[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"current-quiz":3},{"id":4,"slug":5,"kind":6,"week_label":7,"title":8,"intro":9,"published_at":10,"is_live":11,"question_count":12,"questions":13},"b4890cda-6469-4860-b78e-ecaa0dc37919","2026-w33","weekly","2026-W33","Security week of August 10 to 16, 2026","Five questions from last week in security. Each one is a real incident, and each answer explains what made it a business risk and what doing it right looks like. No signup, about three minutes, and your first attempt is the one that counts.","2026-08-19T06:00:00+00:00",true,5,[14,25,36,47,58],{"index":15,"id":16,"category":17,"scenario":18,"question":19,"options":20},0,"1a2c438a-831e-46e6-9c76-09c2713ceeb4","Technical","Last week a zero-day called ShieldBreak was disclosed in Microsoft Defender. Exploiting it grants SYSTEM privileges, and a public proof of concept claims it bypasses the first patch. Microsoft is still working on a complete fix.","What makes this a boardroom problem and not just another patching ticket?",[21,22,23,24],"Defender is free, so there is no vendor SLA to lean on","The vulnerable component runs with maximum privileges on virtually every Windows endpoint in the company, so one exploit is an enterprise-wide privilege escalation","Antivirus products cannot be updated remotely","SYSTEM privileges only matter on servers, not workstations",{"index":26,"id":27,"category":28,"scenario":29,"question":30,"options":31},1,"79587175-d6eb-4d43-8519-b28a4536960d","Supply chain","The Trivy security scanner was compromised last week, and the poisoned version reached roughly 2,500 organizations before it was caught. Trivy is itself a tool teams run to find vulnerabilities.","What is the uncomfortable lesson for every engineering organization?",[32,33,34,35],"Open source security tools should be replaced with commercial ones","Scanners are read-only, so a compromised scanner is harmless","The tools you trust to check your software are software too, and they usually run with deep access inside your build pipeline","Only small vendors get compromised, so choose large ones",{"index":37,"id":38,"category":39,"scenario":40,"question":41,"options":42},2,"bd524ee2-e683-474b-9648-b2e7342e499a","Privacy and fines","The City-Forum campaign has quietly pulled customer data out of corporate Salesforce and ServiceNow portals since March 2025. No vulnerability was exploited: the portals were simply configured to allow more access than anyone intended.","Why does the phrase no vulnerability was exploited make this worse for the affected companies, not better?",[43,44,45,46],"It does not matter, misconfigurations count as force majeure","Regulators treat an exploited misconfiguration as a failure of basic due care, which is exactly what GDPR Article 32 fines are written for","Misconfigured SaaS portals are legally the vendor's problem","Data taken through a misconfiguration does not count as a breach",{"index":48,"id":49,"category":50,"scenario":51,"question":52,"options":53},3,"c88059f7-d92d-4f7c-9de8-c929bd90c415","Patch management","CVE-2026-59310, a VMware vCenter remote code execution flaw, went from disclosure to active APT exploitation across 47 countries within days. The same week, Adobe Commerce and SAP Commerce flaws were both exploited within days of their patches being released.","What has actually changed about patching, and what should follow from it?",[54,55,56,57],"Nothing has changed, a 30-day patch cycle is still considered fast","The patch release itself is now the starting gun: attackers diff the fix and weaponize it faster than most change windows open","Only systems that miss patches entirely get attacked","Virtualization infrastructure is rarely targeted, so vCenter can wait",{"index":59,"id":60,"category":61,"scenario":62,"question":63,"options":64},4,"f691163d-b750-4f3f-aaf0-598933b3a411","Third-party risk","ShipMonk, a fulfillment provider, was breached last week and the shipping records of 14,000 Trezor hardware-wallet customers leaked. The data was only names and home addresses.","Why is this a serious incident rather than a trivial one?",[65,66,67,68],"It is not serious, names and addresses are effectively public anyway","Context makes data sensitive: a list of people who own crypto hardware wallets, with home addresses, is a ready-made target list for phishing and physical theft","Trezor should simply have shipped from anonymous PO boxes","Fulfillment providers fall outside GDPR, so there is no exposure"]