================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Saturday, July 18, 2026 - 6:07 AM EDT ================================================================ Working exploit code went public for critical WordPress and Windows flaws as OpenSSL patched a one-packet denial-of-service bug and a Chinese group made off with DigiCert's code-signing certificates. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Working exploit code went public within days for the wp2shell WordPress flaw and Nightmare Eclipse's LegacyHive Windows privilege-escalation bug, shrinking defenders' window before mass exploitation begins. see: Public Exploit Code Lands for WordPress and Windows Flaws * [TREND] Attackers chase cloud credentials through novel plumbing, from ViteVenom npm packages routing command-and-control over blockchain to the NadMesh botnet scraping AWS keys off exposed AI services. see: npm Packages and NadMesh Botnet Harvest Cloud Keys * [UPDATE (new)] Expel tied April's DigiCert breach to China's GoldenEyeDog, whose theft of code-signing certificates lets stolen signatures pass malware off as legitimate software. see: GoldenEyeDog Steals DigiCert Code-Signing Certificates * [UPDATE (new)] Okta's Red Team disclosed HollowByte, an OpenSSL memory-exhaustion denial-of-service, as Symantec documented Spirals, Rust ransomware that raced from initial access to full encryption in under a day. see: OpenSSL HollowByte Freezes Server Memory; Spirals Ransomware Encrypts in Under a Day * [UPDATE (updated)] Iran switched to deadlier missiles in the Gulf war, striking a Kuwaiti desalination plant in one of the bloodiest stretches yet for commercial sailors. see: Iran Turns to Deadlier Missiles in Gulf War * [TREND] Saturday storms should wash out the wildfire smoke that thinned Picklesburgh crowds downtown, clearing the air before Sunday's Vintage Grand Prix. see: Storms to Wash Out Wildfire Smoke; Picklesburgh Winds Down Downtown; Vintage Grand Prix Races Sunday SECURITY ---------------------------------------------------------------- 1. PUBLIC EXPLOIT CODE LANDS FOR WORDPRESS AND WINDOWS FLAWS Vulnerabilities and Exploits · [zero-day, patch, exploit] Latest developments: wp2shell picked up CVE IDs today, and researchers published its full mechanism, a persistent-object-cache condition, and a working proof-of-concept, while a researcher using the handle Nightmare Eclipse released a complete LegacyHive exploit that hands attackers administrator rights on fully patched Windows. wp2shell, a WordPress core flaw Adam Kues of Assetnote found, runs code from a single anonymous HTTP request against any 6.9 or 7.0 site until admins install 6.9.5 or 7.0.2; LegacyHive escalates a local user to administrator on up-to-date Windows through the User Profile Service. Patch WordPress now and prepare for Microsoft's fix. - The Hacker News: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/new-windows-legacyhive-zero-day-exploit-grants-hackers-admin-access/ 2. OPENSSL HOLLOWBYTE FREEZES SERVER MEMORY Vulnerabilities and Exploits · [dos, patch] Latest developments: Okta's Red Team disclosed HollowByte, a denial-of-service flaw that makes an unpatched OpenSSL server reserve up to 131 KB of memory for an 11-byte TLS request that never arrives, memory that stays gone on glibc systems until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, advisory, or changelog note, so many administrators never learned to update, and unauthenticated attackers can exhaust server memory with tiny payloads. Rebuild against the patched OpenSSL. - The Hacker News: https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/ 3. SPIRALS RANSOMWARE ENCRYPTS IN UNDER A DAY Ransomware and Cybercrime · [ransomware] Latest developments: Symantec's Threat Hunter Team documented Spirals, a Rust ransomware that hit an IT services company in South Asia last month and moved from initial access to data theft and full encryption in under 24 hours, as a separate crew struck German naval-defense builder TKMS. Spirals encrypts each file with its own AES-128 key wrapped by attacker-controlled ECDH, leaving defenders little time to react, and the TKMS hit shows ransomware reaching into defense manufacturing. Tighten initial-access controls and rehearse rapid containment. - Help Net Security: https://www.helpnetsecurity.com/2026/07/17/spirals-ransomware-south-asia/ - SecurityWeek: https://www.securityweek.com/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/ 4. NPM PACKAGES AND NADMESH BOTNET HARVEST CLOUD KEYS Software Supply Chain · [supply-chain, botnet, cloud] Latest developments: Checkmarx flagged seven malicious npm packages, codenamed ViteVenom, that target the Vite tooling ecosystem and route command-and-control through a four-tier blockchain infrastructure spanning Tron to deliver a remote access trojan, while the new Go botnet NadMesh scanned exposed AI services and claims 3,811 stolen AWS keys. NadMesh harvests cloud keys and Kubernetes tokens from fast-deployed, slow-firewalled AI tools such as ComfyUI, Ollama, and Open WebUI, and ViteVenom extends the ChainVeil campaign's blockchain-based