[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"quiz-2026-w38":3},{"id":4,"slug":5,"kind":6,"week_label":7,"title":8,"intro":9,"published_at":10,"is_live":11,"org_name":12,"audience":12,"question_count":13,"questions":14},"daf0da90-fd3b-456e-b9be-4cd3815a8e09","2026-w38","weekly","2026-W38","Security week of September 14 to September 20, 2026","Seven real incidents from the past week: a network enforcement layer hit by a CVSS-10 zero-day, an AI agent that improvised its way into GitHub without being asked, and a CDN supply chain attack that reached more than a hundred thousand sites before anyone noticed. Each one carries a concrete business consequence, not a theoretical one. No signup required, about three minutes, and your first attempt is the one that counts.","2026-09-23T06:00:06.335+00:00",false,null,5,[15,27,39,51,63],{"index":16,"id":17,"category":18,"scenario":19,"question":20,"options":21,"regulation_refs":26},0,"a7f85074-7799-4054-94fd-700eb21a857e","Access control","Cisco's Identity Services Engine (ISE) is your organization's network access control backbone: it makes the allow\u002Fdeny decisions for every device trying to join the corporate network. CVE-2026-76460, a CVSS 10.0 authentication bypass in ISE's web management API, is confirmed actively exploited and now on CISA's KEV catalog. Your CISO asks you to characterize the actual blast radius before declaring an emergency change window tonight.","What is the most accurate description of why a successful exploit of this flaw is worse than a typical application-layer breach?",[22,23,24,25],"Attackers can modify network access policies and extract credentials from the enforcement layer itself, invalidating the trust decisions every downstream system relies on.","Because ISE is a Cisco product, the vendor bears liability for any resulting breach under product security regulations, reducing internal legal exposure.","The CVSS score of 10.0 guarantees exploitability from the internet, so all internet-facing systems must be treated as already compromised.","Authentication bypass flaws are self-limiting because attackers still need valid credentials to pivot beyond the initial access point.",[],{"index":28,"id":29,"category":30,"scenario":31,"question":32,"options":33,"regulation_refs":38},1,"d3ea8a4a-3b87-474d-8c6f-5aace3dda53f","Supply chain","Brevo, a CRM and digital marketing platform, suffered a supply chain attack when attackers stole a Cloudflare API key and used it to create a Cloudflare Worker that modified content at the CDN edge. Malicious ClickFix scripts were injected into Brevo's own domains and into the embedded JavaScript files served to customer sites for approximately five and a half hours. Your company embeds third-party CRM or analytics JavaScript on your public-facing web properties.","What control, if implemented before this incident, would have most directly limited the damage to your visitors during those five and a half hours?",[34,35,36,37],"Requiring Brevo to hold a SOC 2 Type II certification, which audits CDN key management controls and would have prevented the API key theft.","Running a daily integrity scan of your own web server files to detect unauthorized changes to locally hosted assets.","Blocking the Brevo domains at your perimeter firewall immediately after the advisory, which would have stopped script delivery to internal users.","A strict Content Security Policy scoped to known-good script hashes or origins, preventing the modified CDN-delivered script from executing in visitor browsers.",[],{"index":40,"id":41,"category":42,"scenario":43,"question":44,"options":45,"regulation_refs":50},2,"81125ed3-e455-47aa-9468-11c382ee70b6","Technical","A critical unauthenticated RCE vulnerability, CVE-2026-58138, in Orkes Conductor is being actively exploited. Attackers submit malicious workflow definitions containing JavaScript or Python expressions that execute arbitrary OS commands via unsandboxed GraalVM evaluators. Fortinet observed a significant spike in attack attempts originating from multiple countries. Your organization uses Orkes Conductor to orchestrate internal data processing pipelines, and the Conductor API is reachable from your development network.","Until the patch to version 3.30.2 is applied, what is the most effective interim control to reduce exposure without halting all pipeline operations?",[46,47,48,49],"Disable all JavaScript and Python in workflow definitions organization-wide and rewrite affected pipelines using only built-in Conductor task types.","Require workflow submissions to pass through a WAF rule that blocks requests containing common shell metacharacters before they reach Conductor.","Restrict network access to the Conductor workflow definition API endpoints so only authorized internal CI\u002FCD systems can reach them, eliminating unauthenticated external attack surface.","Increase logging verbosity on GraalVM to capture attempted injections, allowing the security team to detect and respond before payloads execute.",[],{"index":52,"id":53,"category":54,"scenario":55,"question":56,"options":57,"regulation_refs":62},3,"2c013468-8979-46d4-b0b5-9920c4554aad","Nation-state and social engineering","A joint advisory from the US, Japan, Germany, and Australia describes WaterPlum, a North Korean threat group linked to the Contagious Interview campaign. Between December 2025 and July 2026, the group compromised over 30,000 devices by posing as prospective employers at AI and crypto companies, targeting software developers and IT professionals seeking jobs. The infection vector is malicious npm packages delivered as part of a fake technical interview process, resulting in theft of more than $10.7 million in cryptocurrency and exfiltration of credentials.","A developer on your team mentions they completed a technical coding challenge sent by a recruiter from an AI startup last week and ran the provided npm package locally. What is your most important immediate action?",[58,59,60,61],"Ask the developer to identify the recruiter's LinkedIn profile and verify the company is real before taking any further technical steps.","Treat the developer's workstation as potentially compromised: isolate it, preserve forensic state, and begin credential rotation for every service the developer accessed from that machine.","Scan the developer's machine with your current endpoint detection tool and clear it for use if no malware signature is detected.","Report the recruiter's contact details to your HR team so they can add the company to a vendor blocklist and warn other employees.",[],{"index":64,"id":65,"category":66,"scenario":67,"question":68,"options":69,"regulation_refs":74},4,"3eb0b38a-0ecd-4605-8ecd-ae7a367583dc","Regulatory","CISA added three Linux kernel vulnerabilities, CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, to its Known Exploited Vulnerabilities catalog this week, covering memory disclosure, denial-of-service, and privilege escalation. Federal agencies are subject to Binding Operational Directive 26-04, which mandates patching these specific flaws by September 21, 2026. Your organization is a federal contractor that operates Linux-based systems processing government data under a contract that references BOD 26-04 compliance.","The patch window closes in 48 hours and your change management process requires a five-day lead time. What is the correct next step?",[70,71,72,73],"Document the five-day process requirement as a compensating control and submit a plan of action and milestones to your contracting officer, which satisfies BOD 26-04 for contractors.","Apply the patches immediately under an emergency change process, notify your contracting officer of the BOD deadline and the emergency action taken, and document the deviation from standard change management.","Request a deadline extension from CISA through the standard POA&M process, as BOD deadlines for contractors are advisory rather than mandatory.","Prioritize patching the privilege escalation flaw first since it carries the highest exploitability risk, and defer the others until the standard change window opens.",[]]