The LiteLLM fallout is a CI credential problem, not an AI problem
August 18, 2026. From issue 2 of The Compliance Brief, 2 stories for teams preparing for a first SOC 2 audit.
Issue 2 of The Compliance Brief went to subscribers on August 18, 2026. 2 of its 5 stories bear on the controls a SOC 2 audit tests, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for teams preparing for a first SOC 2 audit.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: Help Net Security
A 153GB archive stolen in the LiteLLM supply chain attack has surfaced, containing 433,909 files. Hudson Rock attributed 118,829 CI runner dumps to 2,488 corporate domains, with credentials tied to AWS, Samsung, Cisco and Salesforce among them.
Our take, in short
CI runner dumps are the worst possible thing to lose, because build environments tend to hold the credentials nobody wants to rotate: cloud keys, registry tokens, signing material, production database strings. If you added an LLM gateway or proxy to your stack in the last year, treat every secret that environment could read as burned and rotate on that basis...
Read the full take on traztech.ca
An AWS key in a public JavaScript bundle took down 1,000 charity CRMs
Source: SecurityWeek
CRM provider Beacon disclosed a breach affecting more than 1,000 UK charities. The suspected root cause was a compromised AWS access key that had been exposed in publicly available JavaScript build artifacts.
Our take, in short
This is one of the most common findings I get on web application tests, and it is almost never in the source repository where the scanner is pointed. It gets baked into the built bundle, or into a sourcemap that ships to production alongside it.
Read the full take on traztech.ca
Related on SOC2Prep
- SOC 2 incident response plan requirements
- SOC 2 CC6: access control evidence, all 8
- SOC 2 acceptable use policy, minus the filler
- SOC 2 access control policy: what to write
Also in issue 2
Outside the controls a SOC 2 audit tests, but in the same email:
- Metabase SQL injection is now on the KEV list
- A year-long campaign is quietly draining Salesforce and ServiceNow tenants
- When the subprocessor is breached, your customer writes the letter with your name in it
All issues on SOC2Prep Newer: issue 3
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.