoke, high 88F. Tonight: Smoke, low 71F. Saturday: Areas Of Smoke then Patchy Smoke, high 86F. Business: * Startup Bank Files for Pittsburgh Charter Latest developments: Two former bank executives and a Pittsburgh lawyer filed a national-charter application July 14, launching the region's first new bank in almost 20 years, WPXI reported. A core group of six—led by former BNY and Huntington executives and a law-firm partner—applied to federal regulators to charter a startup bank in Pittsburgh, the first new bank in the region in nearly two decades. - WPXI: https://www.wpxi.com/news/local/former-bny-huntington-execs-law-firm-partner-file-launch-startup-bank-pittsburgh/4HY55FEQHVBMRECQ6XPTUWQPPQ/ * U.S. Steel Showcases Braddock Mill Investment Latest developments: U.S. Steel showcased job openings and its multibillion-dollar Edgar Thomson investment Friday, July 17, projecting the new Braddock hot strip mill will finish by 2029 and add $1.7 billion to Pennsylvania's economy, WTAE reported. U.S. Steel is building a new hot strip mill at its Edgar Thomson plant in Braddock, with completion projected in 2029 and $1.7 billion in economic impact for the commonwealth. - WTAE: https://www.wtae.com/article/us-steel-investment-braddock-mill-edgar-thomson/72914201 Around town: * Wildfire Smoke to Clear With Saturday Storms Latest developments: Meteorologists said Friday, July 17, that strong to severe storms arriving late Saturday will wash out the wildfire smoke, ending the Code Purple alert that shut Kennywood, Sandcastle, and Idlewild and canceled Allegheny County events. Thick smoke from Canadian and Minnesota wildfires held Pennsylvania under a statewide Code Purple "very unhealthy" alert Friday, closing the Kennywood, Sandcastle, and Idlewild amusement parks and prompting County Executive Sara Innamorato to urge residents to stay indoors. - WTAE: https://www.wtae.com/article/heavy-smoke-to-storms-two-alert-days-for-western-pa/73148972 - WTAE: https://www.wtae.com/article/kennywood-sandcastle-and-idlewild-all-closed-due-to-code-purple-air-quality-alert/73168952 * I-279 North to Close Five Nights Next Week Latest developments: The Allegheny County Department of Public Works released a schedule Friday, July 17, to fully close northbound I-279 for five overnight stretches next week. Crews will fully close a portion of northbound Interstate 279 for five nights next week to demolish Jacks Run Bridge No. 3, which carries Jacks Run Road over the highway. - WPXI: https://www.wpxi.com/news/local/portion-northbound-i-279-fully-close-5-nights-next-week/KRQQXCW7OJHDPDVKM75YBMGFBU/ * State Police, Turnpike Collect $2 Million in Tolls Latest developments: The Pennsylvania Turnpike and state police said their first joint toll-enforcement initiative recovered more than $2 million in unpaid tolls, KDKA reported July 17. A one-month enforcement push by the Pennsylvania Turnpike and Pennsylvania State Police collected more than $2 million in unpaid tolls, stopping aggressive drivers and those with suspended registrations tied to unpaid bills. - KDKA: https://www.cbsnews.com/pittsburgh/news/pa-state-police-and-pa-turnpike-team-up-to-collect-more-than-2-million-in-unpaid-tolls/ SPORTS ---------------------------------------------------------------- Pirates (50-47) Up Next · Pirates @ Guardians · Fri Jul 17, 7:10 PM https://plaintextsports.com/mlb/2026-07-17/pit-cle Team USA: * Lindsey Heaps Returns Home With Denver Summit Latest developments: ESPN reported July 17 that U.S. women's national team midfielder Lindsey Heaps, after stints with Paris Saint-Germain and abroad, joined NWSL expansion side Denver Summit FC, a return to her native Colorado. United States women's national team midfielder Lindsey Heaps, a veteran of Paris Saint-Germain and Olympique Lyonnais, signed with new NWSL club Denver Summit FC, bringing her career back to the Colorado region where she grew up. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49363167/for-uswnt-star-lindsey-heaps-transfer-denver-summit-marks-welcome-return-home READING ---------------------------------------------------------------- * Stratechery -- IBM Misses, IBM’s Mainframe Moat, IBM’s Many AI Problems Ben Thompson reads IBM's spooked-the-market preliminary results as a story about the durability and limits of its mainframe franchise, and why that franchise leaves the company poorly positioned for the AI era. https://stratechery.com/2026/ibm-misses-ibms-mainframe-moat-ibms-many-ai-problems/ * Ed Zitron -- The OpenAI Bubble Zitron argues OpenAI's finances and growth story amount to an unsustainable bubble, a company burning cash without a path to the returns its valuation implies. https://www.wheresyoured.at/the-openai-bubble/ * Cal Newport -- Why Reading Matters Responding to an Atlantic piece declaring 'the end of reading,' Newport defends deep reading as a cognitive skill worth preserving against the drift toward shorter, shallower attention. https://calnewport.com/why-reading-matters/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,548.10 ▲ +0.5% Dow 52,571.11 ▼ -0.3% Nasdaq 26,082.60 ▲ +0.4% WTI crude 77.49 ▲ +9.7% EUR/USD 1.1423 = -0.0% GBP/USD 1.3418 ▲ +0.4% USD/JPY 162.19 ▲ +0.1% ================================================================ Generated 2026-07-17 16:05 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================