================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Friday, July 24, 2026 - 4:05 PM EDT ================================================================ A threat actor turned the open-source Hermes AI agent loose on Thailand's Ministry of Finance, the clearest sign yet that autonomous agents now run real intrusions with no human at the keyboard. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Attackers handed a whole intrusion to the autonomous Hermes agent aimed at Thailand's Ministry of Finance, running unattended while similar AI now drafts defenders' patches. see: Hermes AI Agent Automates Thai Finance Ministry Attack * [TREND] North Korea's BlueNoroff spoofs Zoom and Teams to profile crypto wallets while hackers hijack hotel Wi-Fi DNS to fake Microsoft 365 logins. see: BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets; Hotel Wi-Fi DNS Hijack Steals Microsoft 365 Logins * [UPDATE (new)] OnTrac, Chick-fil-A, and Origin Energy each disclosed consumer data exposures in a single day, with credential-stuffing compromising more than 13,000 accounts. see: OnTrac, Chick-fil-A, and Origin Breaches * [UPDATE (new)] XBOW's crafted SVG ran code as SYSTEM on Bing's image workers, while the Golden Chickens malware-as-a-service ecosystem resurfaced with four new families. see: Bing Images SVG Flaws Run Code as SYSTEM; Golden Chickens Malware-as-a-Service Resurfaces * [TREND] Gulf Arab warplanes from Bahrain and Kuwait bombed Iran while Trump threatened fresh EU tariffs over the bloc's fines on American tech firms. see: Gulf Arab States Strike Iran; Trump Threatens EU Tariffs Over Tech Fines SECURITY ---------------------------------------------------------------- 1. ONTRAC, CHICK-FIL-A, AND ORIGIN BREACHES Data Breaches · [breach, credential-stuffing] Latest developments: Parcel carrier OnTrac told customers hackers breached its corporate network and may have taken personal details, Chick-fil-A confirmed credential-stuffing attacks between June 17 and June 19 compromised more than 13,000 customer accounts, and a hacker claims to hold data on 2 million Origin Energy customers with a threat to leak it. Three consumer-facing firms in parcel delivery, fast food, and Australian energy exposed customer records through network intrusion and credential reuse. Affected customers should reset reused passwords and enable multifactor authentication. - BleepingComputer: https://www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/chick-fil-a-data-breach-affects-more-than-13-000-customers/ - SecurityWeek: https://www.securityweek.com/data-breach-confirmed-after-australian-energy-giant-origin-is-hacked/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/ 2. HERMES AI AGENT AUTOMATES THAI FINANCE MINISTRY ATTACK AI Security · [ai, breach] Latest developments: A threat actor installed the open-source Hermes AI agent on a rented server, switched off the setting that makes it ask permission before risky commands, and pointed it in unattended "YOLO" mode at Thailand's Ministry of Finance, where it checked hosts for root access, searched file systems, and ran post-exploitation on its own. The ministry runs Thailand's treasury and tax collection. The alleged breach marks a real attacker handing an autonomous agent free rein over a live intrusion; defenders should lock down outbound agent tooling and watch for unattended automation. - BleepingComputer: https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/ - The Hacker News: https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html 3. BING IMAGES SVG FLAWS RUN CODE AS SYSTEM Vulnerabilities and Exploits · [rce, patch] Latest developments: XBOW submitted a crafted SVG to Bing's image search that ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers and as root on the Linux machines in the same fleet, reproduced the result across different hosts and network ranges, and drew two critical Microsoft patches including CVE-2026-32194. The bug sat in Bing's image-processing tier rather than one bad machine, exposing Microsoft's own production servers to remote code execution through a single uploaded image. Microsoft has issued fixes. - The Hacker News: https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html 4. BLUENOROFF ZOOM PHISHING KIT PROFILES CRYPTO WALLETS Nation-State Activity · [apt, phishing, cryptocurrency] Latest developments: The Hacker News detailed an active BlueNoroff phishing kit that impersonates Zoom and Microsoft Teams through typosquatted domains, leans on compromised industry contacts for credibility, and profiles a victim's cryptocurrency wallets before it delivers malware. BlueNoroff is a North Korean state-backed group that runs ClickFix-style social engineering to rob crypto holders. Treat unexpected Zoom or Teams download prompts on lookalike