================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Tuesday, July 21, 2026 - 12:06 PM EDT ================================================================ Attackers are weaponizing fresh disclosures within hours, driving active exploitation of critical SharePoint, ServiceNow, and WordPress flaws faster than defenders can patch. CONTENTS: Emerging Trends and Key Updates | Security | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Attackers are weaponizing enterprise flaws within days, exploiting SharePoint and ServiceNow bugs while CISA added WordPress, Langflow, and DD-WRT flaws to its KEV catalog. see: Enterprise RCE Flaws Exploited Within Days; CISA Adds WordPress, Langflow, and DD-WRT Flaws to KEV * [TREND] Attackers increasingly target the AI stack itself, as ENCFORGE ransomware encrypts model weights while FakeGit floods GitHub with thousands of repos posing as AI Skills and MCP servers. see: ENCFORGE Ransomware Targets AI Model Files; FakeGit Floods GitHub With 7,600 Malicious Repos * [TREND] Espionage crews keep hiding command channels in trusted services, with the CAV3RN module steering control through a compromised Outlook calendar over Microsoft Graph and falling back to DNS. see: Calendar-Abusing Espionage Malware CAV3RN and HollowGraph * [UPDATE (new)] Kenya opened an investigation after attackers hijacked President William Ruto's official website, replacing its homepage with a Bitcoin wallet and a threat to publish information. see: Kenyan President's Website Hacked for Bitcoin Ransom * [UPDATE (new)] Allegheny County secured nearly $90 million in state Redevelopment Assistance Capital Program awards spread across 60 local projects. see: Allegheny County Wins $90 Million in State Grants * [TREND] Fresh commentary keeps questioning the AI economy and media, as Zitron calls OpenAI an unsustainable bubble while Thompson reads Netflix earnings as solid but maturing. see: The OpenAI Bubble; Netflix Earnings, Is Netflix Washed?, Additional Notes SECURITY ---------------------------------------------------------------- 1. ENTERPRISE RCE FLAWS EXPLOITED WITHIN DAYS Vulnerabilities and Exploits · [rce, exploit, patch] Latest developments: watchTowr caught attackers exploiting SharePoint deserialization flaw CVE-2026-50522, the third July SharePoint bug to go live after a public proof-of-concept, and Defused Cyber spotted in-the-wild exploitation of ServiceNow AI Platform sandbox-escape CVE-2026-6875. Both flaws let an unauthenticated attacker run code over the network—CVE-2026-50522 rates 9.8 and CVE-2026-6875 rates 9.5. Microsoft patched SharePoint in its July Patch Tuesday and credited DEVCORE, and ServiceNow shipped its fix days before the attacks began. Patch both now. - The Hacker News: https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html - The Hacker News: https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html - SecurityWeek: https://www.securityweek.com/exploitation-of-servicenow-vulnerability-seen-days-after-disclosure/ - The Hacker News: https://thehackernews.com/2026/07/n-day-is-becoming-n-hour-patching.html 2. CISA ADDS WORDPRESS, LANGFLOW, AND DD-WRT FLAWS TO KEV Vulnerabilities and Exploits · [exploit, patch, rce] Latest developments: CISA added four actively exploited flaws to its Known Exploited Vulnerabilities catalog on July 21—WordPress core bugs CVE-2026-60137 and CVE-2026-63030 that together form the wp2shell chain, Langflow flaw CVE-2026-0770, and DD-WRT stack overflow CVE-2021-27137—as wp2shell scanning and successful compromises spread within three days of disclosure. wp2shell chains a WordPress-core SQL injection with an interpretation-conflict bug to reach unauthenticated remote code execution, and WordPress pushed 6.9.5 and 7.0.2 through auto-update. Federal agencies face a KEV patch deadline, and every site owner should update immediately. - CISA Advisories: https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog - The Hacker News: https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html - Dark Reading: https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover - SANS Internet Storm Center: https://isc.sans.edu/diary/rss/33168 3. ENCFORGE RANSOMWARE TARGETS AI MODEL FILES AI Security · [ransomware, ai] Latest developments: Sysdig tied a second attack on the same Langflow server to JadePuffer, the AI-agent-driven extortion operator, which now deploys ENCFORGE, a compiled Go ransomware that encrypts model weights, vector indexes, training datasets, and model checkpoints across the host. JadePuffer runs its extortion end-to-end through an autonomous AI agent, and the same extortion contact ties both campaigns; ENCFORGE is the first ransomware aimed squarely at AI and machine-learning infrastructure. The operators entered through a Langflow remote-code-execution flaw. - The Hacker News: https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware/ - Help Net Security: https://www.helpnetsecurity.com/2026/07/21/jadepuffer-encforge-ransomware/ 4. CALENDAR-ABUSING ESPIONAGE MALWARE CAV3RN AND HOLLOWGRAPH Nation-State Activity · [apt, espionage, malware] Latest developments: Kaspersky's GReAT team detailed a new Project CAV3RN module that drives command-and-control through a compromised Outlook calendar over Microsoft Graph and falls back to DNS AAAA responses to recover its configuration, while researchers separately traced HollowGraph turning a hijacked Microsoft 365 calendar into a two-way dead-drop. Both families bury their command traffic inside legitimate Microsoft cloud services to support long-term espionage, and investigators have linked the calendar-hijacking activity to Iranian operations. Hunt for anomalous Graph API and calendar activity on compromised mailboxes. - Securelist (Kaspersky): https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/ - SecurityWeek: https://www.securityweek.com/new-hollowgraph-malware-abuses-microsoft-365-calendar-for-cc-communication/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/ 5. FAKEGIT FLOODS GITHUB WITH 7,600 MALICIOUS REPOS Software Supply Chain · [supply-chain, malware, ai] Latest developments: Island uncovered FakeGit, roughly 7,600 malicious GitHub repositories—more than 800 posing as AI Skills or Model Context Protocol servers—tied to about 6,600 accounts and built to feed SmartLoader malware to developers and to the AI agents that recommend code. The repos copy real projects with lookalike developer profiles and convincing READMEs, ranging from Gmail and WhatsApp integrations to AI workflows, and deliver SmartLoader through malicious ZIP files; the wave peaked in April 2026. Verify a repository's provenance before cloning it or trusting an agent's suggestion. - Help Net Security: https://www.helpnetsecurity.com/2026/07/21/github-repos-malware-campaign-fakegit-ai-agents/ - The Hacker News: https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html 6. KENYAN PRESIDENT'S WEBSITE HACKED FOR BITCOIN RANSOM Ransomware and Cybercrime · [extortion, breach] Latest developments: Kenya opened an investigation after attackers hijacked President William Ruto's official website on Saturday, July 18, swapping its homepage for a cryptocurrency wallet address and a threat to publish unspecified information about Ruto unless he paid. The attackers left an extortion demand and a bitcoin wallet address, and no group has claimed the hack. Kenyan authorities are probing how the intruders reached the site. - The Record: https://therecord.media/kenya-probes-hack-of-presidents-website-after-ransom-demand PITTSBURGH ---------------------------------------------------------------- Weather: This Afternoon: Chance Showers And Thunderstorms, high 83F. Tonight: Chance Showers And Thunderstorms, low 65F. Wednesday: Slight Chance Rain Showers then Mostly Sunny, high 77F. Business: * Hey Babe Adds a Dining Room in East Liberty Latest developments: WPXI reported July 21 that Hey Babe is expanding with a 50-seat dining room. Hey Babe, the East Liberty cocktail lounge inside the Maverick Hotel run by married industry veterans Danielle Cain and Rob Hirst, who met working at Soba in Shadyside, is adding a 50-seat dining room. - WPXI: https://www.wpxi.com/news/local/east-liberty-cocktail-lounge-hey-babe-expands-with-50-seat-dining-room/544IZPYDU5C4BBUI2ECBWL2U4M/ * Trump Praises Giant Eagle Price Cuts Latest developments: President Trump publicly praised Giant Eagle on July 21 for cutting prices this summer. Giant Eagle, the O'Hara Township-based supermarket chain, drew praise from President Trump for lowering prices on many items this summer. - WTAE: https://www.wtae.com/article/president-trump-giant-eagle-grocery-prices/73194101 Around town: * Severe Storms Threaten the Pittsburgh Area Latest developments: The National Weather Service put all of the Pittsburgh area under an enhanced risk for severe storms Tuesday, July 21. Forecasters warned that strong to severe thunderstorms could bring damaging winds, hail, flash flooding, and isolated tornadoes across the Pittsburgh area, eastern Ohio, and the West Virginia panhandle between noon and 8 p.m. Tuesday, July 21, and Duquesne Light said it is staging crews for outages. - KDKA: https://www.cbsnews.com/pittsburgh/news/severe-weather-pittsburgh-area-hail-wind-tornado-threats/ - WPXI: https://www.wpxi.com/news/local/duquesne-light-preparing-more-severe-weather-across-pittsburgh-area-tuesday/EZD7SCNKJZAVBDCZC3XQJTCC7U/ * Allegheny County Wins $90 Million in State Grants Latest developments: WPXI reported July 21 that Allegheny County secured nearly $90 million in Redevelopment Assistance Capital Program awards for 60 projects. County Executive Sara Innamorato and the Shapiro administration landed nearly $90 million in state Redevelopment