[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"quiz-2026-w39":3},{"id":4,"slug":5,"kind":6,"week_label":7,"title":8,"intro":9,"published_at":10,"is_live":11,"org_name":12,"audience":12,"question_count":13,"questions":14},"f1fa0945-dd59-49ba-8a66-8c7870307b49","2026-w39","weekly","2026-W39","Security week of September 21 to 27, 2026","Seven real incidents from this week: a URL-encoding trick that made WAF coverage worthless overnight, compromised GitHub Actions that reactivated without anyone pushing new code, and AI agents quietly pillaging government portals for months. Each one translates directly to money, downtime, or regulatory exposure. No signup, about three minutes, first attempt counts.\n\nThese questions were generated by AI from the week’s reported security incidents and checked against their original sources.","2026-09-27T23:59:59+00:00",false,null,5,[15,27,39,51,63],{"index":16,"id":17,"category":18,"scenario":19,"question":20,"options":21,"regulation_refs":26},0,"b0d866f4-54ed-4a99-bcea-6802abf22eb8","Vulnerability management","ShinyHunters (UNC6240) resumed mass exploitation of Oracle PeopleSoft CVE-2026-35273 after WAF vendors had published blocking rules for the vulnerable PSEMHUB endpoint. The group bypassed those rules by URL-encoding characters in their requests, deploying web shells and the SIDEEYE backdoor across education, healthcare, and government targets. Your CISO points to the existing WAF rule set and asks why you are escalating the patch request given that the endpoint is already blocked.","What is the most accurate explanation of why WAF coverage does not close this risk?",[22,23,24,25],"The WAF vendor has not yet published an updated signature for the encoding variant, so the gap is temporary and will close without a patch once the vendor ships the update.","URL-encoding bypass only works against cloud-hosted WAFs; on-premises WAF appliances normalize encoding before inspection and are not affected.","WAF rules block the known request pattern, but encoding variants are a well-documented bypass class that rule sets routinely fail to cover exhaustively, making WAF a detection layer rather than a patch substitute.","WAF rule sets are designed around known-bad request signatures and cannot reliably inspect encoding variants that alter the signature while preserving the exploit semantics, so the inspection layer sees a permissible request even when the underlying payload is identical.",[],{"index":28,"id":29,"category":30,"scenario":31,"question":32,"options":33,"regulation_refs":38},1,"5f4ee65e-a490-4790-90dc-2d056e20173a","Supply chain","Two GitHub Actions, actions-cool\u002Fissues-helper and actions-cool\u002Fmaintain-one-comment, were disabled in May 2026 after being compromised in the Mini Shai-Hulud credential-harvesting campaign. On September 16, repository maintainers re-enabled them without removing the malicious tags. Any workflow referencing those actions by mutable tag automatically resumed executing the payload, exposing an estimated 15,000 dependent repositories for over a week.","What change to how your pipelines reference GitHub Actions would have prevented this re-enablement from affecting your build environment?",[34,35,36,37],"Adding the two action repositories to a deny list in your firewall so outbound requests to those repos are blocked during CI runs.","Pinning all GitHub Actions references to a specific commit SHA rather than a mutable version tag, so re-enabling the repository cannot silently change what code executes.","Requiring that all third-party actions pass a manual security review before each workflow run, which would catch the malicious tag on re-activation.","Enabling GitHub's dependency graph and Dependabot alerts, which notify maintainers when a dependency repository changes status or is re-enabled.",[],{"index":40,"id":41,"category":42,"scenario":43,"question":44,"options":45,"regulation_refs":50},2,"410650cc-1ec8-4aad-bae1-9c2d72090594","AI risk","A financially motivated, Chinese-speaking threat actor used three AI agents named Strix, Cairn, and Hermes to conduct an automated campaign against online retailers from at least July 2026. The agents handled vulnerability scanning, exploitation, and skimmer deployment autonomously, compromising at least 27 companies and stealing over 600,000 credit card records. The total operational cost for the attacker was estimated at $12,000 to $18,000.","What does the cost-to-impact ratio of this campaign most directly imply about the threat model for mid-market e-commerce operators?",[46,47,48,49],"Mid-market retailers are now realistic targets for sophisticated, automated attacks at a price point that makes broad opportunistic targeting economically rational for threat actors.","The campaign confirms that AI-assisted attacks primarily succeed against retailers lacking PCI DSS compliance, so achieving and maintaining certification is the most effective risk reduction.","The low operational cost indicates the attacker used commodity tools rather than custom malware, meaning existing endpoint detection platforms should already flag the activity.","The scale of card theft suggests the attacker had prior insider access to payment systems, making third-party background screening the most relevant preventive control.",[],{"index":52,"id":53,"category":54,"scenario":55,"question":56,"options":57,"regulation_refs":62},3,"b21f0bb9-039f-4cec-8105-3a76701d16f9","Technical","Citrix confirmed that two critical NetScaler ADC and Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited as zero-days. Both vulnerabilities allow unauthenticated attackers to execute arbitrary commands or cause denial-of-service conditions. CISA added both to its KEV catalog and security firm watchTowr reported on September 26 that patches were not yet available at the time of initial disclosure, leading some administrators to take appliances offline.","Before vendor patches are available for an actively exploited zero-day in a network edge appliance, what is the most defensible interim action?",[58,59,60,61],"Apply virtual patching rules from your WAF vendor, which will block known exploit patterns for the vulnerable endpoint until Citrix releases an official fix.","Restrict management interface access to internal networks only and consider taking exposed appliances offline if the business function they support can tolerate the downtime.","Enable enhanced logging on the NetScaler appliances to detect exploitation attempts in real time, allowing the security team to respond before an attacker achieves persistence.","Rotate all service account credentials associated with NetScaler and revoke active VPN sessions to invalidate any tokens that may have been harvested by the exploits.",[],{"index":64,"id":65,"category":66,"scenario":67,"question":68,"options":69,"regulation_refs":74},4,"a4943866-aa4c-41ca-a75f-94975c14d0a8","Regulatory","CISA added Microsoft SharePoint CVE-2026-65660 to its Known Exploited Vulnerabilities catalog with a federal agency patch deadline of September 28, 2026. The vulnerability requires authentication but allows arbitrary code execution. Your organization is a federal contractor whose ATO requires compliance with CISA KEV remediation timelines under BOD 26-04. Your change advisory board meets weekly and the next scheduled window is October 3.","What is the correct organizational response when a KEV-listed patch deadline falls inside your standard change management cycle?",[70,71,72,73],"Document the conflict between the BOD deadline and your change management policy, notify your AO, and invoke your emergency change procedure to patch before September 28.","Submit the change request at the next scheduled CAB meeting on October 3 with a risk acceptance memo noting the deadline miss, which satisfies audit requirements.","Apply the SharePoint patch immediately in production without a change request, since BOD 26-04 supersedes internal change management policy for all federal contractors.","Isolate the SharePoint server from external access by September 28 to meet the spirit of the BOD deadline and schedule the formal patch through the standard October 3 window.",[]]