================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Friday, July 24, 2026 - 12:07 PM EDT ================================================================ Autonomous AI agents crossed into the vulnerability pipeline this week, mining Redis and NodeBB for fresh zero-days, as a public Certighost exploit handed any low-privileged user the keys to Active Directory. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Autonomous coding agents jumped straight into the vulnerability pipeline, with Kimi K3 bots building working Redis remote-code-execution exploits and surfacing fresh NodeBB zero-days. see: AI Agents Mine Redis and NodeBB for Zero-Days * [TREND] Fresh privilege-escalation exploits target identity systems, with Certighost impersonating domain controllers to steal krbtgt and a default Azure Automation setting enabling cross-tenant takeover. see: Certighost Exploit Impersonates Domain Controllers; Default Azure Automation Setting Enabled Cross-Tenant Takeover * [TREND] Extortion crews lean on pure data theft, as Clop mines PTC Windchill and FlexPLM instances while Origin Energy confirms a breach exposing 2 million customers. see: Clop Extorts PTC Windchill and FlexPLM Users; Origin Energy Breach Exposes 2 Million Customers * [UPDATE (new)] Russia-aligned UAC-0099 dressed malware as a familiar Notepad++ plugin, bundling the genuine editor with LunchPoke to establish persistence and deliver MATCHBOIL on Ukrainian targets. see: UAC-0099 Hides Malware in a Fake Notepad++ Plugin * [TREND] Trump escalates on two fronts as the Iran war enters a fifth month of nightly airstrikes and new 10% tariffs now cover 99% of imports. see: Iran War Enters Fifth Month as Trump Weighs Escalation; Trump's New Tariffs Now Cover 99% of U.S. Imports * [TREND] Locally, Steelers camp opens under Mike McCarthy amid a Will Howard quarterback battle while GoatFest, DanceAfrica, and OpenStreetsPGH fill the weekend. see: Five Storylines for Steelers Training Camp; Weekend in Pittsburgh: GoatFest, DanceAfrica, OpenStreetsPGH SECURITY ---------------------------------------------------------------- 1. AI AGENTS MINE REDIS AND NODEBB FOR ZERO-DAYS AI Security · [ai, zero-day, patch] Latest developments: Redis shipped seven security releases July 23 after Kimi K3 agents found memory-corruption zero-days and built authenticated remote-code-execution exploits spanning stock Redis 6.2.22 through 8.8.0, while Aikido Security's AI pentest agents surfaced eight high-severity NodeBB flaws in a six-hour code review and Google previewed CodeMender, an agent that confirms exploitable bugs and writes the patch. Autonomous agents now scan source code, prove exploitability, and in Google's case propose fixes, compressing the disclosure cycle; Redis operators should move to 6.2.23, 7.2.15, or 7.4.10, and NodeBB administrators to 4.14.2. - The Hacker News: https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html - The Hacker News: https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html - Help Net Security: https://www.helpnetsecurity.com/2026/07/24/google-codemender-ai-agent-code-security/ 2. CLOP EXTORTS PTC WINDCHILL AND FLEXPLM USERS Ransomware and Cybercrime · [ransomware, extortion, breach] Latest developments: The Clop gang launched a data-theft extortion campaign against Internet-exposed PTC Windchill and FlexPLM product-lifecycle-management instances, the same week Black Kite counted 61 new ransomware groups entering the market between April 2025 and March 2026. Clop, which built its name on mass data theft through enterprise file-transfer and PLM software, steals data and threatens to leak it rather than encrypt; organizations running PTC Windchill or FlexPLM should pull the systems off the public Internet and patch. - BleepingComputer: https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/ - Help Net Security: https://www.helpnetsecurity.com/2026/07/24/ransomware-attack-trends-2026-report/ 3. ORIGIN ENERGY BREACH EXPOSES 2 MILLION CUSTOMERS Data Breaches · [breach, data-leak] Latest developments: Origin Energy confirmed that an intruder accessed and then leaked customer data online, and the hacker claims to hold personal information on 2 million Origin customers with a threat to publish the rest. Origin Energy, one of Australia's largest electricity and gas retailers, exposed customer personally identifiable information; affected customers should watch for fraud and phishing tied to their account details. - SecurityWeek: https://www.securityweek.com/data-breach-confirmed-after-australian-energy-giant-origin-is-hacked/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/ 4. UAC-0099 HIDES MALWARE IN A FAKE NOTEPAD++ PLUGIN Nation-State Activity · [apt, malware] Latest developments: Ukraine's CERT-UA warned that the Russia-aligned UAC-0099 cluster now ships an archive bundling the genuine Notepad++ editor with LunchPoke, a malicious utility disguised as a plugin that