================================================================ INFOSECFOLLOW -- security, markets, business, pittsburgh Thursday, July 30, 2026 - 4:07 PM EDT ================================================================ Google credited AI with patching more than a thousand Chrome bugs across two releases while Palo Alto caught a Chinese actor turning AI loose to hunt and exploit flaws, cementing AI's grip on both sides of the vulnerability race. CONTENTS: Emerging Trends and Key Updates | Security | Business and Politics | Pittsburgh | Sports | Reading | Markets EMERGING TRENDS AND KEY UPDATES ---------------------------------------------------------------- * [TREND] Artificial intelligence now works both sides of the exploit pipeline, with Google crediting AI for a Chrome patch surge as a Chinese-speaking crew ran autonomous scans before exploiting bugs by hand. see: AI Rewrites Both Vulnerability Hunting and Attacks * [TREND] North Korea keeps multiplying delivery routes, pushing fake full-screen macOS update screens through Contagious Interview and abusing hijacked Korean sites that lean on financial-security software. see: North Korea Widens macOS Malvertising and Korean Software Attacks * [TREND] Data-theft extortion crews stayed busy as ShinyHunters claimed Brinks Home, criminals squeezed Britain's schools over 600,000 records, and Analog Devices confirmed intruders stole files. see: Extortion Crews Hit Analog Devices, Brinks, and UK Schools * [UPDATE (new)] Fresh urgent fixes landed as Broadcom patched critical VMware VM-escape flaws and Cisco firewall bugs, while CISA issued eleven industrial-control advisories touching MikroTik and Schneider Electric. see: VMware VM-Escape and Cisco Firewall Flaws Draw Urgent Fixes; CISA and FCC Move on ICS and Supply-Chain Risk * [TREND] Chinese espionage kept escalating as Silver Fox chained vulnerable drivers to drop ValleyRAT on a Japanese manufacturer, while Kaspersky exposed OctLurk memory backdoors. see: Chinese-Linked Espionage Deploys ValleyRAT and Memory Backdoors SECURITY ---------------------------------------------------------------- 1. AI REWRITES BOTH VULNERABILITY HUNTING AND ATTACKS AI Security · [ai, vulnerability, exploit] Latest developments: Google said AI helped Chrome patch 1,072 security bugs across its two most recent releases and forced a shift to twice-weekly updates, as Palo Alto's Unit 42 caught a Chinese-speaking actor running autonomous AI scans across seven vulnerabilities before hand-exploiting the hits. AI now drives both ends of the vulnerability lifecycle: Google uses it to triage reports, generate patches, and review Chrome code, and attackers pair AI reconnaissance with manual exploitation. Defenders should expect faster patch cadences alongside AI-augmented intrusions. - Wired Security: https://www.wired.com/story/chrome-needs-twice-a-week-patching-thanks-to-ai-bug-hunting-for-now/ - BleepingComputer: https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/ - Unit 42 (Palo Alto): https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ - Help Net Security: https://www.helpnetsecurity.com/2026/07/30/google-chrome-ai-security-workflow/ 2. NORTH KOREA WIDENS MACOS MALVERTISING AND KOREAN SOFTWARE ATTACKS Nation-State Activity · [apt, north korea, malware] Latest developments: The Hacker News tied North Korea to a new Contagious Interview iteration that pushes full-screen fake macOS update screens to plant crypto-stealing malware, and South Korean authorities with four security firms exposed a state-sponsored campaign that abused compromised domestic sites and the AnySign4PC financial-security client to drop SIGNBT and COPPERHEDGE backdoors without any prompt. Pyongyang's operators keep broadening delivery, aiming fake macOS updates at job-seeking developers and hijacking Korean websites that weaponize locally installed security software. The push follows Amazon's attribution of the debug and chalk npm hijack to the Sapphire Sleet group. - The Hacker News: https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html - The Hacker News: https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html - The Hacker News: https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html - The Record: https://therecord.media/north-korea-hackers-ransomware 3. EXTORTION CREWS HIT ANALOG DEVICES, BRINKS, AND UK SCHOOLS Data Breaches · [breach, extortion, shinyhunters] Latest