================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Thursday, July 30, 2026 - 6:06 AM EDT ================================================================ A coordinated cyberattack struck operational technology at more than 30 Minnesota community water systems, knocking Braham's plant offline and triggering a statewide incident response. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] A coordinated cyberattack knocked operational-technology controls offline at more than 30 Minnesota water utilities on July 26 and 27, taking Braham's plant down. see: Coordinated Cyberattack Hits 30-Plus Minnesota Water Systems * [TREND] AI agents became targets themselves as Noma's maximum-severity RufRoot flaw let unauthenticated attackers hijack Ruflo harnesses driving Anthropic's Claude Code and OpenAI's Codex swarms. see: RufRoot Flaw Turns Ruflo AI Harness Into an Attack Engine * [TREND] State-backed espionage widened as Russia's Laundry Bear rode a Microsoft OWA zero-day to keep mailbox access past password resets while Amazon tied the debug and chalk npm hijack to North Korea. see: Laundry Bear Rides OWA Zero-Day Past Credential Resets; Amazon Ties debug and chalk npm Hijack to North Korea * [UPDATE (new)] Broadcom shipped fixes for a critical 9.8-rated vCenter authentication bypass and an ESX VM escape as Kaspersky detailed Toy Ghouls' new GenieLocker ransomware. see: Broadcom Patches Critical VMware Auth Bypass and VM Escape; Toy Ghouls Deploy GenieLocker Ransomware * [TREND] Commentators from Ben Thompson to Newport reframed the OpenAI–Hugging Face breach as mundane engineering rather than rogue AI, while Zitron argues bigger compute spending only deepens losses. see: OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips; Did OpenAI’s New Model “Go Rogue”?; The More You Buy, The More You Lose SECURITY ---------------------------------------------------------------- 1. COORDINATED CYBERATTACK HITS 30-PLUS MINNESOTA WATER SYSTEMS Critical Infrastructure · [ics, critical-infrastructure, ot] Latest developments: Minnesota IT Services confirmed that a coordinated cyberattack on July 26 and 27 struck operational-technology systems at more than 30 community water utilities, taking Braham's water plant offline and disrupting automated controls and communications at Plymouth, South St. Paul, and Maple Plain, while CISA and Australia released guidance the same week on isolating OT to survive such intrusions. Unknown attackers hit control systems across dozens of small Minnesota water utilities at once; Braham asked residents to minimize water use after its plant went dark. Operators of internet-exposed OT should segment and isolate control networks and prepare to run them disconnected. - Help Net Security: https://www.helpnetsecurity.com/2026/07/30/minnesota-water-utilities-coordinated-cyberattack/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack/ - The Hacker News: https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html - SecurityWeek: https://www.securityweek.com/us-australia-release-ot-isolation-guidance-for-critical-infrastructure/ 2. RUFROOT FLAW TURNS RUFLO AI HARNESS INTO AN ATTACK ENGINE AI Security · [ai, zero-day, rce] Latest developments: Noma Security disclosed CVE-2026-59726, a 10.0-rated flaw it codenamed RufRoot in Ruflo, an open-source agent meta-harness for Anthropic's Claude Code and OpenAI's Codex, that lets an unauthenticated attacker send an HTTP request to an exposed endpoint, run commands inside the MCP bridge container, and poison agent memory so malicious behavior survives patching. Every Ruflo version before 3.16.3 exposes an MCP bridge that grants remote code execution and lets attackers spawn rogue AI agent swarms. Operators must upgrade to 3.16.3 and purge any corrupted agent memory, since a patch alone does not evict persisted instructions. - The Hacker News: https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html - Dark Reading: https://www.darkreading.com/cyber-risk/patch-resistant-rufroot-flaw-malicious-ai-agent-swarms - SecurityWeek: https://www.securityweek.com/critical-ruflo-flaw-lets-attackers-spawn-rogue-ai-swarms/ 3. LAUNDRY BEAR RIDES OWA ZERO-DAY PAST CREDENTIAL RESETS