================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Friday, July 24, 2026 - 6:06 AM EDT ================================================================ Autonomous AI agents found and exploited zero-days in Redis and NodeBB within hours, and Google answered with CodeMender, an agent that writes patches for the flaws it finds. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Autonomous coding agents like Moonshot's Kimi K3 are surfacing exploitable zero-days, forcing Redis to ship seven emergency releases with published RCE proof-of-concepts against stock builds. see: AI Agents Uncover Redis and NodeBB Zero-Days * [TREND] Russia-aligned crews keep hiding malware in trusted software, with UAC-0099 disguising its MATCHBOIL loader as a Notepad++ plugin while Laundry Bear steals full Zimbra mailboxes. see: UAC-0099 Hides MATCHBOIL.V2 in a Fake Notepad++ Plugin; Laundry Bear Zimbra Espionage Reveals Full Mailbox Theft * [TREND] Data-theft extortion is widening as Clop hunts Internet-exposed PTC Windchill and FlexPLM servers while a lone hacker threatens to dump two million Origin Energy records. see: Clop Extorts PTC Windchill and FlexPLM Users; Origin Energy Breach Exposes Australian Customers * [TREND] Middle East tensions spiked as the Houthis fired on Saudi oil tankers and Trump threatened Iran, helping push Brent crude above $100 and triggering a global bond selloff. see: Houthis Hit Saudi Tankers; Trump Threatens Iran; Oil Tops $100, Driving a Global Bond Selloff * [UPDATE (new)] A newly disclosed nine-year-old XFS race condition, RefluXFS tracked as CVE-2026-64600, lets local Linux attackers overwrite protected files and escalate to root. see: RefluXFS Grants Root Through Linux XFS Race Condition SECURITY ---------------------------------------------------------------- 1. AI AGENTS UNCOVER REDIS AND NODEBB ZERO-DAYS AI Security · [ai, zero-day, patch] Latest developments: Redis shipped seven security releases on July 23 after researchers drove Moonshot's Kimi K3 agents to find memory-corruption flaws and publish authenticated RCE proof-of-concepts against stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0, while Aikido Security's AI pentest agents found eight high-severity flaws in NodeBB during a six-hour source review and Google previewed CodeMender, an agent that confirms exploitability and writes fixes. AI systems now discover and weaponize software flaws at machine speed, forcing vendors like Redis and NodeBB to patch and prompting defenders such as Google to automate remediation; administrators should move to Redis 6.2.23, 7.2.15, or 7.4.10 and NodeBB 4.14.2. - The Hacker News: https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html - The Hacker News: https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html - Help Net Security: https://www.helpnetsecurity.com/2026/07/24/google-codemender-ai-agent-code-security/ - SecurityWeek: https://www.securityweek.com/is-patching-dead-vulnerability-management-in-the-post-mythos-era/ 2. ORIGIN ENERGY BREACH EXPOSES AUSTRALIAN CUSTOMERS Data Breaches · [breach, extortion] Latest developments: Origin Energy confirmed that an unauthorized party accessed and leaked customer data online, as a hacker claimed to hold the personal information of 2 million Origin customers and threatened to publish it. Origin Energy, one of Australia's largest energy suppliers, disclosed a breach exposing customer personally identifiable information and is still counting how many Australians the theft touched; affected customers should watch for fraud and phishing. - SecurityWeek: https://www.securityweek.com/data-breach-confirmed-after-australian-energy-giant-origin-is-hacked/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/ - The Record: https://therecord.media/australia-origin-energy-data-breach 3. UAC-0099 HIDES MATCHBOIL.V2 IN A FAKE NOTEPAD++ PLUGIN Nation-State Activity · [apt, malware] Latest developments: Ukraine's CERT-UA warned that the Russia-aligned cluster UAC-0099 now ships an archive bundling the legitimate Notepad++ application with a malicious utility called LunchPoke, disguised as a plugin, to establish