================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Saturday, July 25, 2026 - 12:08 PM EDT ================================================================ Attackers race to exploit an unpatched Fastjson flaw in Java applications while a threat actor turns the open-source Hermes agent loose on Thailand's finance ministry. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] A threat actor drove the open-source Hermes AI agent in unattended mode to automate post-exploitation of Thailand's Ministry of Finance, handing routine intrusion work to autonomous AI. see: Hermes AI Agent Automates Thai Finance Ministry Breach * [TREND] Attackers are outpacing defenders on server-side flaws, exploiting an unpatched Fastjson bug CVE-2026-16723 in Spring Boot apps and a fresh GitLab exploit weeks after the fix shipped. see: Unpatched Fastjson RCE CVE-2026-16723 Under Attack; GitLab RCE PoC Runs Commands as Git User * [TREND] Leaked records keep powering downstream crime, with ShinyHunters breach data now fueling $2,000 sextortion emails as OnTrac's fresh network intrusion widens the pool of exposed victims. see: ShinyHunters Breach Data Fuels $2,000 Sextortion; OnTrac Parcel Carrier Discloses Network Breach * [UPDATE (new)] A massive malvertising campaign serves counterfeit Solana, Luno, and TradingView pages whose JavaScript instructs the browser to assemble malware directly in memory. see: Malvertising Builds Malware in Browser Memory * [TREND] Commentators weigh AI's fallout, from OpenAI's accidental Hugging Face 'hack' and its alignment lessons to Zitron's warning that debt-fueled data center building echoes subprime lending. see: OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips; The Subprime Data Center Crisis SECURITY ---------------------------------------------------------------- 1. UNPATCHED FASTJSON RCE CVE-2026-16723 UNDER ATTACK Vulnerabilities and Exploits · [zero-day, rce, patch] Latest developments: ThreatBook and Imperva reported on July 25 that attackers are exploiting CVE-2026-16723 in the wild, and Alibaba has shipped no patch. Fastjson, Alibaba's JSON library for Java, carries a critical flaw that lets a malicious JSON request run code without authentication in affected Spring Boot applications, executing with the Java process's privileges; Alibaba rates it CVSS 9.0. Organizations running Fastjson 1.x should restrict exposure and monitor for exploitation until a fix arrives. - The Hacker News: https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html 2. GITLAB RCE POC RUNS COMMANDS AS GIT USER Vulnerabilities and Exploits · [rce, patch] Latest developments: Researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched on June 10, letting any authenticated user who can push to a project run commands as git on self-managed 18.11.3 servers that skipped the update. The attacker commits a crafted Jupyter notebook and opens its commit diff, leaking heap memory to reach code execution as the git user. Administrators of self-managed GitLab should apply the June 10 update immediately. - The Hacker News: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html 3. MALVERTISING BUILDS MALWARE IN BROWSER MEMORY Ransomware and Cybercrime · [malware, malvertising] Latest developments: BleepingComputer detailed a massive malvertising campaign on July 25 that serves counterfeit Solana, Luno, and TradingView pages whose JavaScript instructs the browser to assemble malware directly in memory. The operation lures victims to fake cryptocurrency and trading sites, where in-browser JavaScript builds the payload in memory to dodge disk-based detection. Users should avoid ads promising crypto tools and verify domains before entering anything. - BleepingComputer: https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/ 4. SHINYHUNTERS BREACH DATA FUELS $2,000 SEXTORTION Ransomware and Cybercrime · [breach, scam] Latest developments: BleepingComputer reported on July 25 that scammers are mining email addresses from breaches ShinyHunters leaked to send sextortion emails demanding $2,000 in Bitcoin. The campaign pairs victims' real email addresses from ShinyHunters-leaked breaches with threats to expose fabricated compromising material, extorting $2,000 in Bitcoin per target. Recipients should ignore and report the messages and rotate any exposed passwords. - BleepingComputer: https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/ 5. HERMES AI AGENT AUTOMATES THAI FINANCE MINISTRY BREACH AI Security · [apt, malware] Latest developments: BleepingComputer reported on July 24 that a threat actor drove the open-source Hermes AI agent in unattended 'YOLO' mode to automate post-exploitation during an alleged breach of Thailand's Ministry of Finance. Hermes, an open-source autonomous agent, ran attacker commands after an intrusion into the Thai Ministry of Finance, marking offensive use of agentic AI against a government target. Defenders should watch for agent-driven, high-speed post-exploitation on sensitive networks. - BleepingComputer: https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/ 6. ONTRAC PARCEL CARRIER DISCLOSES NETWORK BREACH Data Breaches · [breach] Latest developments: OnTrac began notifying customers on July 24 that hackers breached its corporate network and may have accessed their personal details. OnTrac, a regional parcel-delivery carrier, says intruders reached its corporate network and possibly took customer personal information. Affected customers should watch for fraud and phishing tied to their delivery accounts. - BleepingComputer: https://www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/ BUSINESS AND POLITICS ---------------------------------------------------------------- * U.S.