Nation-State Activity · [apt, zero-day, espionage] Latest developments: Researchers reported that Russia's Laundry Bear, also tracked as Void Blizzard, has exploited a Microsoft Outlook Web Access zero-day since July 22 to plant the OWAReaper backdoor, which retains mailbox access even after victims rotate credentials, striking US and European government, telecommunications, financial, hospitality, and aerospace targets. The same Russian group behind the Zimbra espionage campaign now abuses OWA to hold email accounts through password changes, defeating a standard remediation step. Organizations running on-premises Exchange OWA should hunt for OWAReaper and monitor for persistent access surviving resets. - The Hacker News: https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html - BleepingComputer: https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/ - The Record: https://therecord.media/russia-hackers-outlook-webmail-malware 4. AMAZON TIES DEBUG AND CHALK NPM HIJACK TO NORTH KOREA Nation-State Activity · [apt, supply-chain, npm] Latest developments: Amazon attributed the September 2025 hijack of the npm packages debug and chalk to North Korea's Sapphire Sleet, an attack the public record had filed for ten months as ordinary crypto theft after a maintainer fell to a lookalike npm domain and a wallet-draining script reached at least 18 packages carrying more than 2 billion weekly downloads. The compromise poisoned two of JavaScript's most-downloaded utility packages, and Amazon now links it to a state-sponsored North Korean group rather than freelance thieves. Developers who pulled affected versions last fall should audit builds and rotate any exposed wallet or CI credentials. - The Hacker News: https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html 5. TOY GHOULS DEPLOY GENIELOCKER RANSOMWARE Ransomware and Cybercrime · [ransomware, esxi, extortion] Latest developments: Kaspersky dissected GenieLocker, a new custom ransomware family with distinct variants for Windows, Linux, and VMware ESXi that the financially motivated extortion group Toy Ghouls wields in its attacks. GenieLocker's ESXi build lets Toy Ghouls encrypt entire virtualization estates in a single stroke, the tactic that makes hypervisor-targeting ransomware so damaging. Defenders should harden ESXi hosts, restrict management interfaces, and keep offline backups of virtual-machine data. - Securelist (Kaspersky): https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/ 6. BROADCOM PATCHES CRITICAL VMWARE AUTH BYPASS AND VM ESCAPE Vulnerabilities and Exploits · [patch, vulnerability, virtualization] Latest developments: Broadcom shipped fixes for five VMware flaws, three of them critical, led by CVE-2026-59309, a 9.8-rated authentication bypass in vCenter that a network-adjacent attacker can exploit, alongside a virtual-machine escape in ESX that lets a guest break out to the host. The bugs hit VMware ESX, vCenter, Workstation, and Fusion, the backbone of most enterprise virtualization; a vCenter auth bypass and an ESX VM escape hand attackers control of the hypervisor and everything on it. Administrators should apply Broadcom's updates immediately given the products' exposure. - The Hacker News: https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html - SecurityWeek: https://www.securityweek.com/critical-vm-escape-vulnerability-patched-in-vmware-esxi/ BUSINESS AND POLITICS ---------------------------------------------------------------- * U.S. and Iran Trade Missile Barrages Latest developments: The United States launched fresh strikes on Iran on July 30, a day after Iranian ballistic missiles hit a base in Jordan that hosts American troops, and hopes for a quick resolution faded. The United States and Iran are exchanging missile barrages across the Middle East after President Trump vowed to hit Iran "very hard," widening a war that has driven crude prices and energy-trading profits higher, with Shell posting its second-highest earnings ever on the disruption. - FT World: https://www.ft.com/content/42e83b67-cfb8-46af-b50e-3ac77748ce38?syn-25a6b1a6=1 PITTSBURGH ---------------------------------------------------------------- Weather: Today: Sunny, high 