================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Saturday, July 25, 2026 - 4:06 PM EDT ================================================================ Attackers exploit an unpatched Fastjson RCE and chain fresh PTC product-lifecycle flaws for Cl0p extortion, while cybercrime tooling from SourTrade malvertising to DevMan's ransomware portal grows steadily more industrialized. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Cybercrime keeps industrializing, from DevMan's self-service portal handing affiliates payload builders and payout dashboards to SourTrade malvertising that turns victims' browsers into malware compilers. see: DevMan RaaS Portal Centralizes Affiliate Operations; SourTrade Malvertising Builds Malware in the Browser * [TREND] Attackers are weaponizing enterprise software, exploiting the unpatched Fastjson flaw in Spring Boot, chaining fresh PTC Windchill and FlexPLM bugs for Cl0p extortion, as Rockwell patches Arena. see: Unpatched Fastjson RCE CVE-2026-16723 Under Attack; Clop Extortion Campaign Hits PTC Windchill and FlexPLM; Rockwell Patches Arena Simulation Code-Execution Flaws * [UPDATE (new)] Insurance-focused phishing crews are compressing the kill chain, now hijacking accounts in real time as victims type credentials rather than banking them for later use. see: Insurance Phishing Shifts to Real-Time Account Hijacking * [TREND] In Reading, Ed Zitron likens AI data-center financing to subprime lending while Ben Thompson finds reassurance on alignment in OpenAI's accidental Hugging Face hack. see: The Subprime Data Center Crisis; OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips * [UPDATE (new)] Around town, wildfire smoke returns to Pittsburgh with a Monday storm risk, a Little Debbie driver faces $17,000 fraud charges, and Arnold Palmer airport's shutdown reshuffles regional travel. see: Wildfire Smoke Returns, Storms Possible Monday; Little Debbie Driver Charged in $17,000 Fraud; Arnold Palmer Airport Shutdown Reshuffles Regional Air Travel SECURITY ---------------------------------------------------------------- 1. SOURTRADE MALVERTISING BUILDS MALWARE IN THE BROWSER Ransomware and Cybercrime · [malvertising, cryptocurrency] Latest developments: Confiant named the campaign SourTrade on July 23 and traced it to late 2024, finding it uses the legitimate Bun runtime as its base while victims' browsers assemble the final Windows executable in memory from pieces instead of downloading one complete file. SourTrade serves counterfeit TradingView, Solana, and Luno pages to retail cryptocurrency traders, and malicious JavaScript directs the browser to compile the malware itself, evading URL-based detection. Traders should reach these platforms through bookmarks and treat sponsored search results with suspicion. - The Hacker News: https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/ 2. UNPATCHED FASTJSON RCE CVE-2026-16723 UNDER ATTACK Vulnerabilities and Exploits · [rce, zero-day] Latest developments: The Hacker News detailed on July 25 that the confirmed chain hits affected Spring Boot applications, where a single malicious JSON request runs code unauthenticated at the Java process's privileges, and that Alibaba rates the flaw 9.0 while shipping no fix. CVE-2026-16723 sits in Fastjson 1.x, Alibaba's widely used JSON library for Java. Attackers who reach a vulnerable endpoint run code without authentication; with no patch available, defenders must restrict exposure and filter untrusted JSON input. - The Hacker News: https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html 3. ROCKWELL PATCHES ARENA SIMULATION CODE-EXECUTION FLAWS Vulnerabilities and Exploits · [patch, ics] Latest developments: Rockwell Automation patched code-execution vulnerabilities in its Arena simulation software on July 25 after a researcher showed how an attacker could exploit them against industrial organizations. The flaws let an attacker run code on machines running Arena, Rockwell's discrete-event simulation tool used across industrial engineering. Operators should apply the fixes and keep engineering workstations off untrusted networks. - SecurityWeek: https://www.securityweek.com/rockwell-patches-code-execution-flaws-in-arena-simulation-software/ 4. CLOP EXTORTION CAMPAIGN HITS PTC WINDCHILL AND FLEXPLM Ransomware and Cybercrime · [ransomware, extortion, rce] Latest developments: The