persistence and deliver the MATCHBOIL.V2 payload on Windows systems. UAC-0099, a Russia-aligned group that previously weaponized WinRAR flaws against Ukrainian targets, hides its malware inside a trusted editor's plugin directory; defenders should scrutinize unexpected Notepad++ archives and plugin utilities. - The Hacker News: https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/ 4. CLOP EXTORTS PTC WINDCHILL AND FLEXPLM USERS Ransomware and Cybercrime · [ransomware, breach, extortion] Latest developments: BleepingComputer reported the Clop ransomware gang, also tracked as Cl0p, is hunting Internet-exposed PTC Windchill and FlexPLM product-lifecycle-management instances in a new data-theft extortion campaign. Clop, the crew known for mass-exploiting managed file-transfer and enterprise software, now steals data from exposed PTC Windchill and FlexPLM servers and threatens to leak it; organizations running those systems should restrict Internet exposure and hunt for intrusion. - BleepingComputer: https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/ 5. LAUNDRY BEAR ZIMBRA ESPIONAGE REVEALS FULL MAILBOX THEFT Nation-State Activity · [apt, zero-day, espionage] Latest developments: BleepingComputer tied the Russian state-sponsored group Laundry Bear to the alias Void Blizzard, and The Hacker News detailed the Zimbra webmail payload harvesting each victim's last 90 days of email, the full organizational directory, the browser-saved password, and the two-factor recovery codes, with Unit 42 mapping the JavaScript injection behind the credential theft. Laundry Bear, a Kremlin-backed espionage group, has read Western government and commercial mailboxes since July 2025 through a zero-click Zimbra Collaboration Suite flaw that a victim triggers merely by previewing a message; the NSA, CISA, and partner agencies urge patching in advisory AA26-204A. - CISA Advisories: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a - The Hacker News: https://thehackernews.com/2026/07/russian-espionage-group-exploited.html - Unit 42 (Palo Alto): https://unit42.paloaltonetworks.com/russian-webmail-espionage/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/ 6. REFLUXFS GRANTS ROOT THROUGH LINUX XFS RACE CONDITION Vulnerabilities and Exploits · [patch, privilege-escalation] Latest developments: BleepingComputer detailed RefluXFS, tracked as CVE-2026-64600, a nine-year-old race condition in the Linux kernel's XFS filesystem that lets a local attacker overwrite protected files and escalate to root. The long-dormant XFS flaw affects Linux systems using the widely deployed filesystem and hands local users full root control; administrators should apply kernel updates as distributions ship fixes. - BleepingComputer: https://www.bleepingcomputer.com/news/linux/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/ BUSINESS AND POLITICS ---------------------------------------------------------------- * Oil Tops $100, Driving a Global Bond Selloff Latest developments: Brent crude settled above $100 a barrel Thursday, heading for a weekly gain of more than 12% and pushing Treasury yields to the highest levels of President Trump's second term. Red Sea attacks by Yemen's Houthis on oil shipping have spurred a surge in Brent crude that lifted the 2-year and 10-year Treasury yields, dragged equities lower, and stoked bets the Federal Reserve will raise rates—a squeeze that tightens financial conditions worldwide and threatens Republican midterm hopes. - WSJ Markets: https://www.wsj.com/business/energy-oil/oil-prices-roar-back-threatening-economy-and-gops-midterm-hopes-73df238a?mod=rss_markets_main - FT Markets: https://www.ft.com/content/f483fa0d-d368-433c-a5b0-40d820766c1a?syn-25a6b1a6=1 * Houthis Hit Saudi Tankers; Trump Threatens Iran Latest developments: The Houthis fired on two Saudi oil tankers in the Red Sea, and Trump vowed 'major military punishment,' saying he will hold Iran responsible for future Houthi attacks. Yemen's Houthi militants have opened a new front in the U.S.