-Iran War Pushes Deeper Into Iran Latest developments: American forces struck deeper inside Iran—hitting bridges and infrastructure in the south and near Tehran's outskirts—as President Trump signaled faster strikes and Yemen's Houthis fired missiles and drones at Saudi Arabia in retaliation for strikes on Hodeidah. The United States and Iran remain locked in a widening cycle of retaliation that has spread across the Gulf, with Saudi Arabia now trading blows with the Iran-backed Houthis and oil prices climbing high enough that investors call next week's Federal Reserve meeting live for a rate increase. - WSJ World News: https://www.wsj.com/world/middle-east/iran-war-us-escalation-cycle-8d90061e - FT World: https://www.ft.com/content/14ee6049-87bf-4aac-b684-c9937374fdcc?syn-25a6b1a6=1 PITTSBURGH ---------------------------------------------------------------- Weather: This Afternoon: Mostly Sunny, high 83F. Tonight: Mostly Clear then Patchy Fog, low 63F. Sunday: Patchy Fog then Mostly Sunny, high 86F. Business: * Pirates Fan Fights Ticket-Resale Rules Latest developments: Jim Crockard, a longtime Pirates fan from Sewickley, received an abrupt July 6 email from the Pittsburgh Pirates and is now crying foul over the team's stance on reselling tickets, TribLive reported. The Pittsburgh Pirates' policy restricting how season-ticket holders resell their seats has drawn a public complaint from a longtime Sewickley fan, spotlighting friction between the club and its ticket base at PNC Park. - TribLive: https://triblive.com/sports/pirates/longtime-pirates-fan-from-sewickley-cries-foul-over-teams-stance-on-ticket-resales/ * County Commits $6 Million to Housing Latest developments: Allegheny County Executive Sara Innamorato announced Friday a $6 million investment in two housing initiatives under her 'Housing for All' executive order. Allegheny County Executive Sara Innamorato is directing $6 million toward two housing programs as part of the Housing for All order she signed, steering county money into affordable-housing efforts across the region. - WPXI: https://www.wpxi.com/news/local/allegheny-county-executive-announces-6m-investment-housing-initiatives/D57TUNKR5RFQZH2JKVLMI36IPE/ SPORTS ---------------------------------------------------------------- Pirates (53-51) Fri Jul 24 · Cubs 3 · Pirates 2 · Final (10) Dansby Swanson's two-out single in the 10th inning, Boyd's strong outing lift Cubs over Pirates 3-2 https://plaintextsports.com/mlb/2026-07-24/chc-pit Up Next · Cubs @ Pirates · Sat Jul 25, 6:40 PM https://plaintextsports.com/mlb/2026-07-25/chc-pit Around the Teams: * Fautanu's Position Switch in Focus Latest developments: The Post-Gazette's camp countdown argued Troy Fautanu's move to a new spot on the offensive line will prove critical to the Steelers' 2026 offense and to protecting quarterback Aaron Rodgers. The Post-Gazette cast Steelers lineman Troy Fautanu's switch, part of a reshuffled front alongside guard Mason McCormick, as a make-or-break factor in keeping Aaron Rodgers upright and the offense functioning. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/25/nfl-trainingcamp-fautanu-mason-mccormick-aaron-rodgers/stories/202607250004 Team USA: * Richardson, Lyles Win 100 Titles Latest developments: Sha'Carri Richardson and Noah Lyles surged to victory in the 100-meter finals at the U.S. track and field championships, converting their first-round heats into national titles. American sprinters Sha'Carri Richardson and Noah Lyles both won the 100 meters at the U.S. championships, cementing their standing as the country's fastest and setting the stage for the summer's global meets. - ESPN Olympics: https://www.espn.com/olympics/trackandfield/story/_/id/49443171/shacarri-richardson-noah-lyles-surge-100-meter-wins-us-track-field-championships * Sonnett Stretchered Off for Gotham Latest developments: United States women's national team defender Emily Sonnett was stretchered off in the opening minutes of Gotham FC's 2-2 draw with the Portland Thorns on Friday after a non-contact knee injury. Emily Sonnett, a USWNT defender, went down with an apparent non-contact knee injury early in Gotham FC's National Women's Soccer League draw against the Portland Thorns, raising concern about her availability with one year until the 2027 Women's World Cup. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49444838/uswnt-gotham-fc-portland-thorns-emily-sonnett READING ---------------------------------------------------------------- * Stratechery -- OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips Ben Thompson unpacks how OpenAI accidentally 'hacked' Hugging Face and argues the episode's lessons about AI alignment and runaway optimization are more reassuring than the alarmed reaction suggests. https://stratechery.com/2026/openai-hacks-hugging-face-what-happened-alignment-and-paper-clips/ * Ed Zitron -- The Subprime Data Center Crisis Zitron argues the debt-fueled rush to build AI data centers resembles subprime lending, with fragile financing propping up an infrastructure boom he expects to unravel. https://www.wheresyoured.at/the-subprime-data-center-crisis/ * Cal Newport -- Why Reading Matters Responding to Rose Horowitch's Atlantic piece 'The End of Reading Is Here,' Newport defends sustained deep reading as an irreplaceable cognitive discipline worth protecting. https://calnewport.com/why-reading-matters/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,454.34 ▼ -0.9% Dow 51,988.28 ▼ -0.9% Nasdaq 25,429.94 ▼ -1.9% WTI crude 87.29 ▲ +9.5% EUR/USD 1.1397 ▼ -0.3% GBP/USD 1.3363 ▼ -0.6% USD/JPY 163.28 ▲ +0.6% ================================================================ Generated 2026-07-25 12:08 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================