Hacker News laid out the exploit chain on July 25: Cl0p affiliates pair a pre-authentication information-disclosure flaw in the FlexPLM WSDL endpoint with a server-side bug in the Windchill login servlet to run code without authentication. Cl0p, also tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest, is stealing data from internet-exposed PTC Windchill and FlexPLM product-lifecycle-management servers for extortion. Organizations running these systems should pull them off the public internet and hunt for the chain. - The Hacker News: https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html 5. DEVMAN RAAS PORTAL CENTRALIZES AFFILIATE OPERATIONS Ransomware and Cybercrime · [ransomware, raas] Latest developments: Swiss firm PRODAFT disclosed on July 25 that the DevMan ransomware-as-a-service operation, which it tracks as Funky Mantis, runs a dedicated web portal that lets affiliates build payloads, manage victims, and track earnings from a single console. DevMan's centrally administered platform bundles payload generation, finances, and victim management into one interface, lowering the skill floor for affiliates. Defenders should watch for payloads bearing its build signatures. - The Hacker News: https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html 6. INSURANCE PHISHING SHIFTS TO REAL-TIME ACCOUNT HIJACKING Ransomware and Cybercrime · [phishing] Latest developments: CTM360 reported on July 25 that insurance-focused phishing has dropped the old harvest-now, exploit-later model and now hijacks accounts in real time, capturing credentials and taking over accounts as victims enter them. The insurance-sector campaigns seize accounts the moment a victim submits credentials, defeating defenses timed to catch later logins. Institutions should enforce phishing-resistant authentication and monitor for live session hijacking. - The Hacker News: https://thehackernews.com/2026/07/ctm360-research-reveals-how-insurance.html BUSINESS AND POLITICS ---------------------------------------------------------------- * Oil Surge Puts a Fed Rate Rise in Play Latest developments: Traders piled into bets on a Federal Reserve rate increase after the oil-price jump, making next week's central-bank meeting 'live,' investors told the Financial Times. The Iran war's run-up in oil prices has pushed markets to price a Federal Reserve rate rise at next week's meeting, as tit-for-tat strikes between Saudi Arabia and Yemen's Houthis over Hodeida threaten Red Sea shipping and the Strait of Hormuz, and Washington and London weigh an international maritime coalition to guard the route. - FT World: https://www.ft.com/content/5019e030-796d-47e8-9f13-bee34de1d374?syn-25a6b1a6=1 - WSJ World News: https://www.wsj.com/world/middle-east/iran-war-us-escalation-cycle-8d90061e PITTSBURGH ---------------------------------------------------------------- Weather: This Afternoon: Partly Sunny, high 83F. Tonight: Mostly Clear then Patchy Fog, low 63F. Sunday: Patchy Fog then Mostly Sunny, high 86F. Business: * Arnold Palmer Airport Shutdown Reshuffles Regional Air Travel Latest developments: The shutdown of Arnold Palmer Regional Airport in Unity Township is sending Westmoreland County travelers to other runways and opening a window for competing regional airfields, TribLive reported. With Arnold Palmer Regional Airport in Unity Township closed, fliers such as Michelle Kish now route trips through Atlanta and other regional airports rather than Pittsburgh International, creating a sudden opening for nearby runways to pick up traffic. - TribLive: https://triblive.com/local/westmoreland/arnold-palmer-airport-shutdown-in-unity-creates-sudden-opportunity-for-regional-runways/ * Little Debbie Driver Charged in $17,000 Fraud Latest developments: The City of Washington Police Department charged a Little Debbie delivery driver with running a $17,000 scheme, selling snacks for cash at flea markets while filing fake invoices to make it look like stores had bought the product. James Powell, 39, of Valley Grove, West Virginia, sold his Little Debbie route inventory for cash at flea markets across Washington County and submitted thousands of dollars of bogus invoices to cover the sales, police said; the City of Washington police opened the case in May after the Jefferson County Sheriff's Office flagged it. - KDKA: https://www.cbsnews.com/pittsburgh/news/little-debbie-snack-delivery-driver-fraud-scheme/ Around town: * State Police Traffic Stops Show No Racial Disparities Latest developments: An analysis released Friday found no substantive racial or ethnic disparities in Pennsylvania State Police traffic stops for a third straight year, officials said. The Pennsylvania State Police's third annual independent review of trooper traffic-stop data found no substantive racial or ethnic disparities in who officers pull over, officials announced Friday. - WPXI: https://www.wpxi.com/news/local/analysis-finds-no-substantive-disparities-pennsylvania-state-police-traffic-stops-officials-say/4EOYZSAHJVHKLA2TZBHO52DEKI/ * Wildfire Smoke Returns, Storms Possible Monday Latest developments: Wildfire smoke drifts back into the Pittsburgh area overnight Saturday, and forecasters flag a lower-end severe-weather risk for Monday and possibly Tuesday, KDKA reported. After a dry Saturday with highs in the low 80s, wildfire smoke returns to the Pittsburgh region overnight, and forecasters see a modest chance of severe storms early next week on Monday and into Tuesday. - KDKA: https://www.cbsnews.com/pittsburgh/news/saturday-dry-wildfire-smoke-returns/ SPORTS ---------------------------------------------------------------- Pirates (53-51) Fri Jul 24 · Cubs 3 · Pirates 2 · Final (10) Dansby Swanson's two-out single in the 10th inning, Boyd's strong outing lift Cubs over Pirates 3-2 https://plaintextsports.com/mlb/2026-07-24/chc-pit Up Next · Cubs @ Pirates · Sat Jul 25, 6:40 PM https://plaintextsports.com/mlb/2026-07-25/chc-pit Around the Teams: * Roethlisberger Previews Steelers Camp on 'Footbahlin' Latest developments: On 'Footbahlin' Episode 133, Ben Roethlisberger broke down what to watch once Steelers training camp opens next week and what makes a franchise quarterback. Former Steelers quarterback Ben Roethlisberger, on his 'Footbahlin' podcast, previewed the real competition and roster questions that surface the moment Pittsburgh hits the practice field at Saint Vincent College, and weighed what defines a franchise quarterback in the new McCarthy era. - Ben Roethlisberger / Channel Seven (YouTube): https://www.youtube.com/watch?v=Z1YJqSjWA74 Team USA: * Barcelona Sign U.S. Goalkeeper Tyler McCamey Latest developments: Barcelona signed American goalkeeper Tyler McCamey for its women's team, the Spanish club announced Saturday. Barcelona, the reigning women's Champions League winner, added United States goalkeeper Tyler McCamey to its squad, the club said July 25. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49447813/barcelona-sign-us-goalkeeper-tyler-mccamey * USWNT's Path to the 2027 World Cup Final Latest developments: With one year to the 2027 Women's World Cup final, ESPN laid out five reasons the United States women's national team will or will not reach it. ESPN marked the one-year countdown to the 2027 Women's World Cup final with an assessment of the U.S. women's national team, weighing five factors that could carry it to the title match or keep it out. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49435317/5-reasons-uswnt-in-women-world-cup-final-one-year READING ---------------------------------------------------------------- * Stratechery -- OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips Ben Thompson argues that OpenAI's accidental 'hack' of Hugging Face carries more encouraging lessons about AI alignment than the initial alarm suggested. https://stratechery.com/2026/openai-hacks-hugging-face-what-happened-alignment-and-paper-clips/ * Ed Zitron -- The Subprime Data Center Crisis Ed Zitron contends the AI build-out rests on shaky, debt-fueled data-center financing he likens to subprime lending, warning it sets up a reckoning. https://www.wheresyoured.at/the-subprime-data-center-crisis/ * Cal Newport -- Why Reading Matters Cal Newport answers Rose Horowitch's Atlantic piece declaring the end of reading, making the case for why sustained deep reading still matters. https://calnewport.com/why-reading-matters/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,454.34 ▼ -0.9% Dow 51,988.28 ▼ -0.9% Nasdaq 25,429.94 ▼ -1.9% WTI crude 87.29 ▲ +9.5% EUR/USD 1.1397 ▼ -0.3% GBP/USD 1.3389 ▼ -0.3% USD/JPY 163.28 ▲ +0.6% ================================================================ Generated 2026-07-25 16:06 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================