Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
The Compliance Brief · Issue 6

Revolut handed data to a fake government request

Free weekly email

This went to subscribers on September 15. Get the next one.

One email every Tuesday: what changed in security and compliance that week, and what it means if you sell to enterprise buyers.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Two of the bigger items this week involve people being talked into something rather than software being broken, which is where most of the loss has been coming from for a while now. There is also a patching item that touches the build pipeline directly, and a quiet piece of state law that will eventually show up in your contract review. I have left out the AI research stories, interesting as they are, because none of them change what you will be asked in a security review this month.

Revolut gave customer data to someone posing as a government agency

Source: BleepingComputer

Revolut disclosed a breach after sharing customer data with a threat actor impersonating a government agency. The exposed information included financial details and passports. The company has not said how many customers were affected.

Our take

No exploit, no malware, a request that looked official enough to get answered. Every fintech I work with has an inbox that receives subpoenas, police requests and regulator letters, and almost none of them have a written procedure for verifying who sent one before data goes out the door. I would put that procedure in place this week, with out-of-band verification of the requester and a named person who has to approve disclosure, because auditors rarely probe this and attackers clearly do.

Trezor's supplier breach keeps growing, and it was never Trezor's system

Source: Infosecurity

Trezor says a breach at its supplier ShipMonk is considerably worse than first reported, now affecting around 81,000 customers. Separately, Trezor warned that attackers who breached its third-party email provider are using the data for phishing.

Our take

This is the fourth-party problem that vendor questionnaires handle badly. You list your subprocessors, your customer's reviewer ticks the box, and nobody asks what the fulfilment house or the email delivery vendor is doing with customer contact data. Make a short list of vendors that hold your customer identities or email addresses, confirm each one is contractually obliged to notify you fast, and assume any breach there arrives at your customers as a phishing campaign with your name on it.

Passkey enrolment is the new phishing target

Source: The Hacker News

Microsoft detailed two campaigns abusing third-party email delivery infrastructure. One sent over a million scam messages between August 3 and 5, 2026, impersonating chief executives. The other used passkey-themed social engineering to get into cloud environments and pull out data.

Our take

Plenty of readers have told a US prospect that they moved to passkeys and are therefore phishing-resistant. That claim holds for the authentication step and falls apart at registration and account recovery, which is exactly where these campaigns are aiming. Treat passkey enrolment as a privileged action with a second human involved, and while you are in there, check whether your outbound mail provider lets anyone send as your domain.

Artifactory auth bypasses are now on the exploited list

Source: CISA

CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalogue on September 11. Two affect JFrog Artifactory, covering incorrect authorization and improper authentication, and one affects ConnectWise ScreenConnect for improper privilege management and missing authorization.

Our take

Artifactory sits between your developers and your customers, so an authorization flaw there is a path to shipping someone else's code under your name. If you self-host it, this is a same-day job rather than a next-sprint job. A useful side effect: writing "KEV listing triggers emergency patching" into your vulnerability management policy gives you a defensible timeline that auditors and reviewers both accept.

Delaware amends its privacy and breach notification laws

Source: DataBreaches.net

On September 2, 2026, Delaware's governor signed HB 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act, which took effect at the start of 2025, and HB 381 amends the state's computer security breach notification law.

Our take

Delaware alone is not going to change anyone's quarter. The pattern is what I would pay attention to: the state obligations you mapped once during SOC 2 prep keep shifting under you, and your US customer contracts usually promise compliance with applicable law rather than with a fixed list. A twice-yearly review of state privacy and notification requirements, owned by someone by name, is cheap insurance against a clause you already signed.

Light week for regulators and a heavy one for anyone whose staff answer the phone. If you only do one thing from this, write down how your team verifies an official-looking data request.

Jacob

Share this issue LinkedIn X Email

Free weekly email

Get the next issue on Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly.

Go deeper

Every past issue · RSS feed