================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Saturday, July 18, 2026 - 12:06 PM EDT ================================================================ Two easy-to-trigger, unauthenticated flaws land with working exploit code the same day—a WordPress core bug that runs code from one anonymous request and an OpenSSL denial-of-service that an 11-byte packet sets off. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Two unauthenticated server flaws now ship with working exploits, as wp2shell runs code on any WordPress core install and HollowByte freezes an OpenSSL server with an 11-byte packet. see: wp2shell WordPress Core Flaw Gains CVEs and Public Exploit; OpenSSL HollowByte Denial-of-Service Flaw * [TREND] Adversaries keep poisoning the software trust layer, with the ViteVenom npm packages smuggling a blockchain C2 trojan while a Chinese crew stole code-signing certificates through DigiCert. see: ViteVenom Poisons npm With Blockchain C2; GoldenEyeDog Subgroup Tied to DigiCert Breach * [TREND] Credential theft scales as the NadMesh botnet loots cloud keys from exposed ComfyUI and Ollama instances while ACR Stealer surges against Microsoft enterprise customers. see: NadMesh Botnet Hunts Exposed AI Services; ACR Stealer Surge Hits Enterprises * [UPDATE (new)] Severe storms and flash flooding sweep the Pittsburgh region after wildfire smoke, prompting Duquesne Light to add crews and Picklesburgh to extend its Sunday hours. see: Storms and Flash Flooding Follow the Smoke; Duquesne Light Staffs Up for Storms; Picklesburgh Extends Sunday Hours * [UPDATE (new)] The Gulf war escalates as Tehran fields deadlier missiles, making the past week the deadliest yet for commercial sailors in the Persian Gulf. see: Gulf War Escalates as Tehran Fields Deadlier Missiles SECURITY ---------------------------------------------------------------- 1. WP2SHELL WORDPRESS CORE FLAW GAINS CVES AND PUBLIC EXPLOIT Vulnerabilities and Exploits · [zero-day, patch, rce] Latest developments: The flaws now carry CVE identifiers including CVE-2026-60137, WordPress shipped the 7.0.2 release, and today the full exploit mechanism plus a working proof-of-concept went public. wp2shell lets an anonymous HTTP request run code on a bare WordPress core install with zero plugins, putting every 6.9 and 7.0 site in range; Adam Kues of Assetnote and Searchlight Cyber traced it to a REST API batch-route confusion and SQL injection chain. Update to 6.9.5 or 7.0.2 at once. - Help Net Security: https://www.helpnetsecurity.com/2026/07/18/wordpress-vulnerabilities-wp2shell-cve-2026-60137-cve-2026-60137/ - The Hacker News: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html 2. ACR STEALER SURGE HITS ENTERPRISES Ransomware and Cybercrime · [infostealer, credential-theft] Latest developments: Microsoft warned of a surge in ACR Stealer attacks against its enterprise customers, pulling browser-stored passwords, authentication tokens, and sensitive documents. ACR Stealer, spread largely through ClickFix copy-paste lures, grabs credentials and session tokens that fuel follow-on intrusion. Reset exposed credentials and block the delivery lures. - BleepingComputer: https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/ 3. OPENSSL HOLLOWBYTE DENIAL-OF-SERVICE FLAW Vulnerabilities and Exploits · [dos, patch, vulnerability] Latest developments: Okta's Red Team disclosed HollowByte, showing an 11-byte TLS request forces an unpatched OpenSSL server to reserve up to 131 KB of memory for a message that never arrives, memory that stays gone on glibc systems until the process restarts. Unauthenticated attackers can exhaust OpenSSL server memory and crash the service; OpenSSL quietly shipped the fix in June with no CVE, advisory, or changelog entry pointing at it. Move to the fixed OpenSSL build. - The Hacker News: https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/ 4. VITEVENOM POISONS NPM WITH BLOCKCHAIN C2 Software Supply Chain · [supply-chain, npm, rat] Latest developments: Checkmarx uncovered seven malicious npm packages targeting the Vite frontend ecosystem, codenamed ViteVenom, expanding the ChainVeil campaign's four-tier blockchain command-and-control spanning Tron and other chains to deliver a remote access trojan. The packages impersonate Vite tooling to drop a RAT on developers, using blockchain infrastructure that resists takedown. Audit dependencies and pull the malicious versions. - The Hacker News: https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html 5. NADMESH BOTNET HUNTS EXPOSED AI SERVICES AI Security · [botnet, cloud, credential-theft] Latest developments: A Go botnet named NadMesh surfaced in early July scanning for