A stolen OAuth token from a former employee's laptop
September 29, 2026. From issue 8 of The Compliance Brief, 2 stories for teams preparing for a first SOC 2 audit.
Issue 8 of The Compliance Brief went to subscribers on September 29, 2026. 2 of its 5 stories bear on the controls a SOC 2 audit tests, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for teams preparing for a first SOC 2 audit.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: Dark Reading
CrowdSec confirmed that attackers took the contents of 170 private repositories from its GitHub organisation. The token used was an OAuth token stolen from a former employee's computer through the TanStack npm supply chain compromise earlier this year.
Our take, in short
Offboarding at most companies this size disables the account and stops there, leaving OAuth grants, personal access tokens and CI credentials alive behind it. Pull the list of third-party OAuth apps authorised against your GitHub organisation this week and see how many you recognise.
Read the full take on traztech.ca
Your AI agents are logging in as humans and SOC 2 cannot tell
Source: BleepingComputer
A vendor-authored piece argues that AI agents often operate through human credentials, so actions taken by an agent look identical to actions taken by the person whose credentials it borrowed. The argument is that existing SOC 2 controls have no way to distinguish the two, leaving a gap in access review and logging evidence.
Our take, in short
It is marketing content and the framing is overheated, but the underlying problem is one I run into on real engagements. If your agent authenticates as a staff member, your quarterly access review is describing a person who is not the one taking the actions, and your audit trail will not survive a serious customer question.
Read the full take on traztech.ca
Related on SOC2Prep
- Are we ready for a SOC 2 auditor?
- SOC 2 CC4: monitoring your own controls
- SOC 2 checklist for a first audit
- SOC 2 policy gap finder
Also in issue 8
Outside the controls a SOC 2 audit tests, but in the same email:
- Eight NetScaler flaws, two already being exploited
- Labcorp's settlement is a preview of your next vendor contract
- Ottawa is looking at how a breach was disclosed, not only how it happened
Older: issue 7 All issues on SOC2Prep
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.