-Iran war by threatening Red Sea oil shipments through one of the world's most vital waterways, and with the conflict in its fifth month Trump has grown skeptical of diplomacy and, per a senior administration official, entered 'revenge mode' against Tehran. - WSJ World News: https://www.wsj.com/world/middle-east/trump-says-iran-will-held-responsible-for-future-houthi-attacks-0bc23ec0 - WSJ World News: https://www.wsj.com/world/middle-east/the-houthis-have-opened-a-new-front-in-the-u-s-iran-war-37afcf41 PITTSBURGH ---------------------------------------------------------------- Weather: Today: Partly Sunny, high 83F. Tonight: Mostly Cloudy then Slight Chance Rain Showers, low 64F. Saturday: Slight Chance Rain Showers then Slight Chance Showers And Thunderstorms, high 84F. Business: * Pennsylvania ACA Insurers Seek 17.1% Rate Hike Latest developments: Health insurers on Pennsylvania's Affordable Care Act marketplace have requested 2027 premium increases averaging 17.1%, the Post-Gazette reported July 24. The proposed increases, filed with Pennsylvania's insurance department for individual-market plans, would raise premiums for marketplace enrollees across the commonwealth heading into 2027. - Pittsburgh Post-Gazette: https://www.post-gazette.com/business/healthcare-business/2026/07/24/affordacale-care-act-rates-pennsylvania/stories/202607230052 * Badamo's to Open Dormont Sandwich Shop and Market Latest developments: Badamo's will expand with a sandwich shop and market in Dormont, the Post-Gazette reported July 24. Badamo's plans a new sandwich shop and market in the South Hills borough of Dormont, extending the brand into a fresh retail format beyond its existing operations. - Pittsburgh Post-Gazette: https://www.post-gazette.com/life/dining/2026/07/24/badamos-sandwich-shop-dormont/stories/202607230045 * Cyclospora Scare Sends Shoppers to Farmers Markets Latest developments: The cyclosporiasis outbreak tied to Taylor Farms lettuce has driven Pittsburgh-area shoppers toward local produce, farmers markets told KDKA July 24. After the Allegheny County Health Department reported 11 county residents sickened by cyclospora linked to Taylor Farms iceberg lettuce, shoppers such as Jim Goliwas have turned to farmers markets like the one in the borough of Green Tree for locally grown produce. - KDKA: https://www.cbsnews.com/pittsburgh/news/cyclosporiasis-outbreak-buying-local-farmers-markets/ Around town: * Pennsylvania Eases School Lead-Reporting Standard Latest developments: The state budget quietly relaxed the standard for lead reporting in Pennsylvania schools, and the Post-Gazette reported July 24 that the law's problems run deeper still. A provision in the new state budget loosened the threshold at which Pennsylvania schools must report lead in drinking water, a change the Post-Gazette found compounds longstanding weaknesses in the commonwealth's school lead-testing law. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/education/2026/07/24/pennsylvania-lead-testing/stories/202607240020 * Ambulance Bills Escape Federal Surprise-Billing Ban Latest developments: PublicSource reported July 24 that Washington's crackdown on surprise medical bills left out ground ambulances, exposing Southwestern Pennsylvania patients to large out-of-network charges. When Congress barred most surprise medical bills, it exempted ground ambulance rides, so a Southwestern Pennsylvania patient can still face a bill topping $400 for an unplanned trip, a gap that hits rural residents hardest. - PublicSource: https://www.publicsource.org/big-ambulance-bills-leave-rural-patients-at-risk/ Events: * This Weekend: GoatFest, DanceAfrica, and OpenStreetsPGH Latest developments: Pittsburgh's weekend of July 24-26 brings GoatFest, DanceAfrica, and OpenStreetsPGH, NEXTpittsburgh's guide reported July 23. NEXTpittsburgh's guide lists more than a dozen things to do across Pittsburgh the weekend of July 24-26, among them GoatFest, the DanceAfrica celebration, and OpenStreetsPGH, which opens city streets to walkers and cyclists. - NEXTpittsburgh Events: https://nextpittsburgh.com/events/13-things-to-do-this-weekend-july-23-26/ * Jake Owen to Play Rivers Casino Next Month Latest developments: Country singer Jake Owen will perform at Rivers Casino in Pittsburgh next