SOC2Prep

Rust crates that ran malware at compile time

August 25, 2026. From issue 3 of The Compliance Brief, 2 stories for teams preparing for a first SOC 2 audit.

Last reviewed 2026-08-25Written by Jacob Masse, TrazTech Inc.

Issue 3 of The Compliance Brief went to subscribers on August 25, 2026. 2 of its 5 stories bear on the controls a SOC 2 audit tests, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: The Hacker News

The Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account published releases adding a typosquatted dependency. The dependency's build script downloaded and executed a remote payload during compilation.

Our take, in short

Build-time execution means the target was your CI runner and whatever credentials live on it, not your production containers, so scanning the shipped artifact would have found nothing. Pinned versions and committed lockfiles are the boring control that stops this, and both are things a SOC 2 auditor will happily take evidence of.

Read the full take on traztech.ca

Microsoft patches a 10.0 in Entra ID

Source: Help Net Security

Microsoft patched CVE-2026-69836, a remote code execution flaw in Entra ID carrying a CVSS score of 10.0, which was initially reported as exploited in the wild. Entra ID, formerly Azure Active Directory, handles logins and access to Microsoft 365, Azure and connected third-party applications.

Our take, in short

The patch is Microsoft's problem, but the questionnaire is yours. If your product federates with Entra or your own staff sign in through it, assume a buyer's security team asks this week whether you were affected, and have an answer that references sign-in logs and privileged service principals rather than a shrug.

Read the full take on traztech.ca

Also in issue 3

Outside the controls a SOC 2 audit tests, but in the same email:

Older: issue 2 All issues on SOC2Prep Newer: issue 4