[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"quiz-2026-w34":3},{"id":4,"slug":5,"kind":6,"week_label":7,"title":8,"intro":9,"published_at":10,"is_live":11,"org_name":12,"audience":12,"question_count":13,"questions":14},"beb1d6d6-de2b-4458-bdac-2e7e62c749b7","2026-w34","weekly","2026-W34","Security week of August 17 to 23, 2026","Five questions from last week in security. Each one is a real incident, and each answer explains what made it a business risk and what doing it right looks like. No signup, about three minutes, and your first attempt is the one that counts.","2026-08-26T06:00:05.265+00:00",false,null,5,[15,27,39,51,63],{"index":16,"id":17,"category":18,"scenario":19,"question":20,"options":21,"regulation_refs":26},0,"9e7f6f8c-d36e-4c59-b2ce-a5c61363b429","Identity","Microsoft Entra ID took a CVSS 10.0 flaw into CISA's KEV catalog this week, with confirmed exploitation in the wild. Entra ID is the identity provider gating sign-ins for a large share of the world's companies.","A maximum-severity flaw in the identity provider is a different class of emergency than one in any single application. Why?",[22,23,24,25],"In practice it is not different: identity providers have layered defenses, so individual application flaws are usually easier to exploit","Whoever controls the identity provider inherits every trust decision built on it: every SSO app, every token, every conditional-access rule downstream","Cloud identity providers cannot be patched by customers, so the only real mitigation is switching vendors","The main risk is downtime: if the identity provider goes offline, nobody can log in and productivity stops",[],{"index":28,"id":29,"category":30,"scenario":31,"question":32,"options":33,"regulation_refs":38},1,"cf09af6a-e4c0-49ad-9ef8-7186b6333aa0","Supply chain","North Korea's Sapphire Sleet poisoned popular Rust crates with a combined 245 million downloads. The malicious versions executed infostealers at build time, on developer machines and CI runners.","What makes build-time execution in a package registry nastier than a malicious app in an app store?",[34,35,36,37],"Very little: build machines are usually sandboxed, so build-time code is contained by default","Compiled languages make payloads easier to detect, so the exposure window is short","It mostly affects hobby projects, since enterprises pin dependencies and mirror their registries","The code runs where your secrets live: developer laptops and CI runners hold cloud keys, signing keys and repo tokens, and no end user ever has to install anything",[],{"index":40,"id":41,"category":42,"scenario":43,"question":44,"options":45,"regulation_refs":50},2,"cf989244-5189-4747-a57c-86f68c1ea683","Regulation","Two weeks ago Australia's prudential regulator APRA began penalty proceedings against Bendigo and Adelaide Bank, with the bank agreeing to pay 8 million Australian dollars. The weaknesses were found by the bank's own penetration test in 2020 and were still unfixed when an attacker used exactly those weaknesses in 2023.","Why does the regulator's case barely depend on the attack itself?",[46,47,48,49],"Regulators price the absence of basic care: a documented, unfixed finding is the violation, and the attack merely proves the point","Because the attack caused no customer losses, only the bank's reputation was harmed","Australian law fines banks for being attacked regardless of their controls, so the pentest history is irrelevant","The case is really about the pentest vendor's liability for not escalating the findings",[],{"index":52,"id":53,"category":54,"scenario":55,"question":56,"options":57,"regulation_refs":62},3,"eaba28a7-d8ce-4ec6-96b4-be114de8442e","AI governance","Multiple organizations reported real Sev-1 incidents this week caused by their own AI agents: automation acting with broad permissions, no owner and no review. Analysts called it a governance gap with no patch available.","Why does the phrase no patch available fit this problem better than it fits most vulnerabilities?",[58,59,60,61],"Because AI vendors refuse to fix agent frameworks, patching is contractually impossible","Because agents run in the vendor's cloud, customers cannot influence their behavior at all","Because the flaw is a process, not code: an agent doing exactly what it was allowed to do, with permissions nobody scoped and actions nobody reviews, cannot be fixed by an update","Because AI models change weekly, any fix is obsolete before it ships",[],{"index":64,"id":65,"category":66,"scenario":67,"question":68,"options":69,"regulation_refs":74},4,"8f9ad646-49e3-4944-bdf3-34ec9d8908c7","Critical infrastructure","AI-generated exploit scripts were observed targeting Siemens S7 PLCs in US critical infrastructure this week. The scripts were not sophisticated; the point is that writing them no longer requires OT expertise.","If AI makes mediocre exploits cheap and abundant, what actually changes for defenders?",[70,71,72,73],"Little: mediocre exploits fail against modern systems, so this is mostly noise","The population of attackers who can try you explodes, so exposure and hygiene failures that once needed a rare specialist now get found by anyone","Defense must adopt AI at equal scale first; until then no effective countermeasure exists","Critical infrastructure is air-gapped by regulation, so internet-facing exposure is not the real issue",[]]