establishes persistence and delivers the MATCHBOIL.V2 backdoor. UAC-0099, a group that previously weaponized WinRAR flaws against Ukrainian targets, uses trusted software as cover; defenders should flag Notepad++ archives from untrusted sources and hunt for LunchPoke persistence. - The Hacker News: https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/ 5. CERTIGHOST EXPLOIT IMPERSONATES DOMAIN CONTROLLERS Vulnerabilities and Exploits · [vulnerability, exploit, active-directory] Latest developments: Researchers H0j3n and Aniq Fakhrul published a working July 24 exploit that lets a low-privileged Active Directory user request a certificate for a Domain Controller, authenticate as that machine, and run DCSync to pull the krbtgt secret. Certighost turns an ordinary domain account into full domain compromise because Domain Controller accounts carry directory replication rights; administrators running Active Directory Certificate Services should restrict enrollment and audit certificate templates immediately. - The Hacker News: https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html 6. DEFAULT AZURE AUTOMATION SETTING ENABLED CROSS-TENANT TAKEOVER Vulnerabilities and Exploits · [cloud, vulnerability, patch] Latest developments: Dark Reading detailed a public-by-default configuration and a chain of code flaws in Microsoft Azure Automation that let an attacker seize another tenant's identity and reach that tenant's data, credentials, and cloud workloads, which Microsoft has since fixed. Azure Automation, the service enterprises use to run scheduled scripts and manage cloud resources, shipped with a setting that exposed accounts across tenant boundaries; Microsoft closed the hole, and customers should review Automation account permissions. - Dark Reading: https://www.darkreading.com/cloud-security/default-azure-automation-setting-cross-tenant-identity-takeover BUSINESS AND POLITICS ---------------------------------------------------------------- * Iran War Enters Fifth Month as Trump Weighs Escalation Latest developments: Trump said Thursday he may intensify operations as U.S. airstrikes reached their 13th straight night, and a senior administration official described him as skeptical of diplomacy and in "revenge mode" against Tehran. The U.S.-Iran war has ground into its fifth month with no end in sight, frustrating President Trump, who once expected a conflict of weeks; the fighting keeps oil markets and the Strait of Hormuz on edge as drones strike near American forces in the region. - WSJ Politics: https://www.wsj.com/politics/policy/trump-is-losing-patience-over-an-iran-war-with-no-clear-end-in-sight-c411d3cd * Trump's New Tariffs Now Cover 99% of U.S. Imports Latest developments: The new 10% duties on 60 trading partners took effect, now covering roughly 99% of U.S. imports while exempting oil, gas, and fertilizer, after the Supreme Court struck down Trump's earlier blanket levies. President Trump reimposed double-digit tariffs on 60 countries, pinning them to a forced-labor enforcement rationale to survive legal challenges; the Financial Times reports the move shifts his trade war from shakedown to lock-in, sparing Europe while hitting Brazil hard. - FT World: https://www.ft.com/content/078269b4-5518-4289-b90a-dd722fd7e703?syn-25a6b1a6=1 - FT World: https://www.ft.com/content/38341bcb-0c45-432a-bd04-fa0b9f2b790a PITTSBURGH ---------------------------------------------------------------- Weather: This Afternoon: Mostly Cloudy, high 83F. Tonight: Mostly Cloudy then Slight Chance Rain Showers, low 64F. Saturday: Slight Chance Rain Showers then Slight Chance Showers And Thunderstorms, high 84F. Business: * Richard King Mellon Foundation Tops $1 Billion in Grants Early Latest developments: Pittsburgh's largest foundation announced it has surpassed its plan to award more than $1 billion in grants and program-related investments three years ahead of schedule. The Richard King Mellon Foundation, the region's biggest philanthropy, blew past the $1 billion giving target set in its multiyear strategic plan, WPXI reported. - WPXI: https://www.wpxi.com/news/local/pittsburghs-largest-foundation-tops-1-billion-giving-goal-3-years-early/VS6FXPQVANFSVCYNB4MJ42AJNA/ * Aurora Puts Driverless Trucks Back on Sun Belt Roads Latest developments: Aurora Innovation rolled out second-generation hardware that removes the safety observer from the cab, returning fully driverless trucks to roads across the Sun Belt. Aurora Innovation, the Pittsburgh-based autonomous-trucking company, debuted upgraded self-driving hardware and resumed running trucks with no human aboard, WPXI reported. - WPXI: https://www.wpxi.com/news/local/aurora-innovation-takes-observers-out-drivers-seat-with-second-generation-hardware/ZUMK6DMTNNH6FFBMHSTZKAGNAI/ Around town: * FDA Chases a New Cyclospora Outbreak Latest developments: The FDA disclosed a separate cyclospora outbreak from an as-yet-unidentified product