daily plain-text briefing: security, markets, business, and pittsburgh
A Chinese-speaking crew wired AI models into an autonomous attack pipeline as a static-credential zero-day in Cisco's firewall manager fell to active exploitation.
Latest developments: CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog after Horizon3.ai's Jimi Sebree reported a pair of Cisco Secure Firewall Management Center flaws whose static low-privilege web credentials let a remote, unauthenticated attacker log into affected devices.
Cisco Secure FMC centrally manages fleets of Cisco firewalls, so a foothold there exposes an entire network's defenses. Administrators should apply Cisco's fixes immediately given confirmed zero-day exploitation.
Sources: SecurityWeek · Help Net Security · The Hacker News · BleepingComputer · ↑ top
Latest developments: CISA and allied agencies published the 2026 Minimum Elements for a Software Bill of Materials, retiring the 2021 NTIA guidance with new required elements and updated terminology, while the FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, 2026, blocking new models from US import, marketing, and sale.
The SBOM refresh helps buyers see what components their software carries, and the FCC action targets China over cyber and national-security risk. Software buyers and hardware importers face fresh compliance expectations.
Sources: Help Net Security · SecurityWeek · The Hacker News · SecurityWeek · ↑ top
Latest developments: Cybercriminals moved to extort Britain's Department for Education over what they claim is more than 600,000 records holding names, emails, and phone numbers, semiconductor maker Analog Devices confirmed intruders detected in June stole files, and Health-ISAC warned healthcare and medical-technology firms of a surge in ShinyHunters data-theft attacks.
The three disclosures span a government ministry, a chip maker, and the health sector, all facing data theft and extortion pressure. Affected organizations should assume exposed personal data and brace for follow-on fraud.
Sources: The Record · SecurityWeek · BleepingComputer · ↑ top
Latest developments: South Korean authorities and four security firms exposed a North Korea-linked campaign that compromised trusted domestic websites to abuse the AnySign4PC financial-security software and drop the SIGNBT and COPPERHEDGE backdoors without any user prompt, while the Chinese group Silver Fox chained three vulnerable drivers in a bring-your-own-vulnerable-driver attack on a Japanese industrial manufacturer to deploy the ValleyRAT remote access trojan.
Both operations abuse software already trusted on the target—Korean banking security add-ons and signed Windows drivers—to reach victims quietly. Organizations should audit locally installed security agents and block known vulnerable drivers.
Sources: The Hacker News · The Hacker News · ↑ top
Latest developments: Palo Alto's Unit 42 disclosed on July 30, 2026 that a Chinese-speaking threat actor ran AI models to autonomously scan seven vulnerabilities, then handed exploitation to human operators who finished the intrusions by hand.
The hybrid campaign lets AI drive reconnaissance and vulnerability discovery at machine speed while operators pick targets and press the attack, a template rival crews can copy. Defenders should expect faster, wider scanning and prioritize patching internet-facing flaws.
Sources: Unit 42 (Palo Alto) · ↑ top
Latest developments: Håkon Måløy disclosed on July 28, 2026, 144 days after reporting it to Microsoft, that hidden instructions inside a Word document can make Microsoft 365 Copilot rewrite a report's figures and then copy those same instructions into the finished file, which re-triggers the behavior in a later drafting session.
The attack turns Copilot into a courier that smuggles its own instructions from one document to the next, propagating without further attacker action. Teams that let Copilot process untrusted documents should treat its output as potentially tainted.
Sources: The Hacker News · ↑ top
Latest developments: United States forces bombed Iran again overnight July 30 in reprisal for Iranian ballistic-missile attacks, and an unclaimed drone struck inside Egypt for the first time, menacing the Suez Canal as an oil route.
The five-month war between the United States and Iran deepened as the two traded missile barrages and Washington launched fresh strikes; the first drone attack on Egyptian soil signaled the Suez Canal may not offer a safe alternative for tankers avoiding the contested Strait of Hormuz, keeping oil prices elevated.
Sources: FT World · WSJ World News · ↑ top
Today: Sunny, high 83F.
Tonight: Clear, low 59F.
Friday: Sunny, high 87F.
Latest developments: Dozens of shoppers flocked to the newly opened Dick's House of Sport in Westmoreland County, TribLive reported, with one buyer lining up for Kobe 5 Protro x Caitlin Clark sneakers.
Coraopolis-based Dick's Sporting Goods debuted one of its large-format House of Sport experiential stores in Westmoreland County, part of the retailer's push to reformat locations around rock walls, batting cages, and premium gear.
Latest developments: NEXTpittsburgh's July roundup counted eight new food-and-drink arrivals, including an island-inspired cocktail destination Downtown and the long-awaited return of a beloved whiskey bar, plus fresh spots for tacos, matcha, and coffee.
Pittsburgh's restaurant scene kept expanding through a stretch of swings between heat advisories and downpours, adding cocktail, taco, coffee, and matcha destinations that give the city's dining map a new set of anchors.
Sources: NEXTpittsburgh · ↑ top
Latest developments: PennDOT reached a major milestone on its year-long reconstruction of the Wexford I-79 interchange, KDKA reported, including a new flyover reshaping a long-congested junction.
PennDOT is not just rebuilding but reimagining the Wexford interchange on Interstate 79 in Pittsburgh's northern suburbs, a chronic bottleneck for commuters, with a flyover among the changes as the project passes a key construction mark.
Latest developments: TribLive reported that Leetsdale borough now owns the parking lot of VFW Post 3372, seized through eminent domain earlier this year, though negotiations between the two continue.
A long-running parking dispute between Leetsdale VFW Post 3372 and the borough of Leetsdale persists even after the local government acquired the Post's lot, leaving the terms of continued use unsettled.
Pirates (55-54)
Wed Jul 29 · Diamondbacks 3 · Pirates 0 · Final
Rodríguez goes 8 innings, Moreno hits 2-run homer as Diamondbacks blank Pirates 3-0
Up Next · Pirates @ Reds · Thu Jul 30, 7:10 PM
Latest developments: Post-Gazette columnist Noah Hiles wrote that an injury scare to outfielder Esmerlyn Valdez underscores how thin the Pirates' offense is one day before the trade deadline.
Hiles argued the Pirates can ill afford to lose young bats like Esmerlyn Valdez, casting a weak lineup as the problem general manager Ben Cherington should prioritize when he buys or sells at the July 31 deadline.
Sources: Post-Gazette Pirates · ↑ top
Latest developments: AS Monaco signed France under-21 striker Matthis Abline from Nantes on July 30, forming a potential forward line alongside United States international Folarin Balogun.
Folarin Balogun, the U.S. men's national team striker, picks up a new attacking partner at his French club Monaco with the arrival of Matthis Abline, a move that shapes his club role heading into the next World Cup cycle.
Sources: ESPN Soccer · ↑ top
S&P 500 7,395.68 ▼ -1.2% Dow 52,042.09 ▼ -0.3% Nasdaq 24,873.09 ▼ -3.2% WTI crude 85.57 ▲ +2.7% EUR/USD 1.1388 ▼ -0.4% GBP/USD 1.3323 ▼ -1.0% USD/JPY 163.63 ▲ +0.7%