83F. Tonight: Clear, low 59F. Friday: Sunny, high 87F. Business: * Federal Broadband Grants Set to Flow to Pennsylvania Latest developments: Federal officials agreed to restore the broadband grant program after dropping diversity-related conditions, poising money to flow into Pennsylvania for high-speed internet expansion. Washington's reversal clears hundreds of millions of dollars in BEAD broadband funding to reach Pennsylvania, money aimed at extending high-speed internet into unserved and rural corners of the state. - Pittsburgh Post-Gazette: https://www.post-gazette.com/business/tech-news/2026/07/30/pennsylvania-broadband-dei/stories/202607300002 * Westinghouse Moves Its Historic Atom Smasher Latest developments: Westinghouse is disassembling its atom smasher in Forest Hills and will rebuild it at the company's nuclear headquarters in Cranberry Township. The Westinghouse atom smasher, a pear-shaped generator that opened in Forest Hills in 1937 and pioneered research that laid the foundation for nuclear power, will be taken apart and reassembled at Westinghouse's Cranberry Township nuclear headquarters; Gary Silversmith owns the Forest Hills property where it stood for nearly 90 years. - KDKA: https://www.cbsnews.com/pittsburgh/news/westinghouse-atom-smasher-disassembled/ Around town: * Strip District Residents Fight Townhome Plan Latest developments: Strip District residents gathered July 29 to oppose a proposed townhome development and related taxing plans, a day after city officials made two decisions affecting the neighborhood. Neighbors in Pittsburgh's Strip District organized against a new townhome project and financing plans they say will reshape the district, meeting the evening after city officials issued two rulings that directly touch the area. - WPXI: https://www.wpxi.com/news/local/strip-district-residents-gather-oppose-new-town-home-development-taxing-plans/AENEGONFZVGLRD732IRAA6HRBQ/ Events: * PulpFest in Cranberry Latest developments: PulpFest, the pulp-fiction and vintage-magazine convention, opens Thursday, July 30 in Cranberry. PulpFest runs Thursday, July 30 through Sunday, August 2 at the DoubleTree by Hilton Pittsburgh, 910 Sheraton Drive in Cranberry, gathering collectors of pulp fiction and vintage magazines; registration runs $50 to $80 at pulpfest.com. - Pittsburgh City Paper: https://www.pghcitypaper.com/listings/pittsburghs-top-events-thu-july-30-wed-aug-5/ * Sweetwater Arts Opening in Sewickley Latest developments: Sweetwater Center for the Arts holds a free opening reception for two new exhibitions on Thursday, July 30. The Sweetwater Center for the Arts, 200 Broad Street in Sewickley, hosts a free opening reception for "During Naptime" and "Interior Kaleidoscope" on Thursday, July 30 from 6 to 8 p.m.; the shows run through September 11. - Pittsburgh City Paper: https://www.pghcitypaper.com/listings/pittsburghs-top-events-thu-july-30-wed-aug-5/ SPORTS ---------------------------------------------------------------- Pirates (55-54) Wed Jul 29 · Diamondbacks 3 · Pirates 0 · Final Rodríguez goes 8 innings, Moreno hits 2-run homer as Diamondbacks blank Pirates 3-0 https://plaintextsports.com/mlb/2026-07-29/ari-pit Up Next · Pirates @ Reds · Thu Jul 30, 7:10 PM https://plaintextsports.com/mlb/2026-07-30/pit-cin Around the Teams: * Pirates Weigh Deadline Moves Latest developments: One day before the July 31 trade deadline, the Post-Gazette laid out five clubs the Pirates could partner with and named pieces in play, including Luke Weaver, Jo Adell, Kirby Yates, and Camilo Doval. With the July 31 Major League Baseball trade deadline looming, the Post-Gazette sketched five potential trade partners for the Pirates and the players who could change hands as general manager Ben Cherington sizes up the market. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/07/30/mlb-trade-deadline-weaver-adell-yates-doval/stories/202607300005 * Rudolph Settled in the QB Room Latest developments: At Steelers camp in Latrobe, veteran Mason Rudolph said he is comfortable in the quarterback competition as Will Howard and Drew Allar develop behind Aaron Rodgers. The Post-Gazette reported from Saint Vincent College that Mason Rudolph, back for another Steelers stint, feels settled in a quarterback room head coach Mike McCarthy is building around starter Aaron Rodgers, with young passers Will Howard and Drew Allar working to develop. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/30/mason-rudolph-training-camp-will-howard-drew-allar-mike-mccarthy-competition/stories/202607290044 * Ryan Clark on 'Not Just Football' Latest developments: On the latest 'Not Just Football,' host Cam Heyward and former teammate Ryan Clark revisited Clark once calling a young Heyward a 'bust,' along with Antonio Brown and old locker-room stories. 'Not Just Football,' the podcast hosted by Steelers defensive lineman Cam Heyward, welcomed former teammate and ESPN analyst Ryan Clark, who recounted a tense early moment with a rookie Heyward, dubbing him a 'bust' at the time, and swapped tales about Antonio Brown and the Steelers locker room. - Not Just Football with Cam Heyward: https://www.youtube.com/watch?v=4lPvsN0SA6A Team USA: * USSF Nears Decision on Pochettino Latest developments: U.S. Soccer president Cindy Parlow Cone said July 29, before the MLS All-Star Game, that talks to extend Mauricio Pochettino as U.S. men's coach are "going well" and an announcement is coming soon. The United States Soccer Federation must settle whether Mauricio Pochettino stays on as men's national team manager after the Americans' round-of-16 exit at the 2026 World Cup, and Parlow Cone signaled a resolution is close. - ESPN Soccer: https://www.espn.com/soccer/story/_/id/49484972/us-soccer-president-parlow-cone-pochettino-new-deal-talks-going-well-announcement-coming-soon * Dressel Opens U.S. Nationals With a Win Latest developments: Caeleb Dressel won the 100-meter freestyle at the USA Swimming National Championships on July 28 in his fastest time since the 2024 Olympic trials. Former Olympic champion Caeleb Dressel opened the USA Swimming National Championships with a 100-meter freestyle victory, his quickest swim in the event since the 2024 trials, a promising marker on the road to the 2028 Los Angeles Games. - ESPN Olympics: https://www.espn.com/olympics/swimming/story/_/id/49476708/dressel-wins-100-free-usa-swimming-championships-commence * U.S. Biathlon Delays Ski Merger Latest developments: The U.S. Biathlon board voted July 29 to push back its planned merger with U.S. Ski & Snowboard to review the details after opposition from its community. U.S. Biathlon, weighing whether to move under U.S. Ski & Snowboard to boost revenue and performance, delayed the decision after pushback from athletes and members, slowing a rare consolidation of Olympic sport organizations. - ESPN Olympics: https://www.espn.com/olympics/story/_/id/49484505/us-biathlon-delays-decision-join-us-ski-snowboard-merger READING ---------------------------------------------------------------- * Ed Zitron -- The More You Buy, The More You Lose Zitron argues that the AI industry's ever-larger spending on chips and data centers deepens the losses of the companies making the bets, so the more compute they buy, the worse their economics become. https://www.wheresyoured.at/the-more-you-buy-the-more-you-lose/ * Cal Newport -- Did OpenAI’s New Model “Go Rogue”? Newport examines the reported intrusion into Hugging Face's infrastructure and pushes back on sensational "rogue AI" framing, arguing the episode reflects mundane engineering failures rather than an autonomous model breaking loose. https://calnewport.com/did-openais-new-model-go-rogue/ * Stratechery -- OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips Ben Thompson walks through how OpenAI accidentally breached Hugging Face and argues the incident's lessons for AI alignment are more reassuring than the alarmed reaction suggests. https://stratechery.com/2026/openai-hacks-hugging-face-what-happened-alignment-and-paper-clips/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,395.68 ▼ -1.2% Dow 52,042.09 ▼ -0.3% Nasdaq 24,873.09 ▼ -3.2% WTI crude 85.57 ▲ +2.7% EUR/USD 1.1388 ▼ -0.4% GBP/USD 1.3323 ▼ -1.0% USD/JPY 163.63 ▲ +0.7% ================================================================ Generated 2026-07-30 06:06 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================