exposed ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio instances, and the operator's own dashboard claims 3,811 stolen AWS keys alongside Kubernetes tokens. NadMesh runs a Shodan-fed scan queue to find self-hosted AI tools that teams stand up fast and firewall late, then harvests cloud credentials for further intrusion. Firewall and authenticate every AI service endpoint. - The Hacker News: https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html 6. GOLDENEYEDOG SUBGROUP TIED TO DIGICERT BREACH Ransomware and Cybercrime · [apt, breach, code-signing] Latest developments: Expel attributed the April 2026 DigiCert incident to CylindricalCanine, a subgroup of the Chinese group GoldenEyeDog, also tracked as APT-Q-27, Dragon Breath, and Miuuti Group, and laid out the code-signing certificate theft behind it. GoldenEyeDog, known for hitting the gambling and gaming sectors, stole code-signing certificates through the DigiCert breach, letting it sign malware as trusted software. Watch for and block binaries signed with the abused certificates. - The Hacker News: https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html BUSINESS AND POLITICS ---------------------------------------------------------------- * Gulf War Escalates as Tehran Fields Deadlier Missiles Latest developments: Beyond Saturday's Saudi strike already reported, the Wall Street Journal reported Iran has switched to more-lethal missiles that made the past week the deadliest yet for commercial sailors in the Persian Gulf, while the U.S. Strategic Petroleum Reserve has drained to its lowest level since 1983. The United States and Iran keep trading strikes on infrastructure and military targets across the Persian Gulf around the Strait of Hormuz, the chokepoint that once carried a fifth of the world's crude, raising the risk of a wider war and tightening global oil supply. - WSJ World News: https://www.wsj.com/world/middle-east/the-u-s-and-iran-creep-toward-a-wider-war-with-escalating-attacks-7323c060 - WSJ World News: https://www.wsj.com/world/middle-east/gulf-sailing-risk-iran-war-fb61d65a - WSJ Markets: https://www.wsj.com/business/energy-oil/u-s-emergency-oil-reserve-hits-lowest-levels-since-1983-why-it-matters-a4ed79aa?mod=rss_markets_main PITTSBURGH ---------------------------------------------------------------- Weather: This Afternoon: Showers And Thunderstorms, high 87F. Tonight: Showers And Thunderstorms then Chance Showers And Thunderstorms, low 66F. Sunday: Mostly Sunny, high 82F. Business: * Fire Damages Fujiya Ramen Latest developments: Firefighters answered a call to South Aiken Avenue around 7:45 a.m. Saturday, July 18, and found flames at Fujiya Ramen. A morning fire damaged the dining room and second floor of Fujiya Ramen on South Aiken Avenue in Pittsburgh, and Allegheny County 911 officials said no one was hurt; the cause is unknown, and whether the flames reached adjoining businesses is unclear. - WPXI: https://www.wpxi.com/news/local/fire-damages-pittsburgh-ramen-restaurant/6AG2747IFRDDHNA7KERFMTDCTA/ * Duquesne Light Staffs Up for Storms Latest developments: Duquesne Light Company added crews Saturday, July 18, ahead of the forecast line of severe storms. Duquesne Light Company increased staffing across its service territory as forecasters warned of widespread damaging winds and isolated tornadoes moving through the Pittsburgh region Saturday evening, conditions that threaten power outages. - WPXI: https://www.wpxi.com/news/local/duquesne-light-company-increases-staffing-ahead-potentially-severe-weather/7TKYGWXHNNBNBAIXM6SUXWDOBM/ Around town: * Storms and Flash Flooding Follow the Smoke Latest developments: Air-quality alerts across the Pittsburgh region ended before 10 a.m. Saturday, July 18, and forecasters posted a flash flood warning and watch as a line of thunderstorms carrying damaging winds, hail, and possible tornadoes drops south after 4 p.m. A wind shift cleared the Canadian wildfire smoke that fouled the week's air across Western Pennsylvania, but strong to severe storms and flooding now threaten to delay games and events into Saturday evening. - WTAE: https://www.wtae.com/article/severe-weather-alerts-saturday-july-18-2026/73176132 - KDKA: https://www.cbsnews.com/pittsburgh/news/air-quality-improves-on-saturday-in-pittsburgh-but-strong-storms-possible-throughout-the-day/ * Water Main Break Closes Baldwin Road Latest developments: A large water main break in the 3300 block of Churchview Avenue shut the congested road for hours in Baldwin Borough on Saturday, July 18. The Baldwin Borough Police Department urged drivers to find alternate routes after the break disrupted water service and closed Churchview Avenue in