and launched a traceback, as North Carolina investigators probe cilantro and parsley. Days after federal officials tied an earlier cyclosporiasis outbreak to central-Mexico iceberg lettuce, the U.S. Food and Drug Administration said Thursday it is hunting a new outbreak whose source it has not pinned down, KDKA reported. - KDKA: https://www.cbsnews.com/pittsburgh/news/fda-new-cyclospora-outbreak-source-unspecified/ * Connellsville's Madison Wiltrout Wins First U.S. Javelin Title Latest developments: Madison Wiltrout, a Connellsville High School graduate, captured her first U.S. javelin championship. Madison Wiltrout, who grew up in Connellsville, Fayette County, won the women's javelin at the U.S. track and field championships, advancing her Olympic ambitions, the Post-Gazette reported. - Pittsburgh Post-Gazette: https://www.post-gazette.com/sports/hsother/2026/07/24/madison-wiltrout-connellsville-javelin-thrower-olympics/stories/202607230064 Events: * Disability Independence Day at The Andy Warhol Museum Latest developments: The Warhol will hold a free ADA-anniversary celebration this Sunday, July 26. The Andy Warhol Museum on the North Shore hosts a free National Disability Independence Day celebration Sunday, July 26, from 10:30 a.m. to 3 p.m., marking the 36th anniversary of the Americans with Disabilities Act, with hands-on art-making open to everyone. - Pittsburgh Magazine: https://www.pittsburghmagazine.com/warhol-disability-independence-day/ * Weekend in Pittsburgh: GoatFest, DanceAfrica, OpenStreetsPGH Latest developments: This weekend, July 24 through 26, brings GoatFest, the DanceAfrica celebration, and OpenStreetsPGH. NEXTpittsburgh's weekend guide for July 23-26 spotlights GoatFest, the DanceAfrica dance celebration, and OpenStreetsPGH, which opens city streets to walkers and cyclists. - NEXTpittsburgh Events: https://nextpittsburgh.com/events/13-things-to-do-this-weekend-july-23-26/ SPORTS ---------------------------------------------------------------- Pirates (53-50) Up Next · Cubs @ Pirates · Fri Jul 24, 6:40 PM https://plaintextsports.com/mlb/2026-07-24/chc-pit Around the Teams: * Five Storylines for Steelers Training Camp Latest developments: The Post-Gazette laid out its camp storylines: Mike McCarthy's first camp as head coach and an open quarterback competition featuring Will Howard and Drew Allar. Steelers training camp opens next week under new head coach Mike McCarthy, who inherits a quarterback battle involving Will Howard and Drew Allar and a defense in transition, the Post-Gazette wrote. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/24/nfl-training-camp-mccarthy-joey-porter-will-howard-drew-allar/stories/202607230005 * Joey Porter Jr. Angles for a Big Payday Latest developments: A Post-Gazette camp countdown framed Joey Porter Jr.'s push for a top-of-market extension and elite-cornerback status as a defining Steelers subplot. Steelers cornerback Joey Porter Jr. is chasing a lucrative extension and aiming to cement himself among the NFL's best corners as his contract talks drag on, the Post-Gazette reported. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/24/nfl-trainingcamp-joey-porter-contract-cornerback-market/stories/202607230004 Team USA: * Beatriz Hatz Wins Para Long Jump National Title Latest developments: Beatriz Hatz, the "Love Island" Season 8 alum, won the T64 long jump national title at the USATF championships. Beatriz Hatz, a U.S. Paralympic long jumper who appeared on "Love Island," captured the T64 long jump crown at the USA Track and Field national championships, ESPN reported. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49436263/beatriz-hatz-love-island-national-championship READING ---------------------------------------------------------------- * Ed Zitron -- The Subprime Data Center Crisis Zitron argues that the AI boom's data-center buildout rests on increasingly shaky financing, drawing a direct parallel to the subprime mortgage crisis. https://www.wheresyoured.at/the-subprime-data-center-crisis/ * Stratechery -- OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips Ben Thompson dissects how OpenAI accidentally "hacked" Hugging Face and argues the episode's lessons about AI alignment are more reassuring than most people realize. https://stratechery.com/2026/openai-hacks-hugging-face-what-happened-alignment-and-paper-clips/ * Cal Newport -- Why Reading Matters Newport answers a splashy Atlantic essay declaring the end of reading, making the case for why sustained deep reading still matters. https://calnewport.com/why-reading-matters/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,463.49 ▼ -1.1% Dow 52,028.11 ▼ -1.0% Nasdaq 25,538.82 ▼ -2.1% WTI crude 85.93 ▲ +10.9% EUR/USD 1.1421 = -0.0% GBP/USD 1.3422 = +0.0% USD/JPY 162.73 ▲ +0.3% ================================================================ Generated 2026-07-24 12:07 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================