<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>The Compliance Brief on SOC2Prep</title>
    <link>https://soc2prep.ca/brief</link>
    <atom:link href="https://soc2prep.ca/brief/feed.xml" rel="self" type="application/rss+xml"/>
    <description>A free weekly email for teams getting ready for SOC 2: the week&#x27;s incidents that trace back to a control an auditor tests, with a take on each.</description>
    <language>en-CA</language>
    <item>
      <title>A stolen OAuth token from a former employee&#x27;s laptop</title>
      <link>https://soc2prep.ca/brief/8-patch-netscaler-then-read-the-labcorp-terms</link>
      <guid isPermaLink="true">https://soc2prep.ca/brief/8-patch-netscaler-then-read-the-labcorp-terms</guid>
      <pubDate>Tue, 29 Sep 2026 13:00:00 +0000</pubDate>
      <description>A stolen OAuth token from a former employee&#x27;s laptop. CrowdSec confirmed that attackers took the contents of 170 private repositories from its GitHub organisation. Your AI agents are logging in as humans and SOC 2 cannot tell. A vendor-authored piece argues that AI agents often operate through human credentials, so actions taken by an agent look identical to actions taken by the person whose credentials it borrowed.</description>
    </item>
    <item>
      <title>A departed employee&#x27;s GitHub account was still live, and 170 private repos walked</title>
      <link>https://soc2prep.ca/brief/7-fake-government-requests-real-ai-attacks</link>
      <guid isPermaLink="true">https://soc2prep.ca/brief/7-fake-government-requests-real-ai-attacks</guid>
      <pubDate>Tue, 22 Sep 2026 13:00:00 +0000</pubDate>
      <description>A departed employee&#x27;s GitHub account was still live, and 170 private repos walked. CrowdSec disclosed that an attacker copied roughly 170 of its private GitHub repositories in May using the account of an employee who had recently left the company. A regulator has now logged an AI agent as the attacker. The Spanish data protection agency received a breach report describing an attack carried out by an AI agent running on a known large language model. Exposed Vite dev servers are being scanned for cloud keys. F5 Labs described an automated mass-scanning campaign hunting internet-exposed Vite development servers.</description>
    </item>
    <item>
      <title>Passkey enrolment is the new phishing target</title>
      <link>https://soc2prep.ca/brief/6-revolut-handed-data-to-a-fake-government-request</link>
      <guid isPermaLink="true">https://soc2prep.ca/brief/6-revolut-handed-data-to-a-fake-government-request</guid>
      <pubDate>Tue, 15 Sep 2026 13:00:00 +0000</pubDate>
      <description>Passkey enrolment is the new phishing target. Microsoft detailed two campaigns abusing third-party email delivery infrastructure.</description>
    </item>
    <item>
      <title>JFrog Artifactory flaw lands in the KEV catalogue</title>
      <link>https://soc2prep.ca/brief/4-what-cisas-two-red-teams-say-about-your-soc-2</link>
      <guid isPermaLink="true">https://soc2prep.ca/brief/4-what-cisas-two-red-teams-say-about-your-soc-2</guid>
      <pubDate>Tue, 01 Sep 2026 13:00:00 +0000</pubDate>
      <description>JFrog Artifactory flaw lands in the KEV catalogue. CISA added three actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalogue: an ownCloud authentication flaw, an unspecified Linux kernel issue, and a path traversal issue in JFrog Artifactory.</description>
    </item>
    <item>
      <title>Rust crates that ran malware at compile time</title>
      <link>https://soc2prep.ca/brief/3-a-cvss-10-in-entra-id-and-a-breach-that-grew-tenfold</link>
      <guid isPermaLink="true">https://soc2prep.ca/brief/3-a-cvss-10-in-entra-id-and-a-breach-that-grew-tenfold</guid>
      <pubDate>Tue, 25 Aug 2026 13:00:00 +0000</pubDate>
      <description>Rust crates that ran malware at compile time. The Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account published releases adding a typosquatted dependency. Microsoft patches a 10.0 in Entra ID. Microsoft patched CVE-2026-69836, a remote code execution flaw in Entra ID carrying a CVSS score of 10.0, which was initially reported as exploited in the wild.</description>
    </item>
    <item>
      <title>The LiteLLM fallout is a CI credential problem, not an AI problem</title>
      <link>https://soc2prep.ca/brief/2-secrets-in-build-artifacts-and-who-gets-blamed</link>
      <guid isPermaLink="true">https://soc2prep.ca/brief/2-secrets-in-build-artifacts-and-who-gets-blamed</guid>
      <pubDate>Tue, 18 Aug 2026 13:00:00 +0000</pubDate>
      <description>The LiteLLM fallout is a CI credential problem, not an AI problem. A 153GB archive stolen in the LiteLLM supply chain attack has surfaced, containing 433,909 files. An AWS key in a public JavaScript bundle took down 1,000 charity CRMs. CRM provider Beacon disclosed a breach affecting more than 1,000 UK charities.</description>
    </item>
  </channel>
</rss>