month, TribLive reported July 24 as Owen discussed his new album. Jake Owen, the country musician, has a show set for next month at Rivers Casino on Pittsburgh's North Shore, tied to promotion of his new album. - TribLive: https://triblive.com/aande/music/country-music-singer-jake-owen-talks-new-album-aaron-rodgers-and-more/ SPORTS ---------------------------------------------------------------- Pirates (53-50) Up Next · Cubs @ Pirates · Fri Jul 24, 6:40 PM https://plaintextsports.com/mlb/2026-07-24/chc-pit Around the Teams: * Camp Countdown: Porter Jr. Eyes a Big Payday Latest developments: The Post-Gazette's training-camp countdown, July 24, framed cornerback Joey Porter Jr. as chasing both a lucrative contract and elite status. Porter Jr., the Steelers cornerback whose contract talks have stalled, aims to prove he belongs among the NFL's top corners and command a payday matching the position's rising market as training camp opens. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/24/nfl-trainingcamp-joey-porter-contract-cornerback-market/stories/202607230004 * Roethlisberger Previews Camp on 'Footbahlin' Latest developments: On 'Footbahlin' Episode 133, July 21, Ben Roethlisberger laid out what to watch when Steelers training camp opens and what makes a franchise quarterback. Roethlisberger, the retired Steelers quarterback, used his 'Footbahlin' podcast to preview the real competitions and first hints of the team's new era once practices begin, roughly a week out from camp. - Ben Roethlisberger / Channel Seven (YouTube): https://www.youtube.com/watch?v=Z1YJqSjWA74 * Camp Countdown: Heyward Still an Elite Force Latest developments: The Post-Gazette's training-camp countdown, July 22, argued defensive tackle Cam Heyward keeps defying his age to play at an elite level. Heyward, the veteran Steelers defensive lineman and captain, continues to perform like a top interior defender, the Post-Gazette wrote, casting him as a Hall-of-Fame-caliber anchor of the defense. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/22/nfl-training-camp-news-cam-heyward-halloffame/stories/202607220001 Team USA: * Norway Weighs FIFA Complaint Over Balogun Ruling Latest developments: Norway's football federation president said she will ask the board to file a FIFA ethics complaint at its next meeting, likely August 6, over Trump's role in lifting U.S. striker Folarin Balogun's World Cup ban. President Trump called FIFA's Gianni Infantino to seek review of a mandatory one-game ban on United States forward Folarin Balogun, and Norway's federation, warning FIFA is on a 'slippery slope,' now moves toward a formal ethics complaint. - Guardian World Cup 2026: https://www.theguardian.com/football/2026/jul/23/norway-fifa-ethics-complaint-trump-balogun-red-card - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49430499/norway-fa-chief-gianni-infantino-admit-folarin-balogun-error-donald-trump-complaint READING ---------------------------------------------------------------- * Ed Zitron -- The Subprime Data Center Crisis Zitron argues the AI data-center buildout rests on shaky, subprime-style financing that leaves the entire expansion dangerously exposed. https://www.wheresyoured.at/the-subprime-data-center-crisis/ * Stratechery -- OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips Ben Thompson recounts how OpenAI accidentally 'hacked' Hugging Face and argues the episode's lessons about AI alignment are more encouraging than alarmists suggest. https://stratechery.com/2026/openai-hacks-hugging-face-what-happened-alignment-and-paper-clips/ * Cal Newport -- Why Reading Matters Newport answers an Atlantic piece declaring 'The End of Reading,' making the case that sustained, deep reading still matters. https://calnewport.com/why-reading-matters/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,463.49 ▼ -1.1% Dow 52,028.11 ▼ -1.0% Nasdaq 25,538.82 ▼ -2.1% WTI crude 85.93 ▲ +10.9% EUR/USD 1.1421 = -0.0% GBP/USD 1.3422 = +0.0% USD/JPY 162.73 ▲ +0.3% ================================================================ Generated 2026-07-24 06:06 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================