daily plain-text briefing: security, markets, business, and pittsburgh
Attackers exploit an unpatched Fastjson RCE and chain fresh PTC product-lifecycle flaws for Cl0p extortion, while cybercrime tooling from SourTrade malvertising to DevMan's ransomware portal grows steadily more industrialized.
Latest developments: Confiant named the campaign SourTrade on July 23 and traced it to late 2024, finding it uses the legitimate Bun runtime as its base while victims' browsers assemble the final Windows executable in memory from pieces instead of downloading one complete file.
SourTrade serves counterfeit TradingView, Solana, and Luno pages to retail cryptocurrency traders, and malicious JavaScript directs the browser to compile the malware itself, evading URL-based detection. Traders should reach these platforms through bookmarks and treat sponsored search results with suspicion.
Sources: The Hacker News · BleepingComputer · ↑ top
Latest developments: The Hacker News detailed on July 25 that the confirmed chain hits affected Spring Boot applications, where a single malicious JSON request runs code unauthenticated at the Java process's privileges, and that Alibaba rates the flaw 9.0 while shipping no fix.
CVE-2026-16723 sits in Fastjson 1.x, Alibaba's widely used JSON library for Java. Attackers who reach a vulnerable endpoint run code without authentication; with no patch available, defenders must restrict exposure and filter untrusted JSON input.
Sources: The Hacker News · ↑ top
Latest developments: Rockwell Automation patched code-execution vulnerabilities in its Arena simulation software on July 25 after a researcher showed how an attacker could exploit them against industrial organizations.
The flaws let an attacker run code on machines running Arena, Rockwell's discrete-event simulation tool used across industrial engineering. Operators should apply the fixes and keep engineering workstations off untrusted networks.
Sources: SecurityWeek · ↑ top
Latest developments: The Hacker News laid out the exploit chain on July 25: Cl0p affiliates pair a pre-authentication information-disclosure flaw in the FlexPLM WSDL endpoint with a server-side bug in the Windchill login servlet to run code without authentication.
Cl0p, also tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest, is stealing data from internet-exposed PTC Windchill and FlexPLM product-lifecycle-management servers for extortion. Organizations running these systems should pull them off the public internet and hunt for the chain.
Sources: The Hacker News · ↑ top
Latest developments: Swiss firm PRODAFT disclosed on July 25 that the DevMan ransomware-as-a-service operation, which it tracks as Funky Mantis, runs a dedicated web portal that lets affiliates build payloads, manage victims, and track earnings from a single console.
DevMan's centrally administered platform bundles payload generation, finances, and victim management into one interface, lowering the skill floor for affiliates. Defenders should watch for payloads bearing its build signatures.
Sources: The Hacker News · ↑ top
Latest developments: CTM360 reported on July 25 that insurance-focused phishing has dropped the old harvest-now, exploit-later model and now hijacks accounts in real time, capturing credentials and taking over accounts as victims enter them.
The insurance-sector campaigns seize accounts the moment a victim submits credentials, defeating defenses timed to catch later logins. Institutions should enforce phishing-resistant authentication and monitor for live session hijacking.
Sources: The Hacker News · ↑ top
Latest developments: Traders piled into bets on a Federal Reserve rate increase after the oil-price jump, making next week's central-bank meeting 'live,' investors told the Financial Times.
The Iran war's run-up in oil prices has pushed markets to price a Federal Reserve rate rise at next week's meeting, as tit-for-tat strikes between Saudi Arabia and Yemen's Houthis over Hodeida threaten Red Sea shipping and the Strait of Hormuz, and Washington and London weigh an international maritime coalition to guard the route.
Sources: FT World · WSJ World News · ↑ top
This Afternoon: Partly Sunny, high 83F.
Tonight: Mostly Clear then Patchy Fog, low 63F.
Sunday: Patchy Fog then Mostly Sunny, high 86F.
Latest developments: The shutdown of Arnold Palmer Regional Airport in Unity Township is sending Westmoreland County travelers to other runways and opening a window for competing regional airfields, TribLive reported.
With Arnold Palmer Regional Airport in Unity Township closed, fliers such as Michelle Kish now route trips through Atlanta and other regional airports rather than Pittsburgh International, creating a sudden opening for nearby runways to pick up traffic.
Latest developments: The City of Washington Police Department charged a Little Debbie delivery driver with running a $17,000 scheme, selling snacks for cash at flea markets while filing fake invoices to make it look like stores had bought the product.
James Powell, 39, of Valley Grove, West Virginia, sold his Little Debbie route inventory for cash at flea markets across Washington County and submitted thousands of dollars of bogus invoices to cover the sales, police said; the City of Washington police opened the case in May after the Jefferson County Sheriff's Office flagged it.
Latest developments: An analysis released Friday found no substantive racial or ethnic disparities in Pennsylvania State Police traffic stops for a third straight year, officials said.
The Pennsylvania State Police's third annual independent review of trooper traffic-stop data found no substantive racial or ethnic disparities in who officers pull over, officials announced Friday.
Latest developments: Wildfire smoke drifts back into the Pittsburgh area overnight Saturday, and forecasters flag a lower-end severe-weather risk for Monday and possibly Tuesday, KDKA reported.
After a dry Saturday with highs in the low 80s, wildfire smoke returns to the Pittsburgh region overnight, and forecasters see a modest chance of severe storms early next week on Monday and into Tuesday.
Pirates (53-51)
Fri Jul 24 · Cubs 3 · Pirates 2 · Final (10)
Dansby Swanson's two-out single in the 10th inning, Boyd's strong outing lift Cubs over Pirates 3-2
Up Next · Cubs @ Pirates · Sat Jul 25, 6:40 PM
Latest developments: On 'Footbahlin' Episode 133, Ben Roethlisberger broke down what to watch once Steelers training camp opens next week and what makes a franchise quarterback.
Former Steelers quarterback Ben Roethlisberger, on his 'Footbahlin' podcast, previewed the real competition and roster questions that surface the moment Pittsburgh hits the practice field at Saint Vincent College, and weighed what defines a franchise quarterback in the new McCarthy era.
Sources: Ben Roethlisberger / Channel Seven (YouTube) · ↑ top
Latest developments: Barcelona signed American goalkeeper Tyler McCamey for its women's team, the Spanish club announced Saturday.
Barcelona, the reigning women's Champions League winner, added United States goalkeeper Tyler McCamey to its squad, the club said July 25.
Sources: ESPN Soccer · ↑ top
Latest developments: With one year to the 2027 Women's World Cup final, ESPN laid out five reasons the United States women's national team will or will not reach it.
ESPN marked the one-year countdown to the 2027 Women's World Cup final with an assessment of the U.S. women's national team, weighing five factors that could carry it to the title match or keep it out.
Sources: ESPN Soccer · ↑ top
S&P 500 7,454.34 ▼ -0.9% Dow 51,988.28 ▼ -0.9% Nasdaq 25,429.94 ▼ -1.9% WTI crude 87.29 ▲ +9.5% EUR/USD 1.1397 ▼ -0.3% GBP/USD 1.3389 ▼ -0.3% USD/JPY 163.28 ▲ +0.6%