[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"quiz-2026-w37":3},{"id":4,"slug":5,"kind":6,"week_label":7,"title":8,"intro":9,"published_at":10,"is_live":11,"org_name":12,"audience":12,"question_count":13,"questions":14},"2c91d618-ea59-4b27-b56d-a264ec50685c","2026-w37","weekly","2026-W37","Security week of September 7 to 13, 2026","Five questions from last week in security. Each one is a real incident, and each answer explains what made it a business risk and what doing it right looks like. No signup, about three minutes, and your first attempt is the one that counts.","2026-09-15T09:07:33.815+00:00",false,null,5,[15,27,39,51,63],{"index":16,"id":17,"category":18,"scenario":19,"question":20,"options":21,"regulation_refs":26},0,"1942f1be-c354-4832-9e07-6b878579f64f","AI risk","Last week researchers documented state-sponsored and criminal groups using Claude, ChatGPT and OpenAI agents to automate exploitation, rebuild malware, and generate roughly one million personalized phishing emails in three days.","What has actually changed for defenders now that attackers have production-grade AI?",[22,23,24,25],"Very little: AI-written phishing still contains tells, so trained staff and existing filters catch it at the same rate","The economics flipped: attacks that used to need scarce human effort are now cheap and personalized at scale, so volume and quality both rise at once","The main change is legal, since AI vendors are now liable for misuse of their models","It mostly affects consumers, because enterprises with email gateways are insulated from AI-generated campaigns",[],{"index":28,"id":29,"category":30,"scenario":31,"question":32,"options":33,"regulation_refs":38},1,"dbbe8940-93e0-4904-bcab-91f2cbf6cbe9","Patch velocity","GitLab's CVSS 10.0 path-traversal flaw (CVE-2026-85706) was exploited in the wild within 24 hours of disclosure. It joined Artifactory, PaperCut, Cisco FMC, Check Point VPN and NetScaler on CISA's KEV catalog in a single week.","What should a week like this change about how an organization prioritizes patching?",[34,35,36,37],"Regulators price the absence of care, so the priority is documentation of the patch schedule rather than its speed","Nothing structural: six critical flaws in a week is normal variance, and monthly cycles still absorb it","The disclosure-to-exploitation window has collapsed to hours for internet-facing systems, so those need an emergency lane measured in hours or days, not the standard cycle","The priority is the vendor with the highest CVSS, so GitLab is patched first and the rest wait for the next window",[],{"index":40,"id":41,"category":42,"scenario":43,"question":44,"options":45,"regulation_refs":50},2,"1f3b0866-4e44-4334-ada1-fa272dd5a08c","Third-party risk","A social-engineering attack on a third-party contractor exposed 4.1 million AdaptHealth healthcare records. The same week, IDScan confirmed 153 million driver's-license scans were stolen from its cloud platform.","Both breaches happened at a supplier, not at the brand-name company. Why does that make it worse, not better, for the company whose customers are affected?",[46,47,48,49],"It does not: liability and notification duties transfer to the contractor once data is in their custody","The company still owns the customer relationship and the regulatory duty, but no longer controls the security of the data, and its customers will blame the name they recognize","Breaches at suppliers are treated as force majeure, so the exposure is mainly reputational and short-lived","Healthcare and identity data lose value once disclosed, so a supplier breach carries lower long-term risk",[],{"index":52,"id":53,"category":54,"scenario":55,"question":56,"options":57,"regulation_refs":62},3,"58fae5ac-6a5b-4700-97ba-b2484be58031","Endpoint and browser","The BlueMoon exploit kit chains a Chrome zero-day with a Windows zero-day and is being rapidly adopted by Chinese espionage groups, with analysts expecting near-term proliferation to financially motivated actors.","A browser-plus-OS zero-day chain needs no user mistake beyond visiting a page. What does that imply for defensive strategy?",[58,59,60,61],"Because the attack starts in the browser and needs no click, defense has to assume endpoints will be compromised and invest in detection, isolation and fast response, not just prevention","User training remains the primary control, since the chain still starts with the user choosing to browse","Air-gapping the affected browsers is the only viable mitigation until both vendors patch","The risk is limited to espionage targets, so commercial organizations can treat it as low priority",[],{"index":64,"id":65,"category":66,"scenario":67,"question":68,"options":69,"regulation_refs":74},4,"82bbfa08-154a-49b7-a67e-296f7d9be014","Identity","ShinyHunters used stolen police-account credentials to abuse a law-enforcement data-request channel, obtaining information they were not entitled to. The credentials worked because the trusted account behind them had not been secured against reuse.","The attackers exploited a trusted process, not a software flaw. Why is that harder to defend than a vulnerability?",[70,71,72,73],"It is easier, because a trusted process has audit logs that a software exploit would bypass","The risk is contained because law-enforcement channels are used too rarely for abuse to scale","Trusted processes are covered by the vendor's controls, so the fix belongs to whoever operates the channel","There is nothing to patch: a legitimate credential used through a legitimate channel looks like authorized activity, so the only defense is stronger authentication and behavioral checks on the account itself",[]]