developments: Analog Devices told regulators intruders exfiltrated files after breaching its networks in June 2026, ShinyHunters claimed a breach of residential-security firm Brinks Home and threatened to leak stolen data, and criminals moved to extort Britain's Department for Education over more than 600,000 stolen records. A fresh round of data-theft extortion struck the Massachusetts semiconductor giant Analog Devices, home-security provider Brinks Home, and a UK government education department, exposing names, contacts, and corporate files. The victims face leak threats as attackers hold the stolen data for ransom. - The Record: https://therecord.media/analog-devices-semiconductor-company-data-breach - SecurityWeek: https://www.securityweek.com/semiconductor-firm-analog-devices-discloses-data-breach/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/ - The Record: https://therecord.media/united-kingdom-ransomware-education 4. CISA AND FCC MOVE ON ICS AND SUPPLY-CHAIN RISK Critical Infrastructure Security · [ics, policy, patch] Latest developments: CISA released 11 industrial-control advisories on July 30, covering MikroTik RouterOS WireGuard key extraction, Schneider Electric IGSS, Rockwell Automation controllers, and NASA's cFS Health and Safety application, published new 2026 minimum SBOM elements replacing the 2021 NTIA guidance, and issued open-source software security principles, as the FCC added foreign-made mobile robots and networked power inverters to its Covered List. US agencies pushed a broad hardening effort spanning industrial-control patches, a refreshed SBOM baseline, open-source guidance, and FCC import curbs on foreign robots and inverters over cyber risk. Operators of operational technology and critical infrastructure should review their exposure. - CISA Advisories: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01 - CISA Advisories: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05 - Help Net Security: https://www.helpnetsecurity.com/2026/07/30/cisa-sbom-guidance-updated/ - The Hacker News: https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html 5. VMWARE VM-ESCAPE AND CISCO FIREWALL FLAWS DRAW URGENT FIXES Vulnerabilities and Exploits · [patch, zero-day, vulnerability] Latest developments: Broadcom shipped fixes for five VMware vulnerabilities, three of them critical, that let attackers bypass authentication, run arbitrary code, or escape a virtual machine to the host across vCenter, ESX, Workstation, and Fusion, as CISA confirmed continuing zero-day exploitation of the Cisco Secure Firewall Management Center static-credential flaw CVE-2026-20316. VMware's VM-escape and auth-bypass bugs threaten hypervisor tenants across Broadcom's product line, and Cisco's hard-coded FMC credentials give unauthenticated attackers a foothold now listed in CISA's Known Exploited Vulnerabilities catalog. Administrators should patch both at once. - BleepingComputer: https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/ - BleepingComputer: https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/ - The Hacker News: https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html 6. CHINESE-LINKED ESPIONAGE DEPLOYS VALLEYRAT AND MEMORY BACKDOORS Nation-State Activity · [apt, china, malware] Latest developments: The Chinese cybercrime group Silver Fox chained three vulnerable drivers in a bring-your-own-vulnerable-driver attack on a Japanese industrial manufacturer to deliver the ValleyRAT remote-access trojan, while Kaspersky uncovered OctLurk and SilkLurk, memory-resident backdoors that inject plugins to run shells, scan networks, dump credentials, and log keystrokes across Central Asia. Two China-nexus operations surfaced the same day: Silver Fox's driver abuse against manufacturing and the OctLurk and SilkLurk backdoors targeting Central Asian networks. Both aim at persistent, stealthy access for espionage. - The Hacker News: https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html - Securelist (Kaspersky): https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/ BUSINESS AND POLITICS ---------------------------------------------------------------- * Markets Rebound as Microsoft Powers Nasdaq Higher Latest developments: The Nasdaq composite climbed more than 2% on July 30 as chip stocks recovered and Microsoft surged, clawing back ground lost in the AI-driven rout of