command-and-control. Lock down exposed AI services and vet npm dependencies. - The Hacker News: https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html - The Hacker News: https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html 5. REGULATORS RESHAPE AI ACCESS AND DEFENSE COMPLIANCE Policy and Regulation · [policy] Latest developments: The European Commission ordered Google to open Android's camera, microphone, on-screen content, and wake word to rival AI assistants in Android 18 by August 1, 2027, and the Pentagon suspended CMMC Phase 2, pausing third-party audits of defense contractors. The EU order forces Google to grant competitors the same device reach Gemini already enjoys, raising fresh privacy and security questions, while the CMMC pause halts audits yet leaves contractors' legal duty to protect controlled unclassified information intact. Track both as they reshape platform and compliance obligations. - The Hacker News: https://thehackernews.com/2026/07/eu-orders-google-to-open-android-mic.html - SecurityWeek: https://www.securityweek.com/industry-reactions-to-pentagon-suspending-cmmc-phase-2-feedback-friday/ 6. GOLDENEYEDOG STEALS DIGICERT CODE-SIGNING CERTIFICATES Nation-State Activity · [apt, breach, supply-chain] Latest developments: Expel attributed the April 2026 DigiCert breach to CylindricalCanine, a subgroup of the Chinese cybercrime group GoldenEyeDog, and tied the intrusion to the theft of code-signing certificates. GoldenEyeDog, also tracked as APT-Q-27, Dragon Breath, and Miuuti Group, has long targeted gambling and gaming operators, and stolen code-signing certificates let its malware masquerade as trusted software. Audit certificate trust and hunt for signed but unexpected binaries. - The Hacker News: https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html BUSINESS AND POLITICS ---------------------------------------------------------------- * Iran Turns to Deadlier Missiles in Gulf War Latest developments: Iran switched to more-lethal missiles over the past week, making it one of the deadliest stretches for commercial sailors since the war began, and on Saturday, July 18, struck neighboring Gulf states—hitting a Kuwaiti desalination plant—while U.S. bombs took out bridges. The United States and Iran traded strikes on infrastructure across the Persian Gulf, with neither side backing down and Iran firing on the waters around the Strait of Hormuz, sending oil futures to double-digit weekly gains and pushing the conflict toward a wider regional war. - WSJ World News: https://www.wsj.com/world/middle-east/the-u-s-and-iran-creep-toward-a-wider-war-with-escalating-attacks-7323c060 - WSJ World News: https://www.wsj.com/world/middle-east/gulf-sailing-risk-iran-war-fb61d65a - WSJ Markets: https://www.wsj.com/finance/commodities-futures/oil-rises-amid-escalating-supply-disruption-concerns-c3dcf86d?mod=rss_markets_main PITTSBURGH ---------------------------------------------------------------- Weather: Today: Showers And Thunderstorms Likely then Chance Showers And Thunderstorms, high 87F. Tonight: Showers And Thunderstorms, low 67F. Sunday: Mostly Sunny, high 82F. Business: * Parkway East Detour Lifts Homestead Shops Latest developments: WTAE reported July 17 that merchants along the Parkway East detour route through Homestead are gaining new customers as roughly 100,000 daily drivers reroute around the closed highway. PennDOT's closure of the Parkway East (I-376) for the Commercial Street Bridge replacement funnels detour traffic through the borough of Homestead, and shops and restaurants along the route say the passing drivers have lifted sales. - WTAE: https://www.wtae.com/article/parkway-east-detour-homestead-businesses/73172981 * Ford Tops J.D. Power Brand Ranking Latest developments: Ford Motor ranked first among mass-market car brands in J.D. Power and Associates' 2026 survey, and KDKA talked July 17 with a Pittsburgh-area dealer about what the result means for buyers. Ford placed atop J.D. Power's 2026 mass-market brand list, a ranking that shapes how area dealerships pitch the brand's reliability to shoppers. - KDKA: https://www.cbsnews.com/pittsburgh/video/ford-tops-2026-jd-power-and-associates-list-for-mass-market-car-brands/ Around town: * Storms to Wash Out Wildfire Smoke Latest developments: The EPA expects Pittsburgh's air to improve sharply this weekend as strong to severe storms forecast for Saturday afternoon, July 18, clear the wildfire smoke, after Thursday hit the hazardous maroon range and Friday held at Code Purple 'very unhealthy.' Smoke from wildfires in Canada and Minnesota drove Western Pennsylvania's air to 'very unhealthy' levels, closing Kennywood and Sandcastle, postponing the Pirates' game in Cleveland, and canceling the America's Mile race, before storms forecast for Saturday afternoon clear it out. - KDKA: https://www.cbsnews.com/pittsburgh/news/pittsburgh-air-quality-improving-wildfire-smoke/ - WTAE: https://www.wtae.com/article/severe-weather-alert-day-stronger-late-day-storms-for-western-pa/73175144 - WPXI: https://www.wpxi.com/news/local/americas-mile-race-canceled-because-poor-air-quality-pittsburgh/BD423Y7LQBBRZFRD6QC2JMF66Q/ * Duquesne-McKeesport School Merger Weighed Latest developments: The Post-Gazette examined July 18 how consolidating the Duquesne City and McKeesport Area school districts could help or hurt both cities, days after the Pennsylvania Department of Education agreed to study the merger. Pennsylvania's education department is analyzing a consolidation of the financially troubled Duquesne City School District with the McKeesport Area School District across the Monongahela River, a step that would give the struggling Duquesne district a full-district partner. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/education/2026/07/18/duquesne-mckeesport-school-merge/stories/202607180016 * Pa. AG Defends Medicaid Abortion Ban Latest developments: The Post-Gazette reported July 18 that Attorney General Dave Sunday is defending Pennsylvania's ban on Medicaid funding for abortion in a court challenge, and examined whether his office is legally required to mount that defense. Pennsylvania Attorney General Dave Sunday is defending the state's prohibition on Medicaid coverage of abortion against a court challenge, raising the question of whether the office must defend a law it may not favor. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/health/2026/07/18/dave-sunday-pennsylvania-medicaid-abortion/stories/202607180006 Events: * Picklesburgh Winds Down Downtown Latest developments: Picklesburgh drew thinner Friday crowds under the wildfire smoke, and the Pittsburgh Downtown Partnership kept all Saturday and Sunday activities on schedule through the festival's close Sunday, July 19. Picklesburgh, the Pittsburgh Downtown Partnership's pickle-themed street festival, runs through Sunday, July 19, in Downtown Pittsburgh, with hours of noon to 6 p.m. on the final day. - KDKA: https://www.cbsnews.com/pittsburgh/news/picklesburgh-not-canceled-air-quality-wildfire-smoke/ * Vintage Grand Prix Races Sunday Latest developments: The 44th Pittsburgh Vintage Grand Prix holds its race Sunday, July 19, as air quality improves following the week's wildfire smoke. The Pittsburgh Vintage Grand Prix, a vintage-car racing weekend, culminates in its 44th running Sunday, July 19. - NEXTpittsburgh Events: https://nextpittsburgh.com/events/14-things-to-do-this-weekend-from-picklesburgh-to-the-pittsburgh-vintage-grand-prix/ SPORTS ---------------------------------------------------------------- Pirates (50-47) Fri Jul 17 · Pirates @ Guardians · Postponed https://plaintextsports.com/mlb/2026-07-17/pit-cle Up Next · Pirates @ Guardians · Sat Jul 18, 1:10 PM https://plaintextsports.com/mlb/2026-07-18/pit-cle Around the Teams: * Steelers Bank on Jamel Dean at Corner Latest developments: A Post-Gazette training-camp countdown July 18 cast free-agent signing Jamel Dean as the Steelers' bid to stabilize a cornerback spot that has churned through open-market additions. The Post-Gazette's camp countdown argues cornerback Jamel Dean, whom the Steelers signed in free agency, must end the team's long run of misses on veteran corners as camp opens in Latrobe. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/18/training-camp-countdown-jamel-dean-cornerback/stories/202607180002 Team USA: * Lindsey Heaps Returns Home to Denver Latest developments: ESPN reported July 17 that United States women's national team star Lindsey Heaps is transferring to NWSL expansion side Denver Summit FC, a homecoming to Colorado after years with PSG and other European clubs. Lindsey Heaps, a veteran United States women's national team midfielder, is joining the new NWSL club Denver Summit FC, ending a globetrotting run through European soccer to return to her home state of Colorado. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49363167/for-uswnt-star-lindsey-heaps-transfer-denver-summit-marks-welcome-return-home READING ---------------------------------------------------------------- * Stratechery -- IBM Misses, IBM's Mainframe Moat, IBM's Many AI Problems Ben Thompson examines how IBM's weak preliminary results rattled software stocks, tracing the mainframe franchise that still forms IBM's moat and the AI-era problems now testing it. https://stratechery.com/2026/ibm-misses-ibms-mainframe-moat-ibms-many-ai-problems/ * Ed Zitron -- The OpenAI Bubble Zitron argues that OpenAI's soaring valuation rests on unsustainable economics and hype, laying out why he sees the company as the center of an AI financial bubble. https://www.wheresyoured.at/the-openai-bubble/ * Cal Newport -- Why Reading Matters Responding to Rose Horowitch's Atlantic piece 'The End of Reading Is Here,' Newport argues that sustained deep reading remains essential to serious thinking even as the habit erodes. https://calnewport.com/why-reading-matters/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,524.56 ▼ -0.1% Dow 52,472.99 ▼ -0.4% Nasdaq 25,930.32 ▼ -0.5% WTI crude 79.70 ▲ +11.9% EUR/USD 1.1434 ▲ +0.1% GBP/USD 1.3444 ▲ +0.4% USD/JPY 162.28 = +0.0% ================================================================ Generated 2026-07-18 06:07 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================