Archive snapshot

Fri, Jul 24 · 12:00 PM CDT

Archived briefing content rendered inside the ACSP site experience.

Archived briefing

Snapshot overview

Generated Fri, Jul 24 · 12:00 PM CDTWindow last 6 hours

Top line

Coverage now updates on a rolling 6-hour window, while NVD entries come from the live API using a last-24-hours modified window and are sorted by severity.

Fast take

News stays on the current 6-hour slice, videos now use the last 24 hours, and NVD uses the API instead of the traditional feed to better match the live site behavior.

Top stories
5
Worth skimming
5
Tracked videos
1
NVD vulnerabilities
25

Top stories

Fri, 24 Jul 2026 20:42:35 +0530

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

9.8/10 · Must read/watch
The Hacker Newsmalwareai

Summary
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns design

Fri, 24 Jul 2026 19:45:21 +0530

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

9.8/10 · Must read/watch
The Hacker Newsvulnaiidentity

Summary
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Control

Fri, 24 Jul 2026 17:23:55 +0530

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

9.7/10 · Must read/watch
The Hacker Newsvulnaiidentity

Summary
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's

Fri, Jul 24 · 12:00 PM CDT

ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check Point

9.4/10 · Must read/watch
Infosecurity Magazinegeneral

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Fri, Jul 24 · 12:00 PM CDT

Ransomware Attacks Targeting Universities on the Rise

9.2/10 · Must read/watch
Infosecurity Magazinemalware

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Worth skimming

Fri, Jul 24 · 12:00 PM CDT

Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors

9.0/10 · Must read/watch
Infosecurity Magazineidentity

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Fri, 24 Jul 2026 17:00:00 +0530

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

9.0/10 · Must read/watch
The Hacker Newsai

Summary
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so man

Fri, Jul 24 · 07:00 AM CDT

My security camera shipped a GitHub admin token in its login page

8.4/10 · Worth your time
Hacker Newssupply-chain

Summary
Surfaced from Hacker News front page during collection run. Freshness on HN: 5 hours ago.

Fri, Jul 24 · 10:00 AM CDT

Government orders GitHub to remove Bluetooth-based chat app Bitchat: Jack Dorsey

8.4/10 · Worth your time
Hacker Newssupply-chainpolicy

Summary
Surfaced from Hacker News front page during collection run. Freshness on HN: 2 hours ago.

Fri, 24 Jul 2026 17:15:17 +0530

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

8.1/10 · Worth your time
The Hacker Newsidentity

Summary
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and