Assistance Capital Program grants spread across 60 projects in Allegheny County. - WPXI: https://www.wpxi.com/news/local/allegheny-county-secures-nearly-90m-funding-60-projects/RUGHCASRR5DP7N66XV67WZ7IFI/ * State Orders Review of Donegal-Area Mine Site Latest developments: TribLive reported July 21 that a state panel ordered the Department of Environmental Protection to study whether the proposed mine land is unsuitable for mining. The Pennsylvania Department of Environmental Protection must review a proposed mine site in Donegal and Mt. Pleasant townships in Westmoreland County to determine whether the land is suitable for mining. - TribLive: https://triblive.com/local/westmoreland/dep-ordered-to-review-site-of-proposed-donegal-area-mine/ Events: * Pittsburgh Caribbean Carnival Returns July 25 Latest developments: Pittsburgh Magazine previewed July 21 that the second-annual Pittsburgh Caribbean Carnival returns Saturday, July 25. The second annual Pittsburgh Caribbean Carnival runs Saturday, July 25, at Allegheny Commons Park West on the North Side, with Caribbean music, costumes, and cuisine; organizers say it will be bigger than last year's inaugural event. - Pittsburgh Magazine: https://www.pittsburghmagazine.com/things-to-do-this-weekend-in-pittsburgh/ SPORTS ---------------------------------------------------------------- Pirates (52-49) Mon Jul 20 · Pirates 5 · Yankees 8 · Final Jazz Chisholm Jr. homers twice and drives in 5 as Yankees sink Pirates 8-5 after benches clear https://plaintextsports.com/mlb/2026-07-20/pit-nyy Up Next · Pirates @ Yankees · Tue Jul 21, 7:05 PM https://plaintextsports.com/mlb/2026-07-21/pit-nyy Around the Teams: * Steelers Need a Leap From Nick Herbig Latest developments: The Post-Gazette's training-camp countdown argued July 21 the Steelers expect edge rusher Nick Herbig to become a front-line starter. Having committed roughly $100 million to outside linebacker Nick Herbig, the Steelers expect him to anchor the pass rush as a full-time starter in 2026, the Post-Gazette wrote as camp opens in Latrobe. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/21/trainingcamp-countdown-analysis-defense-herbig/stories/202607210001 * Hiles Says Keep Oneil Cruz for Now Latest developments: Post-Gazette columnist Noah Hiles argued July 20 the Pirates should hold onto shortstop Oneil Cruz through the trade deadline. With the July trade deadline nearing and reports that the Pirates could listen to offers, columnist Noah Hiles wrote that Pittsburgh should keep Oneil Cruz rather than sell at his current value. - Post-Gazette Pirates: https://www.post-gazette.com/sports/columns/2026/07/20/noah-hiles-weekend-pirates-oneil-cruz-don-kelly/stories/202607200010 Team USA: * McNulty Confronted by Motorist at Tour de France Latest developments: ESPN reported July 21 that an angry motorist confronted American cyclist Brandon McNulty before Tuesday's time trial. A motorist confronted United States rider Brandon McNulty before the individual time trial at the Tour de France on Tuesday, July 21, and McNulty was unhurt. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49417518/brandon-mcnulty-unhurt-pre-trial-driver-confrontation * Trial Date Set for Olympian David Hearn Latest developments: ESPN reported July 20 that a Washington judge set a September 28 trial date for former Olympic canoe racer David Hearn. A judge in Washington set a September 28 trial for former United States Olympic canoe racer David Hearn, charged with deliberately damaging the Lincoln Memorial Reflecting Pool. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49410663/sept-28-trial-date-set-david-hearn-reflecting-pool-case READING ---------------------------------------------------------------- * Stratechery -- Netflix Earnings, Is Netflix Washed?, Additional Notes Ben Thompson reads Netflix's latest earnings as solid but unexciting, marking the streamer as a mature company whose fastest-growing days are behind it. https://stratechery.com/2026/netflix-earnings-is-netflix-washed-additional-notes/ * Ed Zitron -- The OpenAI Bubble Zitron argues OpenAI sits at the center of an unsustainable financial bubble propped up by circular investment and revenue that cannot justify its valuation. https://www.wheresyoured.at/the-openai-bubble/ * Cal Newport -- Why Reading Matters Newport responds to an Atlantic article on collapsing reading habits, arguing that sustained deep reading remains essential to serious thinking. https://calnewport.com/why-reading-matters/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,510.15 ▼ -0.2% Dow 52,341.11 ▼ -0.5% Nasdaq 25,857.30 ▼ -0.6% WTI crude 80.72 ▲ +10.4% EUR/USD 1.1430 ▲ +0.1% GBP/USD 1.3442 ▲ +0.4% USD/JPY 162.32 = +0.0% ================================================================ Generated 2026-07-21 12:06 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================