domains as hostile. - The Hacker News: https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html 5. HOTEL WI-FI DNS HIJACK STEALS MICROSOFT 365 LOGINS Ransomware and Cybercrime · [phishing, credential-theft] Latest developments: Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect guests to fake Microsoft 365 login pages that harvest their usernames and passwords. The tampering happens on the venue's network gear, so a guest who joins the Wi-Fi and signs in lands on the attacker's page. Business travelers should use a corporate VPN and reject certificate warnings on login pages. - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/ 6. GOLDEN CHICKENS MALWARE-AS-A-SERVICE RESURFACES Ransomware and Cybercrime · [malware, maas] Latest developments: The operators behind the Golden Chickens malware-as-a-service ecosystem returned with four new families—TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and a modified web-browser credential stealer—showing no slowdown despite extensive public exposure of their tooling. Golden Chickens rents modular implants to other criminals for credential theft and follow-on intrusion. The refreshed lineup means detection signatures tied to older builds will miss the new ones. - The Hacker News: https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html BUSINESS AND POLITICS ---------------------------------------------------------------- * Gulf Arab States Strike Iran Latest developments: The Wall Street Journal reported that Bahraini and Kuwaiti warplanes bombed Iran earlier this month, the first direct Gulf Arab military action against Tehran in the war. Bahrain and Kuwait, longtime U.S. security partners, entered the American-Iranian war by striking Iranian targets, a reckoning that threatens to pull the Gulf monarchies deeper into a conflict now in its fifth month and to widen the risk to Red Sea and Persian Gulf shipping. - WSJ World News: https://www.wsj.com/world/middle-east/iran-gulf-states-bahrain-kuwait-strikes-009637db * Trump Threatens EU Tariffs Over Tech Fines Latest developments: President Trump said Washington will open a new investigation into European Union trade practices and threatened fresh tariffs in retaliation for the bloc's fines on American technology companies. Trump accused the European Union of unfairly penalizing U.S. tech giants and vowed retaliatory duties and a trade probe, escalating tensions a day after his new 10% and 12.5% tariffs on 60 trading partners took effect. - FT World: https://www.ft.com/content/9b819dfc-8248-4aa5-b670-3a14d05f252e?syn-25a6b1a6=1 PITTSBURGH ---------------------------------------------------------------- Weather: This Afternoon: Mostly Cloudy, high 83F. Tonight: Mostly Cloudy then Chance Rain Showers, low 65F. Saturday: Chance Rain Showers, high 84F. Business: * Original Pittsburgh Winery to Close Latest developments: The Post-Gazette reported that Original Pittsburgh Winery, in the Strip District, is shutting down. Original Pittsburgh Winery, a Strip District winery that doubled as a live-music room, is closing, ending a fixture that served both fine-wine drinkers and concertgoers. - Pittsburgh Post-Gazette: https://www.post-gazette.com/life/drinks/2026/07/24/original-pittsburgh-winery-closing-strip-district/stories/202607240058 * Pittsburgh Mills Roads to Be Repaved Latest developments: Namdar Realty reached a formal agreement with Frazer Township to repave the Galleria at Pittsburgh Mills roads, settling days before a trial set for next week. New York-based Namdar Realty Group, hit with hundreds of code-violation citations, millions of dollars in fines, and an Allegheny County criminal charge, agreed to repave the pothole-ridden roads at the Galleria at Pittsburgh Mills in Frazer Township. - KDKA: https://www.cbsnews.com/pittsburgh/news/pittsburgh-mills-paving-agreement-frazer-township/ Around town: * Union Rally Over Downtown TRID Plan Latest developments: Building-trades union workers rallied downtown after two longtime employees were laid off, pressing for amendments to the city's tax-increment redevelopment plan. Union members demonstrated in downtown Pittsburgh, arguing the Downtown revival financed through the Transit Revitalization Investment District plan should not come at the expense of good-paying jobs, following two layoffs. - WTAE: https://www.wtae.com/article/downtown-pittsburgh-union-layoffs-trid-plan-protest/73256472 * Pennsylvania Added to Cyclospora Outbreak Latest developments: The CDC added Pennsylvania to the list of states tied to the multistate cyclosporiasis outbreak. Federal health investigators linked Pennsylvania cases to a national cyclospora outbreak, part of a broader intestinal-parasite scare that earlier traced to central-Mexico lettuce and now includes a separate, unidentified product still under traceback. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/health/2026/07/24/cyclosporiasis-outbreak-pa/stories/202607240045 * County Commits $6M to Housing Latest developments: Allegheny County's economic development agency approved $6 million for two housing initiatives to preserve affordable units and help homeowners stay in their homes. Allegheny County's economic development authority set aside $6 million for programs officials say will keep affordable housing in service and fund repairs so residents can remain safely in their homes. - TribLive: https://triblive.com/local/allegheny-county-invests-6m-in-housing-initiatives/ SPORTS ---------------------------------------------------------------- Pirates (53-50) Up Next · Cubs @ Pirates · Fri Jul 24, 6:40 PM https://plaintextsports.com/mlb/2026-07-24/chc-pit Around the Teams: * Pirates Weigh Deadline Moves Latest developments: The Post-Gazette reported the Pirates are fielding interest in shortstop Oneil Cruz and hunting bullpen help as the MLB trade deadline nears. Pittsburgh general manager Ben Cherington faces pressure to add talent for a wild-card push, with the Post-Gazette detailing internal debate over dealing or keeping Oneil Cruz and reinforcing a thin bullpen. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/07/24/mlb-trade-rumors-oneil-cruz-bullpen-ben-cherington/stories/202607240042 * Steelers May Expand Herbig's Role Latest developments: A Post-Gazette video weighed whether the Steelers will play outside linebacker Nick Herbig more often alongside T.J. Watt and Alex Highsmith. The Post-Gazette examined how Pittsburgh could deploy Nick Herbig in three-edge looks with T.J. Watt and Alex Highsmith after committing roughly $100 million to him. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/24/nfl-training-camp-news-rumors-nick-herbig-tj-watt-alex-highsmith/stories/202607240049 * Roethlisberger Previews Camp on Footbahlin Latest developments: On his 'Footbahlin' podcast, Ben Roethlisberger broke down what to watch when Steelers camp opens and what makes a franchise quarterback. Ben Roethlisberger, in 'Footbahlin' episode 133, walked through the position battles and real competition to track once the Steelers hit the practice fields at Saint Vincent College, a week out, in Mike McCarthy's new era. - Ben Roethlisberger / Channel Seven (YouTube): https://www.youtube.com/watch?v=Z1YJqSjWA74 Team USA: * USWNT One Year From Women's World Cup Latest developments: With one year until the 2027 Women's World Cup final, ESPN laid out five reasons the U.S. women's national team will or will not reach it. ESPN assessed the U.S. women's national team's path to the 2027 Women's World Cup final, weighing its depth, form, and rivals as the tournament's one-year countdown began. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49435317/5-reasons-uswnt-in-women-world-cup-final-one-year * IOC Passes on Infantino-Trump Probe Latest developments: The International Olympic Committee said it will not investigate allegations that FIFA president Gianni Infantino breached political-neutrality rules in his dealings with President Trump. The IOC declined to examine claims that Infantino violated Olympic neutrality rules, fallout from Trump's intervention that cleared U.S. striker Folarin Balogun of a mandatory World Cup ban and prompted Norway to weigh a FIFA ethics complaint. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49440317/ioc-not-investigate-infantino-trump-interference-allegations READING ---------------------------------------------------------------- * Stratechery -- OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips Ben Thompson argues OpenAI's accidental 'hack' of Hugging Face is less alarming than the headlines suggest and draws from it reassuring lessons about AI alignment. https://stratechery.com/2026/openai-hacks-hugging-face-what-happened-alignment-and-paper-clips/ * Ed Zitron -- The Subprime Data Center Crisis Ed Zitron contends the debt-fueled buildout of AI data centers resembles a subprime bubble, with shaky financing propping up spending that the underlying business cannot sustain. https://www.wheresyoured.at/the-subprime-data-center-crisis/ * Cal Newport -- Why Reading Matters Cal Newport rebuts claims that deep reading is dying, arguing sustained reading builds cognitive capacities that skimming and AI summaries cannot replace. https://calnewport.com/why-reading-matters/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,463.49 ▼ -1.1% Dow 52,028.11 ▼ -1.0% Nasdaq 25,538.82 ▼ -2.1% WTI crude 85.93 ▲ +10.9% EUR/USD 1.1421 = -0.0% GBP/USD 1.3422 = +0.0% USD/JPY 162.73 ▲ +0.3% ================================================================ Generated 2026-07-24 16:05 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================