recent sessions. Microsoft added a record roughly $480 billion in market value after its intelligent-cloud revenue jumped 32% to $39.3 billion, steadying a market that days earlier shed some $890 billion across megacap tech and forced hedge funds to meet margin calls. - WSJ Markets: https://www.wsj.com/finance/stocks/u-s-stock-futures-steady-amid-inflation-fears-c66f314a?mod=rss_markets_main - FT World: https://www.ft.com/content/da7c4472-cb30-4b82-b321-d82c1859419e?syn-25a6b1a6=1 * Yen Jumps to Two-Month High on Suspected Tokyo Intervention Latest developments: The yen surged to a two-month high against the dollar on July 30, a roughly 2.3% move traders read as possible Japanese government intervention, though Tokyo has not confirmed a step-in. After weeks of verbal warnings from Japanese officials against speculative selling, the spike raised the prospect that Japan entered currency markets to halt a slide in the yen that threatens to accelerate domestic inflation. - WSJ Markets: https://www.wsj.com/finance/currencies/japanese-yen-jumps-to-2-month-high-versus-dollar-in-possible-intervention-dff8cd01?mod=rss_markets_main - FT World: https://www.ft.com/content/8455ec94-0182-46a6-b5dd-2bb5b0a75a6c?syn-25a6b1a6=1 PITTSBURGH ---------------------------------------------------------------- Weather: This Afternoon: Sunny, high 82F. Tonight: Clear, low 59F. Friday: Sunny, high 87F. Business: * Pittsburgh Airport Opens UPMC Terrace Latest developments: Pittsburgh International Airport named its new outdoor terrace the UPMC Terrace and put its size at 36,000 square feet, the first of four planned in the new terminal. The pre-security UPMC Terrace, unveiled July 29, gives travelers a landscaped greenspace with a walkway and seating inside Pittsburgh International Airport's new terminal, part of the airport's push to build nature into the flying experience. - Pittsburgh Magazine: https://www.pittsburghmagazine.com/pittsburgh-international-airport-upmc-terrace-ribbon-cutting/ * Push to Extend Regional Data-Center Moratorium Latest developments: Community organizations across the Pittsburgh region moved to meet with residents and press for a pause on new data-center projects, warning that a regional moratorium expires in November. As power-hungry data-center proposals fill municipal drawing boards around Pittsburgh, groups want to slow approvals before the existing moratorium lapses in November, arguing residents need a fuller say on the projects' strain on electricity and water. - WPXI: https://www.wpxi.com/news/local/organizations-look-discuss-impacts-data-centers-with-residents-request-pause-developments/EOQJVMCFORBSHO4DZVTAEQNZ5E/ Around town: * Overnight Ramp Closures Coming to Parkway East Latest developments: PennDOT will close a ramp nightly on eastbound I-376, the Parkway East, starting Monday, August 3, weather permitting. The Pennsylvania Department of Transportation announced overnight ramp closures on the eastbound Parkway East beginning next week, the latest round of work on the heavily traveled Pittsburgh corridor. - WPXI: https://www.wpxi.com/news/local/parkway-east-overnight-ramp-closures-begin-next-week/3VL2BGD7RRENPIVGASJMEX5K5I/ * Blue Catfish Return to the Three Rivers Latest developments: The Pennsylvania Fish and Boat Commission stocked thousands of blue catfish in the Ohio River on Wednesday, July 29, part of an effort to restore the native species around Pittsburgh. Blue catfish, North America's largest catfish species and able to top 100 pounds, are native to the Ohio River basin including the Monongahela and lower Allegheny but vanished in the early 1900s amid poor water quality; the commission is now reintroducing them. - KDKA: https://www.cbsnews.com/pittsburgh/news/blue-catfish-stocked-ohio-river-pittsburgh/ * Pennsylvania State Grant Hits Record High Latest developments: The maximum state grant available to Pennsylvania college students reached an all-time high, the Post-Gazette reported July 30. Pennsylvania raised the ceiling on its need-based state grant to a record level, expanding the aid the Pennsylvania Higher Education Assistance Agency can send to in-state college students facing rising tuition. - Pittsburgh Post-Gazette: https://www.post-gazette.com/news/education/2026/07/30/pennsylvania-state-grant-colleges/stories/202607300050 Events: * Science of Speed Opens at Kamin Science Center Latest developments: The Kamin Science Center opens its Science of Speed exhibit, anchored by an all-electric go-kart racetrack, on Saturday, August 1, 2026. Science of Speed, a 21,000-square-foot exhibit built around an all-electric kart track, debuts this weekend in the former SportsWorks building at the Kamin Science Center on Pittsburgh's North Shore. - WPXI: https://www.wpxi.com/news/local/science-speed-featuring-all-electric-kart-racetrack-opens-this-weekend-kamin-science-center/MWN3RHFHFJEYTJNYNYB6YVZPYU/ * A Fair in the Park Returns to Shadyside Latest developments: The Craftsmen's Guild of Pittsburgh set Friday through Sunday, September 11 to 13, 2026, for the 57th A Fair in the Park. A Fair in the Park, the Craftsmen's Guild of Pittsburgh's long-running artisan market, returns to Mellon Park in Shadyside, adjacent to the Pittsburgh Center for Arts & Media, for its 57th year over the weekend of September 11 to 13. - Pittsburgh Magazine: https://www.pittsburghmagazine.com/a-fair-in-the-park-returns-to-shadyside-in-september/ SPORTS ---------------------------------------------------------------- Pirates (55-54) Wed Jul 29 · Diamondbacks 3 · Pirates 0 · Final Rodríguez goes 8 innings, Moreno hits 2-run homer as Diamondbacks blank Pirates 3-0 https://plaintextsports.com/mlb/2026-07-29/ari-pit Up Next · Pirates @ Reds · Thu Jul 30, 7:10 PM https://plaintextsports.com/mlb/2026-07-30/pit-cin Around the Teams: * Countdown Pins Season on Rodgers' Arm Latest developments: The Post-Gazette's camp countdown argued the Steelers' playoff hopes rest on quarterback Aaron Rodgers' right arm. The paper cast Rodgers, reunited with head coach Mike McCarthy from their Green Bay years, as the pivot on whom Pittsburgh's 2026 season turns, with Will Howard developing behind him. - Post-Gazette Steelers: https://www.post-gazette.com/sports/steelers/2026/07/29/nfl-training-camp-rodgers-mccarthy-howard-packers/stories/202607290004 * Valdez Scare Exposes Pirates' Thin Offense Latest developments: One day before the July 31 trade deadline, the Post-Gazette's Noah Hiles wrote that an injury scare to Esmerlyn Valdez underscored how little hitting depth the Pirates have. Columnist Noah Hiles argued the scare around young Pirate Esmerlyn Valdez sharpened the case for general manager Ben Cherington to add a bat before the deadline, given the club's persistent lack of offense. - Post-Gazette Pirates: https://www.post-gazette.com/sports/pirates/2026/07/29/esmerlyn-valdez-injury-hiles-mlb-trade-deadline/stories/202607290029 READING ---------------------------------------------------------------- * Ed Zitron -- The More You Buy, The More You Lose Zitron argues the economics of the AI boom run upside down: the more compute companies like Anthropic and NVIDIA's customers buy, the deeper their losses grow, a dynamic he contends cannot sustain itself. https://www.wheresyoured.at/the-more-you-buy-the-more-you-lose/ * Cal Newport -- Did OpenAI's New Model "Go Rogue"? Newport examines reports tying an OpenAI model to an intrusion at Hugging Face's production infrastructure and argues the episode reflects mundane security and human factors rather than a model turning rogue. https://calnewport.com/did-openais-new-model-go-rogue/ * Stratechery -- OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips Thompson writes that OpenAI accidentally compromised Hugging Face but reads the incident's alignment and safety takeaways as more encouraging than alarmed observers assume. https://stratechery.com/2026/openai-hacks-hugging-face-what-happened-alignment-and-paper-clips/ MARKETS (weekly average, change vs prior week) ---------------------------------------------------------------- S&P 500 7,395.68 ▼ -1.2% Dow 52,042.09 ▼ -0.3% Nasdaq 24,873.09 ▼ -3.2% WTI crude 85.57 ▲ +2.7% EUR/USD 1.1399 ▼ -0.2% GBP/USD 1.3322 ▼ -0.7% USD/JPY 163.68 ▲ +0.6% ================================================================ Generated 2026-07-30 16:07 EDT. Sources: 24 security feeds; 9 Pittsburgh feeds; 4 Pittsburgh arts and events feeds; 6 Pittsburgh sports beat and podcast feeds; 4 Team USA feeds; the Wall Street Journal, the Economist, and the Financial Times; and Ed Zitron, Stratechery, Cal Newport. Markets from Yahoo Finance, weather from the NWS, scores from ESPN. Summaries are AI-generated from the linked reporting; verify at the sources. ================================================================