the borough south of Pittsburgh. - WPXI: https://www.wpxi.com/news/local/major-water-main-break-closes-road-impacts-service-baldwin/OVHEWTTN25G5ZOQCN2SPUXRKNY/ - WTAE: https://www.wtae.com/article/large-water-main-break-shuts-down-baldwin-borough-road-hours/73175866 * Duquesne-McKeesport School Merger Weighed Latest developments: The Post-Gazette laid out July 18 how consolidating the Duquesne City and McKeesport Area districts across the Monongahela River could help or hurt both cities and their students. The Pennsylvania Department of Education is studying a merger that would give the long-troubled Duquesne City school district a partner in the McKeesport Area district, a step with financial and community stakes for both Mon Valley cities. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/education/2026/07/18/duquesne-mckeesport-school-merge/stories/202607180016 Events: * Picklesburgh Extends Sunday Hours Latest developments: The Pittsburgh Downtown Partnership moved Picklesburgh's Sunday opening earlier, to 11 a.m. through 7 p.m. on July 19, to help vendors recover after wildfire smoke thinned Friday and Saturday crowds. Picklesburgh, the annual pickle-themed food festival in Downtown Pittsburgh, runs its final day Sunday, July 19; chief executive Jeremy Waldrup said the extended hours put the festival's small-business vendors first after an unprecedented weekend. - KDKA: https://www.cbsnews.com/pittsburgh/news/picklesburgh-2026-sunday-extended-hours/ - WTAE: https://www.wtae.com/article/the-pittsburgh-downtown-partnership-announces-extended-picklesburgh-hours/73175812 SPORTS ---------------------------------------------------------------- Pirates (50-47) Fri Jul 17 · Pirates @ Guardians · Postponed https://plaintextsports.com/mlb/2026-07-17/pit-cle Up Next · Pirates @ Guardians · Sat Jul 18, 1:10 PM https://plaintextsports.com/mlb/2026-07-18/pit-cle Around the Teams: * Steelers Bank on Cornerback Jamel Dean Latest developments: The Post-Gazette's training-camp countdown July 18 cast free-agent signing Jamel Dean as the Steelers' bid to finally land an impact cornerback in free agency. As the Steelers open camp at Saint Vincent College in Latrobe, the Post-Gazette framed newly signed cornerback Jamel Dean as the answer to a long drought at the position, working alongside Jalen Ramsey in Patrick Graham's secondary. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/18/training-camp-countdown-jamel-dean-cornerback/stories/202607180002 * Pirates' Second-Half Storylines Latest developments: The Post-Gazette laid out five storylines to watch as the Pirates open the second half chasing a wild-card spot. With ace Paul Skenes anchoring the rotation and a revamped offense, the Post-Gazette weighed the questions that will decide whether the Pirates stay in the National League playoff race. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/07/16/storylines-analysis-mlb-second-half-skenes/stories/202607150032 Team USA: * USWNT's Lindsey Heaps Returns to Colorado Latest developments: Lindsey Heaps and her family told ESPN about her transfer to NWSL expansion side Denver Summit FC, a homecoming after globetrotting with the U.S. women's national team and Paris Saint-Germain. U.S. women's national team midfielder Lindsey Heaps signed with Denver Summit FC, bringing her career back to Colorado after stops in France and beyond. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49363167/for-uswnt-star-lindsey-heaps-transfer-denver-summit-marks-welcome-return-home READING ---------------------------------------------------------------- * Stratechery -- IBM Misses, IBM's Mainframe Moat, IBM's Many AI Problems Argues that IBM's weak preliminary results spooked the software market, but the deeper story is the durability of its mainframe franchise set against its many exposures to the AI shift. https://stratechery.com/2026/ibm-misses-ibms-mainframe-moat-ibms-many-ai-problems/ * Ed Zitron -- The OpenAI Bubble Contends that OpenAI sits at the center of an AI investment bubble whose economics do not add up. https://www.wheresyoured.at/the-openai-bubble/ * Cal Newport -- Why Reading Matters Responds to Rose Horowitch's Atlantic article 'The End of Reading Is Here,' making the case for why sustained deep reading still matters. https://calnewport.com/why-reading-matters/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,524.56 ▼ -0.1% Dow 52,472.99 ▼ -0.4% Nasdaq 25,930.32 ▼ -0.5% WTI crude 79.70 ▲ +11.9% EUR/USD 1.1434 ▲ +0.1% GBP/USD 1.3444 ▲ +0.4% USD/JPY 162.28 = +0.0% ================================================================ Generated 2026-07-18 12:06 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================