SOC2Prep

The LiteLLM fallout is a CI credential problem, not an AI problem

August 18, 2026. From issue 2 of The Compliance Brief, 2 stories for teams preparing for a first SOC 2 audit.

Last reviewed 2026-08-18Written by Jacob Masse, TrazTech Inc.

Issue 2 of The Compliance Brief went to subscribers on August 18, 2026. 2 of its 5 stories bear on the controls a SOC 2 audit tests, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: Help Net Security

A 153GB archive stolen in the LiteLLM supply chain attack has surfaced, containing 433,909 files. Hudson Rock attributed 118,829 CI runner dumps to 2,488 corporate domains, with credentials tied to AWS, Samsung, Cisco and Salesforce among them.

Our take, in short

CI runner dumps are the worst possible thing to lose, because build environments tend to hold the credentials nobody wants to rotate: cloud keys, registry tokens, signing material, production database strings. If you added an LLM gateway or proxy to your stack in the last year, treat every secret that environment could read as burned and rotate on that basis...

Read the full take on traztech.ca

An AWS key in a public JavaScript bundle took down 1,000 charity CRMs

Source: SecurityWeek

CRM provider Beacon disclosed a breach affecting more than 1,000 UK charities. The suspected root cause was a compromised AWS access key that had been exposed in publicly available JavaScript build artifacts.

Our take, in short

This is one of the most common findings I get on web application tests, and it is almost never in the source repository where the scanner is pointed. It gets baked into the built bundle, or into a sourcemap that ships to production alongside it.

Read the full take on traztech.ca

Also in issue 2

Outside the controls a SOC 2 audit tests, but in the same email:

All issues on SOC2Prep Newer: issue 3