A departed employee's GitHub account was still live, and 170 private repos walked
September 22, 2026. From issue 7 of The Compliance Brief, 3 stories for teams preparing for a first SOC 2 audit.
Issue 7 of The Compliance Brief went to subscribers on September 22, 2026. 3 of its 5 stories bear on the controls a SOC 2 audit tests, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for teams preparing for a first SOC 2 audit.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: The Hacker News
CrowdSec disclosed that an attacker copied roughly 170 of its private GitHub repositories in May using the account of an employee who had recently left the company. The company had left that GitHub access open.
Our take, in short
Offboarding is the SOC 2 control where I see the most theatre. The HR ticket gets closed, the SSO account gets disabled, and the GitHub org, the cloud console, the CI tokens and the personal access tokens survive because they were never tied to the identity provider in the first place.
Read the full take on traztech.ca
A regulator has now logged an AI agent as the attacker
Source: SecurityWeek
The Spanish data protection agency received a breach report describing an attack carried out by an AI agent running on a known large language model. Regulators say the agent chained a successful login, discovery of a vulnerability, and access to personal data.
Our take, in short
This changes nothing about your obligations and quite a lot about your assumptions. Most detection tuning quietly assumes a human pace between login, poking around, and pulling data, and an agent collapses that into minutes.
Read the full take on traztech.ca
Exposed Vite dev servers are being scanned for cloud keys
Source: The Hacker News
F5 Labs described an automated mass-scanning campaign hunting internet-exposed Vite development servers. The goal is to pull AWS and Azure credentials, configuration files and infrastructure state files from those hosts.
Our take, in short
Development and preview environments get written out of audit scope constantly, and infrastructure state files are exactly where long-lived keys and connection strings sit. Ask your team whether any Vite dev server has ever been reachable from the internet, and if the answer is anything other than a confident no, rotate what was on that box.
Read the full take on traztech.ca
Related on SOC2Prep
- Do we need to hire someone for SOC 2?
- SOC 2 CC6: access control evidence, all 8
- SOC 2 checklist for a first audit
- SOC 2 bridge letters: what to write
Also in issue 7
Outside the controls a SOC 2 audit tests, but in the same email:
- Revolut handed over customer data to someone pretending to be a government
- OCR is still writing cheques for Security Rule failures
Older: issue 6 All issues on SOC2Prep Newer: issue 8
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.