infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

Autonomous AI agents graduated to real intruders as one breached Hugging Face's production infrastructure while researchers escaped the sandboxes of four leading AI coding tools.


Emerging Trends and Key Updates

Security

1. Autonomous AI Agent Breaches Hugging Face

AI Security · [ai, breach]

Latest developments: Hugging Face disclosed that an autonomous AI agent system breached its production infrastructure through a malicious dataset, reaching a limited set of internal datasets and several service credentials before the company detected and contained the intrusion.

read more

Hugging Face, the largest open-source repository for machine-learning models and datasets, said an attacker weaponized a poisoned dataset to hijack an agent and pivot into internal systems; users should rotate exposed credentials and scrutinize untrusted datasets.

Sources: BleepingComputer · The Hacker News · SecurityWeek · Help Net Security · ↑ top

2. AI Agents Weaponized Against Code and Models

AI Security · [ai, rce, ransomware]

Latest developments: Researchers escaped the sandboxes of Cursor, Codex, Gemini CLI, and Antigravity by getting the agent to write files that trusted host tools later execute, drawing multiple CVEs and patches while Google downgraded two Antigravity findings, and the JadePuffer autonomous agent gained EncForge malware that encrypts AI training datasets, vector databases, and model checkpoints.

read more

Developers' AI coding assistants and the AI supply chain now form an active attack surface; the same session logs that exposed sandbox escapes also caught Russian-speaking actor bandcampro driving a botnet through Google's Gemini CLI, so teams should patch these tools and constrain what agents can write and run.

Sources: BleepingComputer · BleepingComputer · The Hacker News · ↑ top

3. WP2Shell WordPress Core RCE Exploited

Vulnerabilities and Exploits · [rce, exploit, patch]

Latest developments: Attackers began chaining CVE-2026-60137 and CVE-2026-63030 against WordPress sites within three days of Searchlight Cyber's disclosure, and the SQL-injection-to-remote-code-execution flaw sitting in WordPress core itself drew CVE-2026-63030.

read more

WP2Shell lets an unauthenticated attacker run code on any unpatched WordPress site through a SQL injection in core, exposing millions of sites; administrators should confirm they run the patched releases immediately.

Sources: Dark Reading · SANS Internet Storm Center · SecurityWeek · ↑ top

4. HollowGraph Linked to Iranian Espionage

Nation-State Activity · [apt, espionage]

Latest developments: Group-IB tied HollowGraph with high confidence to the modular Cavern backdoor framework and linked the calendar-hijacking campaign to Iranian espionage activity.

read more

HollowGraph turns a compromised Microsoft 365 calendar into a command channel, hiding tasking and stolen files in appointments dated to 2050 so activity blends into legitimate Microsoft Graph traffic; defenders should audit mailbox calendar automation and Graph API access.

Sources: Help Net Security · The Hacker News · BleepingComputer · ↑ top

5. SonicWall SMA1000 Zero-Days Push Custom Malware

Vulnerabilities and Exploits · [zero-day, vpn, exploit]

Latest developments: SonicWall and researchers confirmed the two SMA1000 flaws, CVE-2026-15409 and CVE-2026-15410, carried custom malware onto the VPN appliances during the weeks Volexity-tracked actor UTA0533 ran them as zero-days ahead of the patch.

read more

SonicWall's Secure Mobile Access 1000 series VPN appliances gave UTA0533 root and a foothold for bespoke implants; organizations running them should patch at once and hunt for signs of compromise.

Sources: BleepingComputer · SecurityWeek · ↑ top

6. Estée Lauder and Ernst & Young Breaches

Data Breaches · [breach, exploit]

Latest developments: Estée Lauder began notifying customers after hackers exploited an Oracle E-Business Suite flaw in the human-resources systems the cosmetics company ran, and Ernst & Young started notifying people after thieves pulled names, addresses, Social Security numbers, and payment-card numbers from a third-party management platform.

read more

Two large enterprises traced fresh breaches to vulnerable back-office software, one an Oracle E-Business Suite flaw and one a compromised third-party platform; affected customers should watch for identity theft and card fraud.

Sources: BleepingComputer · SecurityWeek · ↑ top

Business and Politics

U.S. Slaps 50% Tariffs on Canadian Goods

Latest developments: President Trump imposed an additional 50% tariff Monday on a wide range of Canadian goods, accusing Ottawa of unfair practices in autos, alcohol, and dairy.

read more

The measure covers most Canadian imports including wine and cheese while exempting energy and parts of the auto sector, and it threatens to reignite the North American trade war between the two neighbors.

