| DEAFNEWS |
DEAFLETTER // SECURITY BRIEF |
|
|
VERIFIED SIGNALS // EDITORIAL SNAPSHOT
DeafLetter — week 37AI AppSec: Scanners Agree on Just 5%, Triage Costs $128,000 | 01 // LEAD STORY LEAD // 01 AI AppSec: Scanners Agree on Just 5%, Triage Costs $128,000Contrast Security's AppSec Overflow 2026 report reveals three AI scanners testing the same codebase agree on only 5% of findings, while a single scanner reproduces just 17% of its own results across runs. Scanning 2 million lines costs roughly $315 in API fees; triaging the output costs about $128,000 — a 400-to-1 asymmetry. OPEN REPORT → |
| 02 // THREE SIGNALS SIGNAL // 02 Dark Web: 153 Million Driver's Licenses for Sale, FBI Investigates IDScan.netThe Nexus dark web platform claims 153 million U.S. and Canadian driver's licenses. KrebsOnSecurity empirically verified records and traced the chain to IDScan.net, which processes over 21 million identity checks monthly. The FBI's New Orleans field office has opened an official inquiry. READ THE ANALYSIS → | SIGNAL // 03 Google Patches Chrome Zero-Day: Urgent Update for 3 Billion UsersGoogle released Chrome 152.0.7977.82 to fix CVE-2026-85046, an actively exploited zero-day in the V8 engine with a CVSS score of 8.8. The vulnerability allows remote code execution in the renderer process via a crafted HTML page. READ THE ANALYSIS → | SIGNAL // 04 FalconFlank PoC: Zero-Day Privilege Escalation in CrowdStrike Falcon SensorA researcher has publicly released a proof-of-concept exploiting the Office macro remediation feature to escalate privileges in the EDR sensor. CrowdStrike has not yet responded. READ THE ANALYSIS → |
| 03 // CVES AND PATCHES CVE_PATCH // 05 JetBrains: TeamCity Flaw Exposed Cadence Service DataJetBrains disclosed a breach of its Cadence cloud service after attackers exploited an unpatched TeamCity server vulnerable to CVE-2026-63077. The intrusion, which occurred between August 8 and 24, 2026, exposed a 2024 backup containing AWS IAM credentials, user data, and potentially synchronized PyCharm source code. READ THE ANALYSIS → | CVE_PATCH // 06 Medusa Hits 500 Victims and Sells Time as a ServiceCISA, FBI, and HHS updated the joint advisory AA25-071A in August 2026: Medusa ransomware has struck over 500 U.S. critical infrastructure organizations, adding roughly 200 victims in 18 months since the 300+ counted in March 2025. The figure reflects a mature criminal model where extortion has become a commercial service with negotiable terms, including the option to buy countdown extensions at $10,000 per day. READ THE ANALYSIS → | CVE_PATCH // 07 OWASP Launches OASIS: AI and AppSec Join Forces Against Open-Source VulnerabilitiesOWASP unveiled OASIS on August 26, 2026, a community project that pairs AI-generated patches with human AppSec validation to accelerate remediation in open-source software. READ THE ANALYSIS → | CVE_PATCH // 08 MikroTrick Hits RouterOS: Active Attacks and First Coordinated LLM-Assisted DisclosureCERT Polska uncovers the MikroTrick chain — six vulnerabilities in MikroTik RouterOS, two critical for unauthenticated remote control. Active attacks confirmed since September 2, 2026. READ THE ANALYSIS → | CVE_PATCH // 09 Docker CVE-2026-34040: Ten-Year AuthZ Bypass via a Single Padded HTTP RequestCVE-2026-34040 lets attackers bypass Docker Engine authorization plugins with a single HTTP request exceeding 1 MB. The patch landed on March 25, 2026. READ THE ANALYSIS → |
| 04 // THE GUIDE GUIDE // 10 Foundations of Ethical Security Testing with Python: A Beginner's Laboratory GuideYou have a terminal open and a fresh Kali ISO on your desktop, but no idea which command runs first—or whether that command is even legal. This guide is for that exact moment. We start from zero: installing Python, writing your first script, and understanding why a variable named `password` is not the same as a variable named `PASSWORD`. From there we build a vocabulary of defense—CIA triad, CVE, scope, responsible disclosure—and construct a legally isolated lab network we call Wintermute. Every attack category is taught from two angles: how it works conceptually, and how you would detect or block it. You will not find live exploit code against real targets here. You will find commented Python snippets, lab checklists, and the explicit requirement of written authorization before any technique leaves your virtual network. Sections 1–4 establish your toolkit and ground rules; Sections 5–9 walk network reconnaissance, web application flaws, DoS concepts, wireless and social vectors, and malware mechanics without executing dangerous payloads; Sections 10–11 consolidate everything into a capstone assessment and a troubleshooting reference for when your lab inevitably breaks. Read with a notebook, test only in machines you own, and treat every script as a defensive sensor in disguise.
**What you need:** a laptop with 8 GB RAM, VirtualBox or VMware, and patience for your first syntax errors.
**What you will not do:** run unmodified exploits against infrastructure you do not own. READ THE ANALYSIS → |
| | MANAGE PREFERENCES → | You receive this email because you subscribed to DeafLetter. Unsubscribe Samuel — DeafNews · Privacy | |