Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Free weekly email · 8 issues so far

The Compliance Brief

Every Tuesday, the security and compliance stories from the past week that change something for a Canadian software company selling to enterprise buyers, with a plain take on each one. Written by Jacob Masse, a published CVE researcher who runs SOC 2, ISO 27001 and penetration testing work at TrazTech. No pitch in the email.

Five stories a weekBreaches, regulator moves and exploited bugs, picked for what they mean for a security review.
A take on eachWhat happened, then what to do about it. Stories with no consequence are left out.
Five minutesPlain text, one sender, one click to unsubscribe. Replies reach Jacob.

Free weekly email

Get the next issue on Tuesday

Join the list and the next issue lands in your inbox Tuesday morning. Or read a few below first.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Every issue

  1. Issue 8 · September 29, 2026
    Patch NetScaler, then read the Labcorp terms
    Two things happened this week that are worth your attention for different reasons. There is an actively exploited gateway bug that needs a maintenance window, and there is a settlement in the United States whose remediation terms will…
    • Eight NetScaler flaws, two already being exploited
    • Labcorp's settlement is a preview of your next vendor contract
    • A stolen OAuth token from a former employee's laptop
    • Your AI agents are logging in as humans and SOC 2 cannot tell
    • Ottawa is looking at how a breach was disclosed, not only how it happened
  2. Issue 7 · September 22, 2026
    Fake government requests, real AI attacks
    Five things came through this week that actually touch how you get through a US security review, and a few of them are about access nobody thought to revoke. The Revolut disclosure is the one I would read twice if you work in fintech…
    • Revolut handed over customer data to someone pretending to be a government
    • A regulator has now logged an AI agent as the attacker
    • A departed employee's GitHub account was still live, and 170 private repos walked
    • Exposed Vite dev servers are being scanned for cloud keys
    • OCR is still writing cheques for Security Rule failures
  3. Issue 6 · September 15, 2026
    Revolut handed data to a fake government request
    Two of the bigger items this week involve people being talked into something rather than software being broken, which is where most of the loss has been coming from for a while now. There is also a patching item that touches the build…
    • Revolut gave customer data to someone posing as a government agency
    • Trezor's supplier breach keeps growing, and it was never Trezor's system
    • Passkey enrolment is the new phishing target
    • Artifactory auth bypasses are now on the exploited list
    • Delaware amends its privacy and breach notification laws
  4. Issue 5 · September 8, 2026
    Court records, driver's licences, and an FTC bill
    Four of the five things worth reading this week were somebody else's vendor getting breached, which tells you where the pressure is going in security reviews. The fifth was the FTC collecting money from a Canadian payments company for…
    • Thomson Reuters court software breached in March, disclosed in September
    • An ID verification vendor appears to be the source of 153 million licence scans
    • FTC takes $4.85M from Nuvei over who it let onto its rails
    • McKesson tells the SEC it was hit through third-party applications
    • AI coding agents are pulling packages nobody registered
  5. Issue 4 · September 1, 2026
    What CISA's two red teams say about your SOC 2
    Quiet week for regulators, busier week for anyone who owns a build pipeline or a vendor list. The through line in most of what landed is detection and third parties, which happens to be where most US security reviews spend their time too…
    • CISA red-teamed two organizations and only one saw it coming
    • McKesson breach came through third-party applications
    • Two arrests in the TeamPCP open-source supply chain spree
    • JFrog Artifactory flaw lands in the KEV catalogue
    • Cyber claims are fewer and far more expensive
  6. Issue 3 · August 25, 2026
    A CVSS 10 in Entra ID and a breach that grew tenfold
    Two things this week actually change what you do on Monday morning: a maximum-severity hole in the identity service most of your customers log in through, and a supply chain attack that runs code while you compile rather than while you…
    • Microsoft patches a 10.0 in Entra ID
    • Rust crates that ran malware at compile time
    • SickKids gets hit through somebody else's software
    • CareCloud's count goes from 350,000 to 3.7 million
    • Defence contractors do not believe their own CMMC scores
  7. Issue 2 · August 18, 2026
    Secrets in build artifacts, and who gets blamed
    Four of the five stories this week come down to the same thing: someone else's credential, sitting somewhere it should not have been, and a customer having to explain it to their customers. If you are answering security questionnaires…
    • An AWS key in a public JavaScript bundle took down 1,000 charity CRMs
    • The LiteLLM fallout is a CI credential problem, not an AI problem
    • Metabase SQL injection is now on the KEV list
    • A year-long campaign is quietly draining Salesforce and ServiceNow tenants
    • When the subprocessor is breached, your customer writes the letter with your name in it
  8. Issue 1 · August 11, 2026
    A $250,000 penalty and a vendor that went dark
    This is the first issue of a weekly note on what actually moved for Canadian SaaS companies selling into the United States. I read the same feeds you do not have time for, and I keep the items that change how a US security review or a…
    • New York fined a money transmitter for a weak program, not a breach
    • LexisNexis pulled products offline over a third-party vendor incident
    • The Snowflake extortion case ends with a guilty plea in Kitchener
    • Gunra ransomware is getting in through firewalls, per a joint advisory
    • Hidden prompt injection is showing up in "Ask AI" buttons on marketing pages

Prefer a reader? The RSS feed carries every issue in full.

Free weekly email

Read this far? Get it weekly.

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly.