Archive snapshot

Wed, Jul 29 · 12:00 PM CDT

Archived briefing content rendered inside the ACSP site experience.

Archived briefing

Snapshot overview

Generated Wed, Jul 29 · 12:00 PM CDTWindow last 6 hours

Top line

Coverage now updates on a rolling 6-hour window, while NVD entries come from the live API using a last-24-hours modified window and are sorted by severity.

Fast take

News stays on the current 6-hour slice, videos now use the last 24 hours, and NVD uses the API instead of the traditional feed to better match the live site behavior.

Top stories
5
Worth skimming
5
Tracked videos
2
NVD vulnerabilities
25

Top stories

Wed, Jul 29 · 08:00 AM CDT

Disrupting supply chain attacks on NPM and GitHub Actions

9.8/10 · Must read/watch
Hacker Newssupply-chainai

Summary
Surfaced from Hacker News front page during collection run. Freshness on HN: 4 hours ago.

Wed, Jul 29 · 12:00 PM CDT

Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows

9.4/10 · Must read/watch
Infosecurity Magazinevulnai

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Wed, Jul 29 · 12:00 PM CDT

LogoKit Phishing Kit Screenshots Victim Sites in Real Time

9.4/10 · Must read/watch
Infosecurity Magazinegeneral

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Wed, Jul 29 · 12:00 PM CDT

The Average Cost of a Data Breach Rises to $5 Million

9.4/10 · Must read/watch
Infosecurity Magazinegeneral

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Wed, 29 Jul 2026 21:09:30 +0530

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

8.6/10 · Worth your time
The Hacker Newsvulnaiidentity

Summary
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-5

Worth skimming

Wed, 29 Jul 2026 19:12:57 +0530

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

8.6/10 · Worth your time
The Hacker Newsai

Summary
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecur

Wed, Jul 29 · 12:00 PM CDT

Researchers Warn of AI-Enhanced Phone Fraud Ecosystem

8.2/10 · Worth your time
Infosecurity Magazineai

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Wed, Jul 29 · 12:00 PM CDT

NCSC Publishes Guidance to Aid Incident Response and Recovery

8.2/10 · Worth your time
Infosecurity Magazineaipolicy

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Wed, Jul 29 · 12:00 PM CDT

Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack

8.2/10 · Worth your time
Infosecurity Magazinegeneral

Summary
Collected from the Infosecurity Magazine news page during the latest run.

Wed, 29 Jul 2026 21:01:15 +0530

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

8.1/10 · Worth your time
The Hacker Newsvulnidentity

Summary
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS s