Archive snapshot

Fri, Jul 17 · 06:00 PM CDT

Archived briefing content rendered inside the ACSP site experience.

Archived briefing

Snapshot overview

Generated Fri, Jul 17 · 06:00 PM CDTWindow last 6 hours

Top line

Coverage now updates on a rolling 6-hour window, while NVD entries come from the live API using a last-24-hours modified window and are sorted by severity.

Fast take

News stays on the current 6-hour slice, videos now use the last 24 hours, and NVD uses the API instead of the traditional feed to better match the live site behavior.

Top stories
5
Worth skimming
5
Tracked videos
0
NVD vulnerabilities
25

Top stories

Sat, 18 Jul 2026 00:24:51 +0530

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

9.7/10 · Must read/watch
The Hacker Newssupply-chainai

Summary
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of

Fri, Jul 17 · 06:00 PM CDT

Government Agencies Falling Victim to Ransomware Daily, Warns Study

9.4/10 · Must read/watch
Infosecurity Magazinemalwareaipolicy

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Fri, Jul 17 · 06:00 PM CDT

23andMe Faces New Security Mandates in $18m Data Breach Settlement

9.0/10 · Must read/watch
Infosecurity Magazinegeneral

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Fri, Jul 17 · 06:00 PM CDT

CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities

8.9/10 · Worth your time
Infosecurity Magazinevuln

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Fri, Jul 17 · 06:00 PM CDT

The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat

8.7/10 · Worth your time
Infosecurity Magazinemalware

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Worth skimming

Fri, 17 Jul 2026 22:42:23 +0530

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

8.6/10 · Worth your time
The Hacker Newsai

Summary
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the imag

Fri, Jul 17 · 06:00 PM CDT

Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass

8.2/10 · Worth your time
Infosecurity Magazinegeneral

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Sat, 18 Jul 2026 02:50:10 +0530

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

8.1/10 · Worth your time
The Hacker Newsvulnidentity

Summary
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced update

Sat, 18 Jul 2026 01:50:53 +0530

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

8.1/10 · Worth your time
The Hacker Newsvuln

Summary
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no a

Fri, Jul 17 · 05:29 PM CDT

Kaiser nurses say AI, workplace surveillance are making their jobs, care worse

8.1/10 · Worth your time
Hacker Newsai

Summary
Surfaced from Hacker News front page during collection run. Freshness on HN: 31 minutes ago.