Sources: WSJ World News · FT World · ↑ top

Iran War Grinds On as Israel Flags Hidden Centrifuges

Latest developments: Israel believes Iran moved nuclear centrifuges into a fortified site called Pickaxe Mountain and Trump threatened to strike it, while the Pentagon said nearly 100 U.S. troops suffered injuries over the past two weeks.

read more

An Iranian missile struck housing units for U.S. troops at a base in Jordan, killing American service members, as U.S.-Iran fighting escalated and mediators pressed for a 10-day ceasefire; U.S. gasoline climbed back above $4 a gallon.

Sources: WSJ World News · FT World · WSJ World News · ↑ top

Pittsburgh

Weather

Tonight: Mostly Cloudy, low 67F.

Tuesday: Slight Chance Showers And Thunderstorms then Showers And Thunderstorms, high 82F.

Tuesday Night: Showers And Thunderstorms then Slight Chance Showers And Thunderstorms, low 65F.

Business

124 Townhomes Planned for Banksville

Latest developments: Split Rock Real Estate Partners filed plans with the city of Pittsburgh for a 124-unit development on the shuttered Vincentian Marian Manor site.

read more

Split Rock Real Estate Partners has proposed Golden Horizons, 124 townhomes marketed to residents 55 and older with a community center, swimming pool, fitness center, and putting green, on the former Vincentian Marian Manor assisted-living property in Pittsburgh's Banksville neighborhood, which closed several years ago.

Sources: KDKA · ↑ top

Fire Shutters Fujiya Ramen in Shadyside

Latest developments: A fire caused significant damage and closed the restaurant until further notice, and the owners say they hope to rebuild.

read more

Fujiya Ramen, a popular restaurant in Pittsburgh's Shadyside neighborhood, closed after a fire caused significant damage to the building.

Sources: WTAE · ↑ top

Around Town

Transit Agency Softens Shaler Bus Cuts

Latest developments: Pittsburgh Regional Transit proposed a compromise to preserve service on the Mount Royal Boulevard corridor after public outcry.

read more

Pittsburgh Regional Transit, which this spring proposed eliminating the Route 2 and P13 flyer along Mount Royal Boulevard in Shaler citing low ridership, now offers a compromise to keep buses running on the North Hills corridor after community leaders and riders objected.

Sources: KDKA · ↑ top

FDA Keeps Focus on Taylor Farms Lettuce

Latest developments: The FDA said a Taylor Farms sample that tested positive for cyclospora was a false positive, then said Monday its investigation still converges on the company's shredded iceberg lettuce from central Mexico.

read more

The multistate cyclosporiasis outbreak, which has sickened 11 people in Allegheny County, still points to shredded iceberg lettuce from Taylor Farms locations in central Mexico, the Food and Drug Administration said, and the company's recall remains in place.

Sources: KDKA · Pittsburgh Post-Gazette · ↑ top

Lyme Disease Cases Climb in Western Pennsylvania

Latest developments: Cases are rising for a second straight year across western Pennsylvania, with Allegheny and Westmoreland counties among the hardest hit.

read more

Lyme disease and other tick-borne illnesses are increasing for a second consecutive year across western Pennsylvania, one of the country's most affected regions, according to Dr. Graham Snyder, UPMC's medical director of infection protection and hospital epidemiology.

Sources: KDKA · ↑ top

Sports

Pirates (52-48)

Sun Jul 19 · Pirates 7 · Guardians 1 · Final

Skenes strikes out 8 in 7 innings as Pirates roll to 7-1 win over Guardians

Mon Jul 20 · Pirates 5 · Yankees 8 · End 5th (in progress at last update)

Up Next · Pirates @ Yankees · Tue Jul 21, 7:05 PM

Around the Teams

Bednar Returns to Face the Pirates

Latest developments: The Post-Gazette caught up with former Pirates closer David Bednar, now with the New York Yankees, ahead of the Pirates-Yankees series.

read more

David Bednar, the Mars, Pennsylvania, native and former Pirates All-Star closer whom Don Kelly's club traded to the New York Yankees, told the Post-Gazette he is grateful for his time in Pittsburgh, IC Light and all, as he prepares to pitch against his old team.

Sources: Post-Gazette Pirates · ↑ top

Prospect Murf Gray Reaches Altoona

Latest developments: The Post-Gazette's MiLB Monday reported infielder Murf Gray, now a top-100 prospect, has been promoted to Double-A Altoona.

read more

Pirates prospect Murf Gray, who has climbed into baseball's top-100 rankings, has arrived with the Double-A Altoona Curve, the Post-Gazette noted in its minor-league roundup tracking the farm system's rising names.

Sources: Post-Gazette Pirates · ↑ top

Reading

Markets

weekly average, change vs prior week

S&P 500     7,510.15  ▼ -0.2%
Dow        52,341.11  ▼ -0.5%
Nasdaq     25,857.30  ▼ -0.6%
WTI crude      79.70  ▲ +11.9%
EUR/USD       1.1430  ▲ +0.1%
GBP/USD       1.3442  ▲ +0.4%
USD/JPY       162.32  = +0.0%