// 2 ZERO-DAY · 2 CVE · 5 EXPLOIT · 1 ADVISORY IN THE LAST 24H
SENT ISSUE WEEKLY-2026-W37

DeafLetter — week 37

AI AppSec: Scanners Agree on Just 5%, Triage Costs $128,000

SNAPSHOT // IMMUTABLEEN
DEAFNEWS DEAFLETTER // SECURITY BRIEF
VERIFIED SIGNALS // EDITORIAL SNAPSHOT

DeafLetter — week 37

AI AppSec: Scanners Agree on Just 5%, Triage Costs $128,000

01 // LEAD STORY
LEAD // 01

AI AppSec: Scanners Agree on Just 5%, Triage Costs $128,000

Contrast Security's AppSec Overflow 2026 report reveals three AI scanners testing the same codebase agree on only 5% of findings, while a single scanner reproduces just 17% of its own results across runs. Scanning 2 million lines costs roughly $315 in API fees; triaging the output costs about $128,000 — a 400-to-1 asymmetry.

OPEN REPORT →
02 // THREE SIGNALS
SIGNAL // 02

Dark Web: 153 Million Driver's Licenses for Sale, FBI Investigates IDScan.net

The Nexus dark web platform claims 153 million U.S. and Canadian driver's licenses. KrebsOnSecurity empirically verified records and traced the chain to IDScan.net, which processes over 21 million identity checks monthly. The FBI's New Orleans field office has opened an official inquiry.

READ THE ANALYSIS →
SIGNAL // 03

Google Patches Chrome Zero-Day: Urgent Update for 3 Billion Users

Google released Chrome 152.0.7977.82 to fix CVE-2026-85046, an actively exploited zero-day in the V8 engine with a CVSS score of 8.8. The vulnerability allows remote code execution in the renderer process via a crafted HTML page.

READ THE ANALYSIS →
SIGNAL // 04

FalconFlank PoC: Zero-Day Privilege Escalation in CrowdStrike Falcon Sensor

A researcher has publicly released a proof-of-concept exploiting the Office macro remediation feature to escalate privileges in the EDR sensor. CrowdStrike has not yet responded.

READ THE ANALYSIS →
03 // CVES AND PATCHES
CVE_PATCH // 05

JetBrains: TeamCity Flaw Exposed Cadence Service Data

JetBrains disclosed a breach of its Cadence cloud service after attackers exploited an unpatched TeamCity server vulnerable to CVE-2026-63077. The intrusion, which occurred between August 8 and 24, 2026, exposed a 2024 backup containing AWS IAM credentials, user data, and potentially synchronized PyCharm source code.

READ THE ANALYSIS →
CVE_PATCH // 06

Medusa Hits 500 Victims and Sells Time as a Service

CISA, FBI, and HHS updated the joint advisory AA25-071A in August 2026: Medusa ransomware has struck over 500 U.S. critical infrastructure organizations, adding roughly 200 victims in 18 months since the 300+ counted in March 2025. The figure reflects a mature criminal model where extortion has become a commercial service with negotiable terms, including the option to buy countdown extensions at $10,000 per day.

READ THE ANALYSIS →
CVE_PATCH // 07

OWASP Launches OASIS: AI and AppSec Join Forces Against Open-Source Vulnerabilities

OWASP unveiled OASIS on August 26, 2026, a community project that pairs AI-generated patches with human AppSec validation to accelerate remediation in open-source software.

READ THE ANALYSIS →
CVE_PATCH // 08

MikroTrick Hits RouterOS: Active Attacks and First Coordinated LLM-Assisted Disclosure

CERT Polska uncovers the MikroTrick chain — six vulnerabilities in MikroTik RouterOS, two critical for unauthenticated remote control. Active attacks confirmed since September 2, 2026.

READ THE ANALYSIS →
CVE_PATCH // 09

Docker CVE-2026-34040: Ten-Year AuthZ Bypass via a Single Padded HTTP Request

CVE-2026-34040 lets attackers bypass Docker Engine authorization plugins with a single HTTP request exceeding 1 MB. The patch landed on March 25, 2026.

READ THE ANALYSIS →
04 // THE GUIDE
GUIDE // 10

Foundations of Ethical Security Testing with Python: A Beginner's Laboratory Guide

You have a terminal open and a fresh Kali ISO on your desktop, but no idea which command runs first—or whether that command is even legal. This guide is for that exact moment. We start from zero: installing Python, writing your first script, and understanding why a variable named `password` is not the same as a variable named `PASSWORD`. From there we build a vocabulary of defense—CIA triad, CVE, scope, responsible disclosure—and construct a legally isolated lab network we call Wintermute. Every attack category is taught from two angles: how it works conceptually, and how you would detect or block it. You will not find live exploit code against real targets here. You will find commented Python snippets, lab checklists, and the explicit requirement of written authorization before any technique leaves your virtual network. Sections 1–4 establish your toolkit and ground rules; Sections 5–9 walk network reconnaissance, web application flaws, DoS concepts, wireless and social vectors, and malware mechanics without executing dangerous payloads; Sections 10–11 consolidate everything into a capstone assessment and a troubleshooting reference for when your lab inevitably breaks. Read with a notebook, test only in machines you own, and treat every script as a defensive sensor in disguise. **What you need:** a laptop with 8 GB RAM, VirtualBox or VMware, and patience for your first syntax errors. **What you will not do:** run unmodified exploits against infrastructure you do not own.

READ THE ANALYSIS →
MANAGE PREFERENCES →
You receive this email because you subscribed to DeafLetter. Unsubscribe
Samuel — DeafNews · Privacy