The Compliance Brief for SOC 2 prep
Every Tuesday, the incidents from the past week that trace back to a control your SOC 2 auditor will test, and what to check on your side.
Readiness work is easier to prioritise when you can see which controls are failing at other companies this month. Most weeks the answer is the same short list: accounts nobody switched off, keys left in build output, access that outlived the person who needed it.
Below are the stories from recent issues that map onto that list, each with the short version of what happened and what to look at before your own audit window opens.
Free weekly email
Get the next issue on Tuesday
Join the list and the next issue arrives Tuesday morning. Or read a few below first.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Latest on the controls a SOC 2 audit tests
- A stolen OAuth token from a former employee's laptop
CrowdSec confirmed that attackers took the contents of 170 private repositories from its GitHub organisation. - Your AI agents are logging in as humans and SOC 2 cannot tell
A vendor-authored piece argues that AI agents often operate through human credentials, so actions taken by an agent look identical to actions taken by the person whose credentials it borrowed. - A departed employee's GitHub account was still live, and 170 private repos walked
CrowdSec disclosed that an attacker copied roughly 170 of its private GitHub repositories in May using the account of an employee who had recently left the company. - A regulator has now logged an AI agent as the attacker
The Spanish data protection agency received a breach report describing an attack carried out by an AI agent running on a known large language model. - Exposed Vite dev servers are being scanned for cloud keys
F5 Labs described an automated mass-scanning campaign hunting internet-exposed Vite development servers. - Passkey enrolment is the new phishing target
Microsoft detailed two campaigns abusing third-party email delivery infrastructure. - JFrog Artifactory flaw lands in the KEV catalogue
CISA added three actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalogue: an ownCloud authentication flaw, an unspecified Linux kernel issue, and a path traversal issue in JFrog Artifactory. - Rust crates that ran malware at compile time
The Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account published releases adding a typosquatted dependency.
Every issue on SOC2Prep
- Issue 8: A stolen OAuth token from a former employee's laptop
- Issue 7: A departed employee's GitHub account was still live, and 170 private repos walked
- Issue 6: Passkey enrolment is the new phishing target
- Issue 4: JFrog Artifactory flaw lands in the KEV catalogue
- Issue 3: Rust crates that ran malware at compile time
- Issue 2: The LiteLLM fallout is a CI credential problem, not an AI problem
Every issue in full, including the stories outside the controls a SOC 2 audit tests, is in the archive on traztech.ca. Issues with nothing on the controls a SOC 2 audit tests are listed there and not here.
Questions
How often does The Compliance Brief arrive?
Once a week, on Tuesday morning. Each issue covers the past week in five stories or so, with what happened and a short take on what it means for teams preparing for a first SOC 2 audit.
What does it cost?
Nothing. It is written by Jacob Masse, Principal at TrazTech Inc., which operates SOC2Prep. There is no paid tier.
Will signing up here send me anything else?
No. The form on this page adds you to The Compliance Brief and nothing else. Downloading a checklist elsewhere on the site is a separate signup, and it says what it sends before you give an address.
How do I stop it?
Every issue ends with a one-click unsubscribe link, and it is honoured immediately. Replying to any issue also reaches Jacob directly.
Free weekly email
Get it every Tuesday
One email a week on the controls a SOC 2 audit tests. Free, and one click to leave.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.