Rust crates that ran malware at compile time
August 25, 2026. From issue 3 of The Compliance Brief, 2 stories for teams preparing for a first SOC 2 audit.
Issue 3 of The Compliance Brief went to subscribers on August 25, 2026. 2 of its 5 stories bear on the controls a SOC 2 audit tests, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for teams preparing for a first SOC 2 audit.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: The Hacker News
The Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account published releases adding a typosquatted dependency. The dependency's build script downloaded and executed a remote payload during compilation.
Our take, in short
Build-time execution means the target was your CI runner and whatever credentials live on it, not your production containers, so scanning the shipped artifact would have found nothing. Pinned versions and committed lockfiles are the boring control that stops this, and both are things a SOC 2 auditor will happily take evidence of.
Read the full take on traztech.ca
Microsoft patches a 10.0 in Entra ID
Source: Help Net Security
Microsoft patched CVE-2026-69836, a remote code execution flaw in Entra ID carrying a CVSS score of 10.0, which was initially reported as exploited in the wild. Entra ID, formerly Azure Active Directory, handles logins and access to Microsoft 365, Azure and connected third-party applications.
Our take, in short
The patch is Microsoft's problem, but the questionnaire is yours. If your product federates with Entra or your own staff sign in through it, assume a buyer's security team asks this week whether you were affected, and have an answer that references sign-in logs and privileged service principals rather than a shrug.
Read the full take on traztech.ca
Related on SOC2Prep
- SOC 2 CC6: access control evidence, all 8
- SOC 2 checklist for a first audit
- SOC 2 readiness scorecard
- SOC 2 vendor risk triage
Also in issue 3
Outside the controls a SOC 2 audit tests, but in the same email:
- SickKids gets hit through somebody else's software
- CareCloud's count goes from 350,000 to 3.7 million
- Defence contractors do not believe their own CMMC scores
Older: issue 2 All issues on SOC2Prep Newer: issue 4
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.